Prosecution Insights
Last updated: October 02, 2026
Application No. 18/307,244

NATIVE DATABASE TENANT LIFECYCLE MANAGEMENT

Final Rejection §103§112
Filed
Apr 26, 2023
Examiner
LOUIE, OSCAR A
Art Unit
2445
Tech Center
2400 — Computer Networks
Assignee
SAP SE
OA Round
2 (Final)
65%
Grant Probability
Moderate
3-4
OA Rounds
11m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 65% of resolved cases
65%
Career Allowance Rate
150 granted / 231 resolved
+6.9% vs TC avg
Strong +34% interview lift
Without
With
+33.7%
Interview Lift
resolved cases with interview
Typical timeline
4y 4m
Avg Prosecution
5 currently pending
Career history
239
Total Applications
across all art units

Statute-Specific Performance

§101
16.8%
-23.2% vs TC avg
§103
49.6%
+9.6% vs TC avg
§102
16.0%
-24.0% vs TC avg
§112
15.9%
-24.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 231 resolved cases

Office Action

§103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Arguments Applicant’s arguments with respect to the prior art rejections made under 35 U.S.C. 103 for claim(s) 1-18 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. Applicant’s arguments, see page 10, filed 09/24/2026, with respect to the claim objections of claims 2-6, 8-12, and 14-18 have been fully considered and are persuasive. The claim objections of claims 2-6, 8-12, and 14-18 have been withdrawn. Allowable Subject Matter Claims 2-4, 6, 8-10, 12, 14-16 and 18 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 1-18 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claims 1, 7, 13 recite “...retrieving by the operator of credentials of a tenant manager user...”, however, it is unclear what is being retrieved. That is, is the retrieval performed by the operator for credentials or is the retrieval performed by an operator of credentials of a tenant manager user from a storage external to the database platform for some other data? Additionally, “...operator...” is unclear as to its functional significance in the claimed method, machine, and article of manufacture. That is, it is unclear what the functional relationship is between the operator and the database instance. From the current claim language, it appears the operator is part of the database platform, but so is the database instance. Is there more significance to the operator than just being some part of the database platform that handles access to database instances using credentials retrieved from an external identity management service/system for a given tenant? It is also unclear whether the “operator” is a part of the database platform or if it is intended as a separate entity which acts as a connecting proxy for authenticated access to database instances. That is, while the claim captures that the operator executes on the database platform, why would the operator need credentials to connect to database instances within the database platform if it is a part of the database platform itself? For the purposes of claim interpretation and construction for the prior art rejections below, this limitation has been read as “in response to the determination, retrieving by the operator (a component of the database system), credentials of a tenant manager user (user/tenant credentials for creating/modifying/accessing a tenant), from a storage external to the database platform (separate authentication/credentials service)”. The operator has been read as a component of the database platform that handles user/tenant access requests to database instances where some authentication occurs using retrieved credentials from an external identity management system for database instance access control on a per tenant basis. The authenticated access then allows the operator to act as a connection relay between the user/tenant and the database platform for access to each database instance that each user/tenant is authorized access to. Examiner notes that applicants’ Figure 3 illustrates with the associated paragraphs 39-43 of the specification describes what applicants appear to have intended to capture more clearly. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claim(s) 1, 7, and 13 are rejected under 35 U.S.C. 103 as being unpatentable over Jhaveri et al. (US 20230409723 A1) in view of Durand et al. (US 20230177201 A1). Claims 1, 7, and 13: Jhaveri et al. teach a computer-implemented method, a database platform comprising: a memory storing executable program code; and at least one processing unit to execute the program code to cause the database platform to, and a non-transitory computer-readable medium storing executable program code, the program code executable to cause a system to, receiving a call to an application programming interface, the call comprising a request to create a database tenant in a database instance executing on a database platform (“...Using the API 230 and the dashboard 210, the users may then send instructions to the database engine 205 and receive information back from the database engine...”) [para 58]; and in response to the received call: determining, at an operator executing on the database platform, to create the tenant (“...creating tenancies within the database system...creating, by the database tenant management system 220, a first tenant entity associated with the first user and the organization entity...”) [para 77]; and transmitting, from the operator to the database instance, a...command to create the tenant and in response to the command, create the tenant in the database instance (“...creating tenancies within the database system...receiving, at the database tenant management system 220, a first subscription request associated with a first user entity associated with an organization entity on the database system 200...”) [para 77]; But, Jhaveri et al. do not teach, in response to the determination, retrieving by the operator of credentials of a tenant manager user from a storage external to the database platform connecting the operator to the database instance using the credentials a Structured Query Language command However, Durand et al. do teach, in response to the determination, retrieving by the operator of credentials of a tenant manager user from a storage external to the database platform connecting the operator to the database instance using the credentials (“...database management system (DBMS) may refer to software that interacts with the underlying database itself...the authorization interceptor determines the tenant who is making the database request and then is able to either apply the security policy for the specific tenant...”) [para 90] (“...The authentication service 1616 may be a stand-alone service or may be part of a service provider or other entity...Upon successful authentication of a request, the authentication service 1616 may then obtain policies applicable to the request. A policy may be applicable to the request by way of being associated with the principal 1602, a resource to be accessed as part of fulfillment of the request, a group in which the principal 1602 is a member, a role the principal 1602 has assumed, and/or otherwise...”) [paras 203-204]; a Structured Query Language command (“...SQL...”) [para 91]; Therefore, it would have been obvious to one of ordinary skill in the art at the time of applicants’ filed invention to incorporate the teachings of Durand et al. into that of Jhaveri et al. in order to provide authentication credentials from a separate source/service via common database protocols like SQL. Authentication services may be provided by either local or remote entities as taught by Durand. When the authentication services are provided by a remote entity, the retrieved authentication credentials would be from an external source. SQL is a common query language of choice for many multi-tenant database systems and would therefore be an obvious choice for usage in communicating with and within a multi-tenant database. The reliance on a separate authentication credentials service provides greater security for ensuring users/tenants may only access the database instances they are authorized for based on the security policies set for their credentials. Claim(s) 5, 11, and 17 are rejected under 35 U.S.C. 103 as being unpatentable over Jhaveri et al. (US 20230409723 A1) in view of Durand et al. (US 20230177201 A1) in view of Li et al. (US 20130218911 A1). Claims 5, 11, and 17: Jhaveri et al. and Durand et al. teach a computer-implemented method, a database platform comprising: a memory storing executable program code; and at least one processing unit to execute the program code to cause the database platform to, and a non-transitory computer-readable medium storing executable program code, the program code executable to cause a system to, as in claims 1, 7, and 13 above, where Durand et al. further teach, wherein the call includes authorization information presenting the authorization information to the database instance (“...The request for access to the service 1608 may be a digitally signed request and, as a result, may be provided with a digital signature...public key specified to be used in authentication of requests...”) [Durand et al. paras 203, 206]; but do not explicitly teach, receiving a user from the database instance in response to the authorization information and transmitting, from the operator to the database instance, a second Structured Query Language command to assign the user a right to assign artifacts to the tenant However, Li et al. do teach, receiving a user from the database instance in response to the authorization information (“...enforcement of security profiles in a multi-tenant database...the set of clients 102 and/or other devices, platforms, services, and/or user portals which is initiating access to the data service 110 can first interact with an authentication service 108...receipt of a user name, password, and/or other credentials from the user. After receiving positive authentication results from the multi-tenant database 108, the user of the set of clients 102 and/or other devices, platforms, services, and/or user portals can be connected to, and/or permitted to access, the data service 110 for purposes of data access, retrieval, updating, and/or other data manipulation or activities...generate a mapping between the current user session and the set of permissions 120, for instance by interacting with the meta-data security engine 114 and/or other security application, platform, and/or service...”) [paras 11, 14, 19-20, 24]; and transmitting, from the operator to the database instance, a second Structured Query Language command to assign the user a right to assign artifacts to the tenant (“...a SQL database...a SQL and/or other request, command, and/or instructions can be generated via the data service 110, reproducing and/or based on the user's original query 116. In 214, the SQL and/or other request, command, and/or instructions generated by the data service 110 can be received in the data entity model 112 and/or other published or exposed model, schema, and/or configuration for purposes of interrogating the set of tables 122 and/or other data structures of the multi-tenant database 108. In 216, the multi-tenant database 108 can be interrogated based on the SQL and/or other request, command, and/or instructions based on or corresponding to the query 116...”) [paras 11, 20]; Therefore, it would have been obvious to one of ordinary skill in the art at the time of applicants’ filed invention to incorporate the teachings of Li et al. into that of Jhaveri et al. and Durand et al. in order to provide more refined access control to the multi-tenant database through the usage of security profiles and associated security policies/rules. The teachings of Li et al. extend the capabilities of the combined teachings of Jhaveri et al. and Durand et al. through the use of user/tenant specific security profiles tied to a security association that is made as a result of the authentication process. The combination of Jhaveri et al. and Durand et al. provides for a multi-tenant database access control system that utilizes authentication that is reliant on a separate entity for authorization, but do not provide details for the enforcement and management of the level of access or permissions, whereas Li et al. provides a framework for a table/list based permissions enforcement for multi-tenant systems like those of Jhaveri et al. and Durand et al. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to Oscar Louie whose telephone number is (571) 270-1684 and E-mail address is OSCAR.LOUIE@USPTO.GOV. Note that a form SB-439 must be on file in order to conduct correspondence by E-mail, however, E-mail may be utilized to arrange time(s) for interview(s) without the SB-439 form. The examiner can normally be reached on Monday through Thursday between 05:30AM-03:30 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /OSCAR A LOUIE/Supervisory Patent Examiner, Art Unit 2445
Read full office action

