Prosecution Insights
Last updated: October 02, 2026
Application No. 18/189,681

Distributed Edge Application Compliance

Final Rejection §101§103
Filed
Mar 24, 2023
Examiner
SHEIKH, ASFAND M
Art Unit
Tech Center
Assignee
International Business Machines Corporation
OA Round
2 (Final)
46%
Grant Probability
Moderate
3-4
OA Rounds
11m
Est. Remaining
94%
With Interview

Examiner Intelligence

Grants 46% of resolved cases
46%
Career Allowance Rate
262 granted / 568 resolved
-13.9% vs TC avg
Strong +48% interview lift
Without
With
+48.3%
Interview Lift
resolved cases with interview
Typical timeline
4y 5m
Avg Prosecution
23 currently pending
Career history
601
Total Applications
across all art units

Statute-Specific Performance

§101
27.8%
-12.2% vs TC avg
§103
46.8%
+6.8% vs TC avg
§102
7.9%
-32.1% vs TC avg
§112
9.0%
-31.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 568 resolved cases

Office Action

§101 §103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim(s) 1-20 are pending for examination. Claim(s) 1, 10, and 19 are amended. This action is Final. Claim Interpretation The examiner notes the following claim interpretation: Regarding Claim(s) 19; “computer readable storage medium” is noted to be statutory based on the definition found in Applicant’s Specification ⁋[0029] – Without limitation, the computer readable storage medium may be an electronic storage medium, a magnetic storage medium, an optical storage medium, an electromagnetic storage medium, a semiconductor storage medium, a mechanical storage medium, or any suitable combination of the foregoing. Some known types of storage devices that include these mediums include: diskette, hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or Flash memory), static random access memory (SRAM), compact disc read-only memory (CD-ROM), digital versatile disk (DVD), memory stick, floppy disk, mechanically encoded device (such as punch cards or pits / lands formed in a major surface of a disc) or any suitable combination of the foregoing. A computer readable storage medium, as that term is used in the present disclosure, is not to be construed as storage in the form of transitory signals per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide, light pulses passing through a fiber optic cable, electrical signals communicated through a wire, and/or other transmission media. As will be understood by those of skill in the art, data is typically moved at some occasional points in time during normal operations of a storage device, such as during access, de-fragmentation or garbage collection, but this does not render the storage device as transitory because the data is not transitory while it is stored.” Therefore, the examiner construes that “computer readable storage medium” is statutory under 35 U.S.C. 101. Response to Arguments Applicant's arguments filed 6/11/2026 with respect to the 35 U.S.C. 101 rejection have been fully considered but they are not persuasive. Applicant Argues: The Examiner suggests that the claimed invention falls into the category of "mental processes." Applicant respectfully disagrees. According to the MPEP § 2106.04(a)(2), subsection IIIA, "Claims do not recite a mental process when they do not contain limitations that can practically be performed in the human mind, for instance when the human mind is not equipped to perform the claim limitations." However, this characterization improperly abstracts the claims away from the specific edge computing network operations recited in the claims. Under current USPTO guidance, claims must be evaluated "as a whole" and examiners must avoid oversimplifying claims by ignoring specific technical limitations. The USPTO memorandum regarding Ex Parte Desjardins expressly states that examiners should avoid evaluating claims "at such a high level of generality" that "potentially meaningful technical limitations are dismissed without adequate explanation." (See Memorandum from Charles Kim, Deputy Commissioner for Patents dated December 5, 2025, at page. 4, hereinafter "USPTO memorandum", revising MPEP § 2106.05(a)). Examiner’s Response: The examiner respectfully disagrees. The examiner notes that the human is capable with the aid of pen and paper “to determining... compliance scores resulting from compliance checks performed at each layer in layers in an edge computing network for components for the application running in the layers, wherein the compliance checks performed at each layer are determined using a compliance profile identifying a set of the compliance checks for each component in the application, and wherein the compliance profile associates compliance checks with tags identifying corresponding layers in the edge computing network, and ... execute compliance checks associated with tags corresponding to the each layer.” The examiner notes that the human mind and identify layers in an edge computing network (i.e., viewing topography) and performing compliance checks based on profiles and tag data via pen and paper. Therefore, the examiner finds this argument not persuasive. Applicant Argues: Even assuming arguendo that certain aspects of the claims could be characterized as involving mental evaluations, the claims integrate any alleged judicial exception into a practical application that improves machine learning calibration technology itself. The Examiner's rejection improperly oversimplifies the claims and fails to evaluate the claims as a whole, contrary to current USPTO guidance and precedential authority. Applicant respectfully submits that under MPEP, Examiners are required to consider whether the claim "purport(s) to improve the functioning of the computer itself' or "any other technology or technical field." (See MPEP, at Section 2106.05(a)). Further, 2019 October Updates from USPTO also mentions similar analysis. For example, the 2019 October Updates from USPTO states that "if the additional limitations reflect an improvement in the functioning of a computer, or an improvement to another technology or technical field, the claim integrates the judicial exception into a practical application and thus imposes a meaningful limit on the judicial exception" (See October 2019 Update: Subject Matter Eligibility, at pg. 11). Applicant respectfully submits that as amended, the pending claims are not directed merely to generic "compliance analysis" or "data evaluation." Rather, the claims are directed to a specific distributed edge-computing architecture in which compliance checks are selectively executed at different layers of an edge computing network using tagged compliance profiles, and those compliance scores are aggregated in a manner that reduces bandwidth usage within the edge computing network itself. The claims therefore recite a specific technological solution to problems arising in distributed edge-computing environments. The amended claims now expressly recite "wherein the compliance profile associates compliance checks with tags identifying corresponding layers in the edge computing network, and wherein agents at each layer selectively execute compliance checks associated with tags corresponding to each layer." The claims further recite "wherein the aggregation of the compliance scores reduce amount of data transmitted through the edge computing network." These limitations are directed to concrete improvements in distributed edge-network operation, including selective layer-specific processing and reduced network transmission overhead. USPTO eligibility guidance, claims are not directed to an abstract idea when the claims integrate the alleged abstract idea into a practical application that improves computer or network functionality. In this case, MPEP § 2106.04(d)(1) expressly explains that improvements to computer capabilities or network functionality represent meaningful practical applications. Likewise, MPEP § 2106.05(a) explains that claims directed to improvements in the functioning of a computer or another technology are patent eligible. The present claims improve operation of distributed edge-computing systems by selectively executing compliance checks at corresponding edge-network layers