Prosecution Insights
Last updated: August 17, 2026
Application No. 18/420,645

ANALYTICS-DEFINED PERIMETERS FOR ZERO TRUST ARCHITECTURES

Non-Final OA §103
Filed
Jan 23, 2024
Examiner
LE, CANH
Art Unit
2439
Tech Center
2400 — Computer Networks
Assignee
Dell Products L.P.
OA Round
3 (Non-Final)
73%
Grant Probability
Favorable
3-4
OA Rounds
1y 2m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 73% — above average
73%
Career Allowance Rate
310 granted / 423 resolved
+15.3% vs TC avg
Strong +72% interview lift
Without
With
+72.4%
Interview Lift
resolved cases with interview
Typical timeline
3y 9m
Avg Prosecution
19 currently pending
Career history
452
Total Applications
across all art units

Statute-Specific Performance

§101
13.5%
-26.5% vs TC avg
§103
56.1%
+16.1% vs TC avg
§102
9.3%
-30.7% vs TC avg
§112
13.7%
-26.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 423 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant’s submission filed on 03/06/2026 has been entered. This Office Action is in response to the amendment filed on 03/16/2026; claims 1 and 11 have been amended; claims 8-9 and 18-19 have been canceled; claims 1 and 11 are independent claims. Claims 1-7, 10-17, and 20-21 have been examined and are pending. This Action is made Non-FINAL. Response to Arguments Applicants’ arguments with respect to the amended limitations “maintaining a network state representation of the IT infrastructure, the network state representation modeling entities and relationships between the entities as a structural configuration of the IT infrastructure based on the telemetry data;” , “wherein the ADP defines a segmentation boundary within the network state representation that partitions the modeled entities into at least a first segment and a second segment based on analytics performed over the network state representation, and wherein a perimeter crossing corresponds to a change in a structural relationship or segment membership of an entity within the network state representation;” , and “ based on the segmentation boundary defined in the network state representation and prior to application of a policy enforcement rule, “ have been fully considered but are moot in view of the new ground(s) of rejection. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-7, 10-17, and 20-21 are rejected under 35 U.S.C. 103 as being unpatentable over Sharda et al. (“Sharda,” US 2024/0356950, filed on Aug. 24, 2023) in view of Kaciulis et al. (“Kaciulis,” US 2024/0154980, filed on Nov. 9, 2022), further in view of Woolward (“Woolward,” US 9,560,081) Regarding claim 1, Sharda teaches a method comprising: collecting telemetry data concerning an activity occurring in an information technology (IT) infrastructure (Sharda: par. 0025, The agent operates in the background, continuously collecting endpoint telemetry data and sending it to a central management console and/or the Extended detection & Response (XDR) system 104; par. 0003, XDR platforms integrate data from the entire information technology (IT) infrastructure of a computing system to provide unified visibility and automated actions against cyberattacks); updating an activity database with the telemetry data (Sharda: par. 0034, Data lake 106 may receive the monitoring events retrospectively (e.g., asynchronously) and/or synchronously (e.g., in real-time) from the monitoring components 102, storing them in a structured or semi-structured format for efficient retrieval and analysis. Data lake 106 may be implemented using a database, data warehouse, and/or cloud storage); applying a rule to determine if the activity is associated with a crossing of an analytics-defined perimeter (ADP) within the IT infrastructure (Sharda: par. 0026, Heuristic analy-sis involves applying predefined rules and behavioral models to detect unknown or emerging threats. In some cases, the IDS/IPS 102B performs at least one of an IDS or an IPS functionality. The IDS functionality may identify suspicious or anomalous network behaviors, such as port scans, unusual data transfer patterns, or unauthorized access attempts); when a perimeter crossing has been determined to have occurred, applying a policy to determine whether, and what, action should be taken with respect to the perimeter crossing (Sharda: par. 0046, In some cases, when the cross-domain analytics component 108 identifies a security incident, the incident response component 110 is triggered to initiate appropriate responses. These responses may be automated, where pre-defined response actions are executed based on predefined playbooks and policies, or manual, where security analysts are involved in making informed decisions on response actions based on the severity and nature of the incident); and implementing an action with respect to an entity whose activity is being evaluated when the perimeter crossing is determined to be contrary to the policy (Sharda: par. 0026, … IPS functionality may take immediate action to block or prevent identified threats from progressing further into the network; par. 0046, the incident response com-ponent 110 may take automated actions to block or blacklist malicious IP addresses or domains associated with the detected threats), wherein the action comprises restricting or facilitating prevention of the entity from engaging in the activity outside of the perimeter (Sharda: par. 0026, … IPS functionality may take immediate action to block or prevent identified threats from progressing further into the network; par. 0046, the incident response com-ponent 110 may take automated actions to block or blacklist malicious IP addresses or domains associated with the detected threats). Sharda applying a rule to determine if the activity is associated with a crossing of an analytics-defined perimeter (ADP) within the IT infrastructure but does not explicitly teach wherein