Prosecution Timeline

Apr 26, 2023
Application Filed
Jun 24, 2025
Non-Final Rejection mailed — §103, §112
Aug 24, 2025
Interview Requested
Sep 03, 2025
Applicant Interview (Telephonic)
Sep 03, 2025
Examiner Interview Summary
Sep 24, 2025
Response Filed
Sep 09, 2026
Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12737475
MULTI-GRANULAR ELASTIC TRUST LABELING FRAMEWORK FOR SOFTWARE DELIVERY
3y 2m to grant Granted Sep 15, 2026
Patent 12712817
ADAPTING TCP IN VARIABLE JITTER ENVIRONMENTS
4y 8m to grant Granted Aug 18, 2026
Patent 12706889
SECURING COLLECTION OF INFORMATION OF TENANT CONTAINER
2y 4m to grant Granted Aug 11, 2026
Patent 12580870
TRANSMISSION DEVICE, TRANSMISSION METHOD, RECEPTION DEVICE, AND RECEPTION METHOD
2y 1m to grant Granted Mar 17, 2026
Patent 12488117
SYSTEMS AND METHODS FOR DETERMINING CURRENT RISK OF CYBERSECURITY VULNERABILITIES
1y 6m to grant Granted Dec 02, 2025
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
65%
Grant Probability
99%
With Interview (+33.7%)
4y 4m (~11m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 231 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month