and by reducing network transmission overhead through intermediary aggregation of compliance scores. These are concrete technological improvements to distributed edge-network architecture itself. Examiner’s Response: The examiner respectfully disagrees. The examiner notes that the human is capable with the aid of pen and paper “to determining... compliance scores resulting from compliance checks performed at each layer in layers in an edge computing network for components for the application running in the layers, wherein the compliance checks performed at each layer are determined using a compliance profile identifying a set of the compliance checks for each component in the application, and wherein the compliance profile associates compliance checks with tags identifying corresponding layers in the edge computing network, and ... execute compliance checks associated with tags corresponding to the each layer.” The examiner notes that the human mind and identify layers in an edge computing network (i.e., viewing topography) and performing compliance checks based on profiles and tag data via pen and paper. The examiner notes “reduce amount of data transmitted through the edge computing network” is an ancillary effect on the computer system based on the mental process of data aggregation. The examiner finds this to be mere instructions to implement an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea. The examiner notes this is further evidenced in Wang, that sates [0037] - Data aggregation may provide various benefits for IoT systems such as, for example, reduced data transmission overhead, reduced data transmission latency, enhanced energy-efficiency, greener data transmissions, or the like. Therefore, the examiner finds this argument not persuasive. Applicant Argues: The specification expressly supports these technical improvements[...]. The specification also provides concrete [...] The amended claims additionally recite a specific networking improvement through reduced data transmission within the edge computing network. The specification explains that "compliance manager 214 also aggregates compliance scores 226 received from components 210 in lower layer 232 for transmission upward in layers 208 to top layer 230." The specification further explains that "compliance scores 226 are transmitted as aggregated compliance scores 234 in results 227." Most importantly, the specification expressly states that "[t]his aggregation of compliance scores 226 can reduce the amount of data transmitted through edge computing network 206" (See Applicant's specification as filed, at paragraphs [0060]-[0061]). [...] The Examiner's rejection also conflicts with the USPTO guidance cautioning against dismissing technological claim limitations as generic computer operations without considering whether those limitations confer technological improvements. Revised MPEP § 2106.05(a), as reflected in the USPTO memorandum, specifically instructs that examiners "should not dismiss additional elements as mere 'generic computer components' without considering whether such elements confer a technological improvement to a technical problem." (See USPTO Memorandum, page 4). Applicant respectfully submits that it seems that the Examiner's rejection fails to analyze how the claimed architecture and how operations performed using such architecture improves efficiency of edge computing networks and instead improperly characterizes the claims at a generalized level divorced from the specific computational operations recited. The claims are therefore fundamentally different from claims directed merely to organizing human activity or performing mental processes. The amended claims require a distributed edge-network architecture involving multiple network layers, tagged compliance profiles associated with corresponding layers, distributed agents deployed at different layers, selective execution of compliance checks based on corresponding tags and layer locations, and aggregation of compliance scores to reduce network bandwidth usage. These operations cannot practically be performed mentally or with pen and paper. Rather, the claims are rooted in distributed network infrastructure and improve the technical operation of edge-computing systems themselves. In addition, Applicant respectfully asserts that the recitation of the various computer components are an integral part of the solution of Applicant's invention. Applicant's claims require accurate analysis and modeling for a large amount of data in a quick and efficient manner. To accomplish this, computer components, which possess a large amount of computing power are required. Without the computing power of computer components, Applicant's claims would be largely ineffective given the massive amount of time it would take to retrieve and carry out Applicant's claims without computer components. Applicant respectfully emphasizes that the amount of information is impossible for human mind to handle quickly with accuracy. Succinctly put, without the accurate implementation of computer components, Applicant's claims would have little to no practical value. Accordingly, the recitation of various computer components is not post-solution activity but are a requisite part of the proposed solution. Examiner’s Response: The examiner notes “reduce amount of data transmitted through the edge computing network” is an ancillary effect on the computer system based on the mental process of data aggregation. The examiner finds this to be mere instructions to implement an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea. In addition, the examiner notes this is further evidenced in Wang, that sates [0037] - Data aggregation may provide various benefits for IoT systems such as, for example, reduced data transmission overhead, reduced data transmission latency, enhanced energy-efficiency, greener data transmissions, or the like and one could argue this is well, understood, routing and conventional in the data aggregation arts involving networks. The examiner notes respectfully notes that the human mind with the aid of pen and apper can process “data” related to a distributed edge-network architecture involving multiple network layers, tagged compliance profiles associated with corresponding layers, distributed agents deployed at different layers, selective execution of compliance checks based on corresponding tags and layer locations, and aggregation of compliance scores to reduce network bandwidth usage. Further, the additional elements of i.e., a number of processing units, agents... execute..., reducing amount of data transmitted through the edge computing network, and program product w/ computer readable storage medium are described at a high level in Applicant’s specification without any meaningful detail about their structure or configuration. These elements in the steps are recited at a high-level of generality such that it amounts no more than mere instructions to apply the exception using a generic computer component and merely invoke such additional elements as a tool to perform the abstract idea. See MPEP 2106.05(f). Accordingly, these additional elements, even in combination, do not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. Therefore, the examiner finds this argument not persuasive. Applicant's arguments filed 6/11/2026 with respect to the 35 U.S.C. 103 rejection have been fully considered but they are not persuasive. Applicant Argues: [...] In this case, the Examiner relies on Wang for layered aggregation in an edge or IoT-style network. Wang does disclose intermediary aggregation generally. For example, Wang discusses intermediary nodes aggregating messages from downstream nodes to reduce communication overhead in distributed systems (See Wang, at paragraphs [0034]-[0045]). However, Wang's aggregation is fundamentally directed to message aggregation for communication efficiency. Wang does not disclose compliance profiles that associate compliance checks with tags identifying corresponding layers in an edge computing network. In addition, Wang does not disclose the amended features of compliance checks associated with tags identifying corresponding network layers, nor does Wang disclose the amended features of agents selectively executing different compliance checks based on those tags at different layers. Wang's intermediary nodes aggregate network messages generally. Wang does not disclose selective compliance-check execution by agents deployed at different edge-network layers based on tagged compliance profiles. Examiner’s Response: The examiner respectfully notes the following: Wang discloses ...wherein [a] “profile” associates “aggregation” with tags identifying corresponding layers in the edge computing network, and wherein agents at each layer selectively execute “aggregation” associated with tags corresponding to the each layer ([0043] - For example, the gateway 108 may request that a particular device only aggregate data from a specific physical region and [0045] - The intermediary nodes may aggregate their local data with forwarded data that they receive from downstream nodes. The intermediary nodes may aggregate data aggregation based on rules and policies, for example, specified in one or more DAREQ messages. In accordance with an example embodiment, an application protocol header is included in one or more data aggregation responses 118 that may be sent upstream from one device to a next hop. The header may indicate how data aggregation should be done. The header may further identify the data that should be aggregated. In accordance with the illustrated embodiment). The examiner has construed a header to a be a form of “profile” identifies (i.e., tags) which data should be aggregated at that specific physical region (i.e., layer). While Wang is related to messages. The examiner sought to combine Fawcett and May to teach the concepts of compliance/compliance profiles. One cannot show nonobviousness by attacking references individually where the rejections are based on combinations of references. Therefore, the examiner finds this argument not persuasive and/or moot in view of new grounds of rejection, i.e., see updated rejection below including May (US 2020/0304533 A1). Applicant Argues: The Examiner further relies on Fawcett for compliance or risk scoring. Fawcett does discuss determining risk or compliance scores for software applications and application components (See Fawcett, at Col. 5:15-45; Col. 7: 5-40). However, Fawcett does not disclose a distributed edge-computing architecture in which compliance checks are tagged for corresponding network layers and selectively executed by agents at those layers. Fawcett evaluates software application risks generally. Fawcett does not disclose cloud- layer tags, near-edge tags, edge-layer tags, distributed edge agents performing different checks depending on layer location, or aggregation of compliance scores to reduce bandwidth usage within an edge computing network. Nor does Fawcett disclose aggregation at intermediary layers for reducing network transmission overhead. Fawcett may aggregate risk scores logically at an application level, but that is fundamentally different from the claimed network-layer aggregation architecture. Examiner’s Response: The examiner respectfully disagrees. The examiner notes as noted above, Wang teaches concepts of disclose a distributed edge-computing architecture in which “messages are aggregated based on” tag[s] for corresponding network layers and selectively executed by agents at those layers, see [0043] and [0045]. The examiner sought to combine May to teach wherein the compliance profile associates compliance checks with tags identifying “elements” in the edge computing network ([0038] - According to an aspect of the present disclosure, system 104 can build an internal network topology to determine network elements 110 that require a compliance report and can execute a collection of security checks on such network elements 110), and wherein agents at each layer selectively execute compliance checks associated with tags corresponding to “the element” ([0038] - .For execution of a collection of security checks, system 104 can request network element 110 for configuration data via the security fabric by assigning a unique authentication token with each request, which can be sent back by network element 110 to system 104 with the configuration data. In response to the request, system 104 can receive the configuration data of network element 110 pertaining to each security check of the collection of security checks via the security fabric). One cannot show nonobviousness by attacking references individually where the rejections are based on combinations of references. Therefore, the examiner finds this argument not persuasive and/or moot in view of new grounds of rejection, i.e., see updated rejection below including May (US 2020/0304533 A1). Applicant Argues: Importantly, neither Wang nor Fawcett discloses the claimed bandwidth-reduction functionality for a edge computing network by aggregating compliance scores at each layer. The amended claims expressly require "wherein the aggregation of the compliance scores reduce amount of data transmitted through the edge computing network." Although Wang generally reduces message traffic through aggregation, Wang does not disclose aggregating compliance scores generated by layer-specific compliance agents using tagged compliance profiles. Fawcett likewise does not disclose reducing edge-network bandwidth usage through intermediary aggregation of compliance-analysis results. Examiner’s Response: The examiner respectfully disagrees. Wang was shown to disclose wherein the aggregation of the [“message data”] reduce amount of data transmitted through the edge computing network; and (FIG. 1 and [0037] - Data aggregation may provide various benefits for IoT systems such as, for example, reduced data transmission overhead, reduced data transmission latency, enhanced energy-efficiency, greener data transmissions, or the like and [0045] - Using the data aggregation requests 116 and response 118, the number of messages that are forwarded from the intermediary nodes to the gateway 108 may be reduced). The examiner sought to combine Fawcett and May to teach the concepts of compliance/compliance profiles. One cannot show nonobviousness by attacking references individually where the rejections are based on combinations of references. Therefore, the examiner finds this argument not persuasive and/or moot in view of new grounds of rejection, i.e., see updated rejection below including May (US 2020/0304533 A1). Applicant Argues: The Examiner's combination therefore improperly reconstructs Applicant's architecture using hindsight. Wang's communication aggregation and Fawcett's software-risk scoring are fundamentally different systems addressing different technical problems. Nothing in the cited references suggests modifying Wang's intermediary communication aggregation system to implement Applicant's tagged compliance-profile architecture with layer-specific compliance execution and bandwidth-reducing compliance-score aggregation. For purposes of the present discussion, independent claims 10 and 19 recite similar limitations to claim 1 and are distinguished from the cited reference for the same reasons. Because claims 7-9 and 16-19 depend from claims 1, 10, and 19, respectively, they are distinguished from the cited references for at least the reasons explained above. Therefore, Applicant respectfully asserts that the rejection of claims 1, 7-10, and 16-19 under 35 U.S.C. § 103 has been overcome and should be withdrawn. Examiner’s Response: In response to applicant's argument that the examiner's conclusion of obviousness is based upon improper hindsight reasoning, it must be recognized that any judgment on obviousness is in a sense necessarily a reconstruction based upon hindsight reasoning. But so long as it takes into account only knowledge which was within the level of ordinary skill at the time the claimed invention was made, and does not include knowledge gleaned only from the applicant's disclosure, such a reconstruction is proper. The examiner respectfully notes both Fawcett, see col. 8, lines 31-39, and May, see Abstract, involve, aggregation of data. Thus, the teaches of Fawcett and May can be combined to Wang as shown in the rejection below. Therefore, the examiner finds this argument not persuasive and/or moot in view of new grounds of rejection, i.e., see updated rejection below including May (US 2020/0304533 A1). Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claim(s) 1-20 is/are rejected under 35 U.S.C. 101 because the claimed invention is directed to abstract idea without significantly more. Step 1: claim(s) 1-20 are directed to a process, machine, and/or manufacture. Therefore, the claims are directed to statutory subject matter under Step 1 (Step 1: YES). See MPEP 2106.03. Prong 1, Step 2A: claim 1, and similar claim(s) 10 and 19, taken as representative, recites at least the following limitations that recite an abstract idea: A determining, , and wherein the compliance profile associates compliance checks with tags identifying corresponding layers in the edge computing network, and transmitting, by the number of processor units, the compliance scores determined in each layer in the layers upward to a top layer in the layers; aggregating, and determining, The above limitations, under their broadest reasonable interpretation, fall within the “Mental Processes” grouping of abstract ideas, enumerated in MPEP 2106.04(a)(2)(III), in that they recite as concepts performed in the human mind, including observations, evaluations, judgments, and opinions. That is, other than reciting for claim 1, and similar claim(s) 10 and 19, i.e., a number of processing units, agents... execute..., reducing amount of data transmitted through the edge computing network, and program product w/ computer readable storage medium; nothing in these claim element(s) precludes the step(s) from practically being performed in the mind. For example, the broadest reasonable interpretation of these limitations for claim 1, and similar claim(s) 10 and 19, includes determining compliance scores resulting from compliance checks performed at each layer in layers in an edge computing network for components for the application running in the layers, wherein the compliance checks performed at each layer are determined using a compliance profile identifying a set of the compliance checks for each component in the application, and wherein the compliance profile associates compliance checks with tags identifying corresponding layers in the edge computing network, and wherein agents at each layer selectively execute compliance checks associated with tags corresponding to the each layer; transmitting the compliance scores determined in each layer in the layers upward to a top layer in the layers; aggregating the compliance scores received from the components in a lower layer for transmission upward in the layers to the top layer as aggregated compliance scores; and determining the compliance for the application using an overall aggregate score determined at the top layer, which, encompass steps that a user can manually perform in the human mind or by a human using a pen and paper. If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components, then it falls within the “mental processes” grouping of abstract ideas. Additionally, with respect to claim(s) 4-5 and 13-14, these claim(s), under their broadest reasonable interpretation, fall within the “Mathematical Concepts” grouping of abstract ideas, enumerated in MPEP 2106.04(a)(2)(I), in that they recite mathematical formulas or equations (i.e., where a formula or equation is written in text format that should also be considered as falling within this grouping). Accordingly, these claims recite an abstract idea. (Prong 1, Step 2A: YES). The types of identified abstract ideas are considered together as a single abstract idea for analysis purposes. Prong 2, Step 2A: Limitations that are not indicative of integration into a practical application include: (1) Adding the words “apply it” (or an equivalent) with the judicial exception, or mere instructions to implement an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea (MPEP 2106.05(f)), (2) Adding insignificant extra-solution activity to the judicial exception (MPEP 2106.05(g)), (3) Generally linking the use of the judicial exception to a particular technological environment or field of use (MPEP 2106.05(h)). Claim 1, and similar claim(s) 10 and 19, recite i.e., a number of processing units, agents... execute..., reducing amount of data transmitted through the edge computing network, and program product w/ computer readable storage medium. These additional elements are described at a high level in Applicant’s specification without any meaningful detail about their structure or configuration. These elements in the steps are recited at a high-level of generality such that it amounts no more than mere instructions to apply the exception using a generic computer component and merely invoke such additional elements as a tool to perform the abstract idea. See MPEP 2106.05(f). Accordingly, these additional elements, even in combination, do not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. In addition, one could alternately note that “ ..., reducing amount of data transmitted through the edge computing network” is well understood, routing, and conventional as shown by Wang, [0037] - Data aggregation may provide various benefits for IoT systems such as, for example, reduced data transmission overhead, reduced data transmission latency, enhanced energy-efficiency, greener data transmissions, or the like. The claim is directed to an abstract idea. As such, under Prong 2 of Step 2A, when considered both individually and as a whole, the limitations of claim 1, and similar claim(s) 10 and 19 are not indicative of integration into a practical application (Prong 2, Step 2A: NO). See MPEP 2106.04(d). Since claim 1, and similar claim(s) 10 and 19 recites an abstract idea and fails to integrate the abstract idea into a practical application, claim 1, and similar claim(s) 10 and 19 is “directed to” an abstract idea under Step 2A (Step 2A: YES). See MPEP 2106.04(d). Step 2B: The recitation of the additional elements is acknowledged, as identified above with respect to Prong 2 of Step 2A. These additional elements do not add significantly more to the abstract idea for the same reasons as addressed above with respect to Prong 2 of Step 2A. The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception because, when considered separately and as an ordered combination, they do not add significantly more to the exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional elements of for claim 1, and similar claim(s) 10 and 19, i.e., a number of processing units, agents... execute..., reducing amount of data transmitted through the edge computing network, and program product w/ computer readable storage medium; thus, amounts to no more than mere instructions to apply the exception using a generic computer component and do not add anything that is not already present when they are considered individually or in combination. Mere instructions to apply an exception using a generic computer component cannot provide an inventive concept. Therefore, under Step 2B, there are no meaningful limitations in claim 1, and similar claim(s) 10 and 19 that transform the judicial exception into a patent eligible application such that the claims amount to significantly more than the judicial exception itself (Step 2B: NO). See MPEP 2106.05. Accordingly, under the Subject Matter Eligibility test, claim 1, and similar claim(s) 10 and 19 is ineligible. Regarding Claims 2-9, 11-18, and 20, claims 2-9, 11-18, and 20 further defines the abstract idea that is present in their respective independent claims and hence are abstract for at least the reasons presented above w/ respect to “Mental Processes” as the claims recite further concepts that can be performed in the human mind, including observations, evaluations, judgments, and opinions. These dependent claim does not include any additional elements that integrate the abstract idea into a practical application; as such elements are recited at a high level of generality such that it amounts not more than mere instructions to apply the exception using a generic computer component. Even in combination, these additional elements do not integrate the abstract idea into a practical application and do no not amount to significantly more than the abstract idea itself. Thus, the aforementioned claims are not patent-eligible. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1, 7-10 and 16-19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Wang et al. (US 20140359035 A1) in view of Fawcett et al. (US 10,484,429 B1) and May et al. (US 2020/0304533 A1). Regarding Claim 1; Wang discloses a computer implemented method for determining [message aggregation] of an application (FIG. 1 and [0034] - Application-Level Data Aggregation, which refers to the aggregation of application-level messages (e.g., request and/or response messages at the IoT service layer), the computer implemented method comprising: determining, by a number of processor units, [“message” data] at each layer in layers in an edge computing network for components for the application running in the layers, wherein the [“message” data]] at each layer are determined using [a request] ([0034] - Application-Level Data Aggregation, which refers to the aggregation of application-level messages (e.g., request and/or response messages at the IoT service layer [0035] - In an example of application-level data aggregation, and in particular in an example of message concatenation, messages that are sent or received by an application or service within a given IoT system may be combined with each other to reduce an overall message overhead in the given IoT system. In another example of application-level data aggregation, and in particular in an example of message reduction, one or more messages that are sent or received by an application or service within a given IoT system may be merged into other messages, removed from the IoT system, not forwarded within the IoT system, or otherwise discarded to reduce unnecessary messages within the IoT system and [0044]-[0045] - In accordance with the illustrated embodiment, during the second phase 114, the devices 106 transmit data upstream toward the gateway 108. In the example network 102, an upstream direction may refer to any path toward the gateway 108, and a downstream direction may refer to any path away from gateway 108. In accordance with the example system 100 illustrated in FIG. 1, some devices 106, for instance devices 106a, 106b, 106c, 106g, and 106h, are configured as intermediary nodes and thus may also be referred to as intermediary nodes 106a, 106b, 106c, 106g, and 106h, respectively), and wherein [a] “profile” associates “aggregation” with tags identifying corresponding layers in the edge computing network, and wherein agents at each layer selectively execute “aggregation” associated with tags corresponding to the each layer ([0043] - For example, the gateway 108 may request that a particular device only aggregate data from a specific physical region and [0045] - The intermediary nodes may aggregate their local data with forwarded data that they receive from downstream nodes. The intermediary nodes may aggregate data aggregation based on rules and policies, for example, specified in one or more DAREQ messages. In accordance with an example embodiment, an application protocol header is included in one or more data aggregation responses 118 that may be sent upstream from one device to a next hop. The header may indicate how data aggregation should be done. The header may further identify the data that should be aggregated. In accordance with the illustrated embodiment); transmitting, by the number of processor units, the [“message” data] determined in each layer in the layers upward to a top layer in the layers, wherein the aggregation of the [“message data”] reduce amount of data transmitted through the edge computing network; and (FIG. 1 and [0037] - Data aggregation may provide various benefits for IoT systems such as, for example, reduced data transmission overhead, reduced data transmission latency, enhanced energy-efficiency, greener data transmissions, or the like and [0045] - The intermediary nodes may aggregate their local data with forwarded data that they receive from downstream nodes... The header may indicate how data aggregation should be done. The header may further identify the data that should be aggregated. In accordance with the illustrated embodiment, the application protocol header may be included in a data aggregation response 118a that is sent from the device 106a to the gateway 108, a data aggregation response 118b that is sent from the device 106b to the device 106a, a data aggregation response 118c that is sent from the device 106c to the device 106a, a data aggregation response 118d that is sent from the device 106d to the device 106b, a data aggregation response 118e that is sent from the device 106e to the device 106b, and/or a data aggregation response 118f that is sent from the device 106f to the device 106c. Using the data aggregation requests 116 and response 118, the number of messages that are forwarded from the intermediary nodes to the gateway 108 may be reduced); aggregating, by the number of processor units, the [“message” data]] received from the components in a lower layer for transmission upward in the layers to the top layer as aggregated [“message” data]] ([0045] - The intermediary nodes may aggregate their local data with forwarded data that they receive from downstream nodes... The header may indicate how data aggregation should be done. The header may further identify the data that should be aggregated. In accordance with the illustrated embodiment, the application protocol header may be included in a data aggregation response 118a that is sent from the device 106a to the gateway 108, a data aggregation response 118b that is sent from the device 106b to the device 106a, a data aggregation response 118c that is sent from the device 106c to the device 106a, a data aggregation response 118d that is sent from the device 106d to the device 106b, a data aggregation response 118e that is sent from the device 106e to the device 106b, and/or a data aggregation response 118f that is sent from the device 106f to the device 106c. Using the data aggregation requests 116 and response 118, the number of messages that are forwarded from the intermediary nodes to the gateway 108 may be reduced); and determining, by the number of processor units, the [message aggregation] for the application using an overall aggregate [“message”] determined at the top layer ([0034] - Application-Level Data Aggregation, which refers to the aggregation of application-level messages (e.g., request and/or response messages at the IoT service layer) and [0045] - In accordance with the illustrated embodiment, the application protocol header may be included in a data aggregation response 118a that is sent from the device 106a to the gateway 108). Wang fails to explicitly disclose a computer implemented method for determining a compliance of an application, the computer implemented method comprising: determining... compliance scores resulting from compliance checks performed... for components for the application, wherein the compliance checks performed are determined using a compliance profile identifying a set of the compliance checks for each component in the application, wherein the compliance profile associates compliance checks with tags ..., and wherein agents at each layer selectively execute compliance checks associated with tags corresponding to the each layer; ... the compliance scores determined...; aggregating... the compliance scores ... as aggregated compliance scores... the aggregation of the compliance scores; and determining....the compliance for the application using an overall aggregate score... However, in an analogous art, Fawcett discloses a computer implemented method for determining a compliance of an application (Abstract), the computer implemented method comprising: determining... compliance scores resulting from compliance checks performed... for components for the application (col. 5, lines 44-46 - Risk scores may be determined for individual components of software applications and/or for an entire software application), wherein the compliance checks performed are determined using a compliance profile identifying a set of the compliance checks for each component in the application (col. 5, lines 15-18 and col. 6, lines 46-67 - Determinations may be made as to the type of data accessed by an application, whether the application has access to the type of data, and the reason why the application has access to the type of data); ... the compliance scores determined... (col. 8, lines 31-39 - At a fourth operation 188, the compliance verification application 124 may generate an aggregate risk score for the application. The aggregate risk score may be based at least in part on risk subscores for components of the application. For example, the compliance verification application 124 may determine an aggregate risk score for the content delivery application 122 based at least in part on respective risk subscores for a bidding component, a content selection component, and a targeting component); aggregating... the compliance scores ... as aggregated compliance scores.... the aggregation of the compliance scores (col. 8, lines 31-39 - At a fourth operation 188, the compliance verification application 124 may generate an aggregate risk score for the application. The aggregate risk score may be based at least in part on risk subscores for components of the application. For example, the compliance verification application 124 may determine an aggregate risk score for the content delivery application 122 based at least in part on respective risk subscores for a bidding component, a content selection component, and a targeting component); and determining... the compliance for the application using an overall aggregate score... (col. 8, lines 31-39 - At a fourth operation 188, the compliance verification application 124 may generate an aggregate risk score for the application. The aggregate risk score may be based at least in part on risk subscores for components of the application. For example, the compliance verification application 124 may determine an aggregate risk score for the content delivery application 122 based at least in part on respective risk subscores for a bidding component, a content selection component, and a targeting component and col. 10, lines 43-54 - ...compliance level of the software application is determined. For example, computer-executable instructions of one or more compliance verification module(s) stored at a remote server may be executed to determine the compliance level of the software application. A compliance level may be indicative of whether an application is fully compliant, partially compliant, or noncompliant. Compliance levels may be determined for components of software applications and/or aggregate compliance levels for software applications based at least in part on compliance determinations for components.). Therefore, it would have been obvious to one of ordinarily skill in the art before the effective filing date of the claimed invention to combine the teachings of Fawcett to the method of Wang to include a computer implemented method for determining a compliance of an application, the computer implemented method comprising: determining... compliance scores resulting from compliance checks performed... for components for the application, wherein the compliance checks performed are determined using a compliance profile identifying a set of the compliance checks for each component in the application; ... the compliance scores determined...; aggregating... the compliance scores ... as aggregated compliance scores; and determining....the compliance for the application using an overall aggregate score.... One would have been motivated to combine the teachings of Fawcett to Wang to do so as it provides / allows continuous or near-continuous (e.g., daily, etc.) verification of compliance for software applications, as opposed to the infrequent and non-scalable compliance verification provided by manual review (Fawcett, col. 2, lines 66-col. 3, lines 3). However, in an analogous art, May teaches wherein the compliance profile associates compliance checks with tags identifying “elements” in the edge computing network (Abstract, and [0038] - According to an aspect of the present disclosure, system 104 can build an internal network topology to determine network elements 110 that require a compliance report and can execute a collection of security checks on such network elements 110), and wherein agents at each layer selectively execute compliance checks associated with tags corresponding to “the element” ([0038] - .For execution of a collection of security checks, system 104 can request network element 110 for configuration data via the security fabric by assigning a unique authentication token with each request, which can be sent back by network element 110 to system 104 with the configuration data. In response to the request, system 104 can receive the configuration data of network element 110 pertaining to each security check of the collection of security checks via the security fabric). Therefore, it would have been obvious to one of ordinarily skill in the art before the effective filing date of the claimed invention to combine the teachings of May to the method of Wang and Fawcett to include wherein the compliance profile associates compliance checks with tags identifying “elements” in the edge computing network, and wherein agents at each layer selectively execute compliance checks associated with tags corresponding to “the element” One would have been motivated to combine the teachings of May to Wang and Fawcett to do so as it provides / allows monitoring of network elements associated with a network (e.g., network security devices of an enterprise network) to determine a security rating of each network element by taking in business level security, risk and compliance requirements, translating those requirements into technical configurations and conveying measurable and meaningful diagnostics on the current state and progress of their security (May, [0002]). Regarding Claim 7; Wang in view of Fawcett and May disclose the method to claim 1. Fawcett further teaches wherein the set of the compliance checks for each component is selected based on a set of attributes for each component (col. 8, lines 21-48 - The aggregate risk score may be based at least in part on risk subscores for components of the application. For example, the compliance verification application 124 may determine an aggregate risk score for the content delivery application 122 based at least in part on respective risk subscores for a bidding component, a content selection component, and a targeting component. The targeting component may have a relatively higher risk subscore since the targeting component may access user specific information, while the bidding component may have a relatively lower risk subscore as it may not access user specific information. The compliance verification application 124 may determine that the software code includes a compliance issue, and may determine a first risk score for the software code based at least in part on the data log 126). Similar rationale and motivation is noted for the combination of Fawcett to Wang in view of Fawcett and May, as per claim 1, above. Regarding Claim 8; Wang in view of Fawcett and May disclose the method to claim 1. Wang further comprising: determining, by the number of processor units, [message aggregation] performed at each layer in the layers in the edge computing network for the components for the application running in the layers ([0045]-[0046] - In an alternative embodiment, select intermediary nodes function as an application-protocol-layer proxy and perform data aggregation, while other intermediary nodes do not participate in data aggregation.); and transmitting, by the number of processor units, a set of the [message aggregation] determined in each layer in the layers upward to a top layer in the layers ([0045] - The intermediary nodes may aggregate their local data with forwarded data that they receive from downstream nodes... The header may indicate how data aggregation should be done. The header may further identify the data that should be aggregated. In accordance with the illustrated embodiment, the application protocol header may be included in a data aggregation response 118a that is sent from the device 106a to the gateway 108, a data aggregation response 118b that is sent from the device 106b to the device 106a, a data aggregation response 118c that is sent from the device 106c to the device 106a, a data aggregation response 118d that is sent from the device 106d to the device 106b, a data aggregation response 118e that is sent from the device 106e to the device 106b, and/or a data aggregation response 118f that is sent from the device 106f to the device 106c. Using the data aggregation requests 116 and response 118, the number of messages that are forwarded from the intermediary nodes to the gateway 108 may be reduced). Fawcett further teaches further comprising: determining...compliance statuses resulting from the compliance checks performed at ... for the components for the application... and /// a set of the compliance statuses determined... (col. 8, lines 21-48 - The aggregate risk score may be based at least in part on risk subscores for components of the application. For example, the compliance verification application 124 may determine an aggregate risk score for the content delivery application 122 based at least in part on respective risk subscores for a bidding component, a content selection component, and a targeting component. The targeting component may have a relatively higher risk subscore since the targeting component may access user specific information, while the bidding component may have a relatively lower risk subscore as it may not access user specific information. The compliance verification application 124 may determine that the software code includes a compliance issue, and may determine a first risk score for the software code based at least in part on the data log 126). Similar rationale and motivation is noted for the combination of Fawcett to Wang in view of Fawcett and May, as per claim 1, above. Regarding Claim 9; Wang in view of Fawcett and May disclose the method to claim 8. Wang further comprising: further comprising: aggregating, by the number of processor units, the [message data] from the components in a lower layer for transmission upward in the layers to the top layer as aggregated statuses ([0045] - The intermediary nodes may aggregate their local data with forwarded data that they receive from downstream nodes... The header may indicate how data aggregation should be done. The header may further identify the data that should be aggregated. In accordance with the illustrated embodiment, the application protocol header may be included in a data aggregation response 118a that is sent from the device 106a to the gateway 108, a data aggregation response 118b that is sent from the device 106b to the device 106a, a data aggregation response 118c that is sent from the device 106c to the device 106a, a data aggregation response 118d that is sent from the device 106d to the device 106b, a data aggregation response 118e that is sent from the device 106e to the device 106b, and/or a data aggregation response 118f that is sent from the device 106f to the device 106c. Using the data aggregation requests 116 and response 118, the number of messages that are forwarded from the intermediary nodes to the gateway 108 may be reduced). Fawcett further teaches ...the compliance statuses... (col. 8, lines 21-48 - The aggregate risk score may be based at least in part on risk subscores for components of the application. For example, the compliance verification application 124 may determine an aggregate risk score for the content delivery application 122 based at least in part on respective risk subscores for a bidding component, a content selection component, and a targeting component. The targeting component may have a relatively higher risk subscore since the targeting component may access user specific information, while the bidding component may have a relatively lower risk subscore as it may not access user specific information. The compliance verification application 124 may determine that the software code includes a compliance issue, and may determine a first risk score for the software code based at least in part on the data log 126). Similar rationale and motivation is noted for the combination of Fawcett to Wang in view of Fawcett and May, as per claim 1, above. Regarding Claim(s) 10 and 16-18; claim(s) 10 and 16-18 is/are directed to a/an system product associated with the method claimed in claim(s) 1 and 7-9. Claim(s) 10 and 16-18 is/are similar in scope to claim(s) 1 and 7-9, and is/are therefore rejected under similar rationale. Regarding Claim(s) 19; claim(s) 19 is/are directed to a/an program product associated with the method claimed in claim(s) 1. Claim(s) 19 is/are similar in scope to claim(s) 1, and is/are therefore rejected under similar rationale. Claim(s) 2, 11, and 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Wang et al. (US 20140359035 A1) in view of Fawcett et al. (US 10,484,429 B1) and May et al. (US 2020/0304533 A1) and further in view of Mannengal et al. (US 2023/0370452 A1). Regarding Claim 2; Wang in view of Fawcett and May disclose the method to claim 1. Wang further discloses ...[“message” data] transmission upward in the layers ([0034]-[0035]). Fawcett further teaches ...the compliance scores... (col. 5, lines 44-46 - Risk scores may be determined for individual components of software applications and/or for an entire software application). Similar rationale and motivation is noted for the combination of Fawcett to Wang in view of Fawcett, as per claim 1, above. Wang in view of Fawcett fail to explicitly disclose further comprising: encrypting, by the number of processor units, ... for transmission .... However, in an analogous art, Mannengal teaches further comprising: encrypting, by the number of processor units, ... for transmission ... ([0170]). Therefore, it would have been obvious to one of ordinarily skill in the art before the effective filing date of the claimed invention to combine the teachings of Mannengal to the method of Wang in view of Fawcett and May to include further comprising: encrypting, by the number of processor units, ... for transmission .... One would have been motivated to combine the teachings of Mannengal to Wang in view of Fawcett and May to do so as it provides / allows tracking both the network topology and the device characteristics [and] formulating a security recommendation (Mannengal, [0024]). Regarding Claim(s) 11; claim(s) 11 is/are directed to a/an system product associated with the method claimed in claim(s) 2. Claim(s) 11 is/are similar in scope to claim(s) 2, and is/are therefore rejected under similar rationale. Regarding Claim(s) 20; claim(s) 20 is/are directed to a/an program product associated with the method claimed in claim(s) 2. Claim(s) 20 is/are similar in scope to claim(s) 2, and is/are therefore rejected under similar rationale. Claim(s) 3 and 12 is/are rejected under 35 U.S.C. 103 as being unpatentable over Wang et al. (US 20140359035 A1) in view of Fawcett et al. (US 10,484,429 B1) and May et al. (US 2020/0304533 A1) and further in view of Ben-Yoseph et al. (US 7,472,163 B1). Regarding Claim 3; Wang in view of Fawcett and May disclose the method to claim 1. Fawcett further teaches wherein determining, by the processor units, the compliance scores comprises: compliance checks for the component. (col. 5, lines 44-46 - Risk scores may be determined for individual components of software applications and/or for an entire software application). Similar rationale and motivation is noted for the combination of Fawcett to Wang in view of Fawcett, as per claim 1, above. Wang in view of Fawcett and May fail to explicitly disclose wherein determining [a] compliance score comprises: dividing a number of successful compliance ... by a total number of the compliance .... However, in an analogous art, Ben-Yoseph teaches wherein determining [a] compliance score comprises: dividing a number of successful compliance ... by a total number of the compliance ... (col. 19, lines 44-col. 20, line 26 - For example, the bulk mail sender compliance may fall within an acceptable tolerance level if the bulk mail sender sends less than 8000 e-mails during the twenty four hour period OR if the bulk mail sender: (1) bounces less than 10% of the total e-mails sent (i.e., the total number of bounced e-mails divided by the total number of e-mails sent over the twenty four hour period must be less than 10%); (2) accepts more than 90% of the bounced e-mails (i.e., the total number of bounced e-mails successfully received by the bulk mail sender system 410 divided by the total number of bounced e-mails for the twenty four hour period must be greater than 90%); and (3) generates less than 100 complaints per million e-mails sent (i.e., the total number of complaints generated divided by the total number of e-mails sent in millions over the twenty four hour period must be less than 100). If the bulk mail sender sends more than 8000 e-mails and does not comply with one or more of the specified requirements over the twenty four hour period, the compliance of the bulk mail sender falls outside of the specified tolerance level). Therefore, it would have been obvious to one of ordinarily skill in the art before the effective filing date of the claimed invention to combine the teachings of Ben-Yoseph to the [a] compliance checks for the component of Wang in view of Fawcett and May to include wherein determining [a] compliance score comprises: dividing a number of successful compliance ... by a total number of the compliance ... One would have been motivated to combine the teachings of Ben-Yoseph to Wang in view of Fawcett and May to do so as it provides / allows to assess behavior over an interval in accordance to policy/tolerance (as gleaned, Ben-Yoseph, col. 19, lines 44-col. 20, line 26). Regarding Claim(s) 12; claim(s) 12 is/are directed to a/an system product associated with the method claimed in claim(s) 3. Claim(s) 12 is/are similar in scope to claim(s) 3, and is/are therefore rejected under similar rationale. Claim(s) 6 and 15 is/are rejected under 35 U.S.C. 103 as being unpatentable over Wang et al. (US 20140359035 A1) in view of Fawcett et al. (US 10,484,429 B1) and May et al. (US 2020/0304533 A1) and further in view of Bulut et al. (US 2021/0075814 A1). Regarding Claim 6; Wang in view of Fawcett and May disclose the method to claim 1. Wang further discloses wherein aggregating, by the processor units, the [message data] ([0034]-[0035]). Fawcett further teaches ...the compliance scores... (col. 5, lines 44-46 - Risk scores may be determined for individual components of software applications and/or for an entire software application). Similar rationale and motivation is noted for the combination of Fawcett to Wang in view of Fawcett, as per claim 1, above. Wang in view of Fawcett and May fail to explicitly disclose wherein aggregating, ...assigning, by the number of processor units, weights to a layer in the layers based on attributes of a set of the components in the layer. However, in an analogous art, Bulut teaches wherein aggregating, ...assigning, by the number of processor units, weights to a layer in the layers based on attributes of a set of the components in the layer ([0110] - In the examples described above, compliance process risk assessment system 102 (e.g., via metric assignment component 108 and/or risk assignment component 110) can thereby assign a risk score associated with each of assets 420 and/or groups of such assets 420. In another example, compliance process risk assessment system 102 (e.g., via metric assignment component 108 and/or risk assignment component 110) can assign a risk score associated with customer level 418 by calculating an average of all risk scores of assets 420 and/or groups of assets 420. In another example, compliance process risk assessment system 102 (e.g., via metric assignment component 108 and/or risk assignment component 110) can assign a risk score associated with customer level 418 by calculating a weighted average of all risk scores of assets 420 and/or groups of assets 420 based on one or more weights 422 (denoted W.sub.o, W.sub.p, W.sub.d in FIG. 4D) corresponding to assets 420 and/or groups of assets 420. In this example, compliance process risk assessment system 102 (e.g., via risk assignment component 110, manager component 208, and/or customer level 418) can generate a weight matrix 426 based on such weighted average of all risk scores of assets 420 and/or groups of assets 420 that can be calculated as described above). Therefore, it would have been obvious to one of ordinarily skill in the art before the effective filing date of the claimed invention to combine the teachings of Bulut to the aggregation of compliance scores of Wang in view of Fawcett and May to include wherein aggregating, ...assigning, by the number of processor units, weights to a layer in the layers based on attributes of a set of the components in the layer One would have been motivated to combine the teachings of Bulut Wang in view of Fawcett and May to do so as it provides / allows to assigning risk assessment metrics and a risk score to a compliance process (Bulut, [0001]). Regarding Claim(s) 15; claim(s) 15 is/are directed to a/an system product associated with the method claimed in claim(s) 6. Claim(s) 15 is/are similar in scope to claim(s) 6, and is/are therefore rejected under similar rationale. Reasons For No Prior Art Rejection Upon review of the evidence at hand, it is hereby concluded that the evidence obtained and made of record, alone or in combination, neither anticipates, reasonably teaches, nor renders obvious the below noted features of applicant’s invention as the noted features amount to more than a predictable use of elements in the prior art. Regarding Claim 4, the prior art of record as cited within this Office Action, nor those cited, in the additional references cited , alone or in combination, neither anticipates, reasonably teaches, nor renders obvious PNG media_image1.png 272 432 media_image1.png Greyscale Regarding Claim 5, the prior art of record as cited within this Office Action, nor those cited, in the additional references cited , alone or in combination, neither anticipates, reasonably teaches, nor renders obvious PNG media_image2.png 226 440 media_image2.png Greyscale Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to ASFAND M SHEIKH whose telephone number is (571)272-1466. The examiner can normally be reached Mon-Fri: 7a-3p (MDT). Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, JESSICA LEMIEUX can be reached at (571)270-3445. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /ASFAND M SHEIKH/Primary Examiner, Art Unit 3626
Read full office action

Prosecution Timeline

Show 1 earlier event
Jan 13, 2024
Response after Non-Final Action
May 19, 2026
Non-Final Rejection mailed — §101, §103
May 28, 2026
Interview Requested
Jun 10, 2026
Applicant Interview (Telephonic)
Jun 11, 2026
Examiner Interview Summary
Jun 11, 2026
Response Filed
Sep 04, 2026
Final Rejection mailed — §101, §103
Sep 29, 2026
Response after Non-Final Action

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12664599
SYSTEM AND METHOD FOR CAREER DEVELOPMENT
2y 8m to grant Granted Jun 23, 2026
Patent 12619950
AUTOMATED FOOD SELECTION USING HYPERSPECTRAL SENSING
2y 5m to grant Granted May 05, 2026
Patent 12614195
RETENTION MANAGEMENT SYSTEM
2y 6m to grant Granted Apr 28, 2026
Patent 12056682
TRANSACTION CHANGE BACK PROCESSING
3y 3m to grant Granted Aug 06, 2024
Patent 12051068
SYSTEM, METHOD, AND COMPUTER PROGRAM PRODUCT FOR REMOTE AUTHORIZATION OF PAYMENT TRANSACTIONS
2y 4m to grant Granted Jul 30, 2024
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
46%
Grant Probability
94%
With Interview (+48.3%)
4y 5m (~11m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 568 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month