the ADP is dynamically defined and modifiable as conditions within the IT infrastructure change, and wherein the conditions are determined from the telemetry data such that the ADP changes based on telemetry data. However, in an analogous art, Kaciulis discloses wherein the ADP is dynamically defined and modifiable as conditions within the IT infrastructure change (Kaciulis: par. 0080, The processor may refer to the first set of dynamically modifiable rules for guidance on how to deal with the anomaly. In one case, the first set of dynamically modifiable rules may provide an indication on how to analyze the data activity and determine if the data activity is harmless or is occurring as a result of malicious activity. The first set of dynamically modifiable rules may, for example, provide security-related guidance on how to detect a code pattern and/or a signature that indicates malicious intent and may also provide information about various malicious code patterns and/or signatures. In another case, the processor may use one or more sets of existing rules to dynamically generate one or more new sets of rules. In an example embodiment, the processor may generate a new set of rules based on applying, for example, machine learning or artificial intelligence, on one or more sets of existing rules. The new set or sets of rules may for example, be applied for malware detection. The dynamic generation of new rules in this manner may be particularly advantageous in dealing with malware that keeps changing, evolving, and transforming at a rapid rate.), and wherein the conditions are determined from the telemetry data such that the ADP changes based on the telemetry data (Kaciulis: par. 0080); Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Kaciulis with the method and system of Sharda to include wherein the ADP is dynamically defined and modifiable as conditions within the IT infrastructure change, and wherein the conditions are determined from the telemetry data such that the ADP changes based on the telemetry data. One would have been motivated to provide directing the rules applicable to data access at procedures related to retrieving, modifying, copying, or moving data between various computing devices in a reliable and secure manner (Kaciulis: par. 0029). The combination of Sharda and Kaciulis teaches updating an activity database with the telemetry data; applying a rule to determine if the activity is associated with a crossing of an analytics- defined perimeter (ADP) within the IT infrastructure, wherein the ADP is dynamically defined and modifiable as conditions within the IT infrastructure change, and wherein the conditions are determined from the telemetry data such that the ADP changes based on telemetry data, when a perimeter crossing has been determined to have occurred, applying a policy to determine whether, and what, action should be taken with respect to the perimeter crossing as recited above but does not explicitly disclose “to maintain a network state representation of the IT infrastructure, the network state representation modeling entities and relationships between the entities as a structural configuration of the IT infrastructure based on the telemetry data;” “wherein the ADP defines a segmentation boundary within the network state representation that partitions the modeled entities into at least a first segment and a second segment based on analytics performed over the network state representation, and wherein a perimeter crossing corresponds to a change in a structural relationship or segment membership of an entity within the network state representation;” “based on the segmentation boundary defined in the network state representation and prior to application of a policy enforcement rule, respectively. However, in an analogous art, Woolward discloses to maintain a network state representation of the IT infrastructure, the network state representation modeling entities and relationships between the entities as a structural configuration of the IT infrastructure based on the telemetry data (Woolward: Col. 11, lines 40-50, intent-driven model which defines groups of bare metal servers .. (e.g., physical hosts 1601 .1-160x,y (FIG. 1)), VMs (e.g, ofVMs 2601-260v (FIG. 2)), and containers (e.g., of containers 3401-3402 (FIG. 3) and 3401 1-340wz (FIG. 4)), and describes permitted connectivity, security, and network services between groups.; Col. 10, lines 28-50, As shown in FIG. 8, entities in Group B can be disposed throughout network entities 800 without limitation. For example, entities in Group B need not be limited to entities connected to the same network server, running on the same VM, running in the same physical server, running in physical servers in the same rack, running in the same data center, and the like.; Col. 10, lines 66-67, “analytics 630 analyze log 640 for malicious behave, and the like; abstract, metadata associated with containers); wherein the ADP defines a segmentation boundary within the network state representation that partitions the modeled entities into at least a first segment and a second segment based on analytics performed over the network state representation (Woolward: abstract: Col. 11, lines 40-50, At step 720, metadata is received. For example, security 40 director 610 (FIG. 6) received metadata from orchestration layer 410 (FIG. 4). At step 730, a (high-level) declarative security policy is received. As explained above with respect to FIG. 4, the high-level declarative security policy is an intent-driven model which defines groups of bare metal servers (e.g., physical hosts 1601 .1-160x,y (FIG. 1)), VMs (e.g, ofVMs 2601-260v (FIG. 2)), and containers (e.g., of containers 3401-3402 (FIG. 3) and 3401 1-340wz (FIG. 4)), and describes permitted connectivity, security, and network services between groups. Since the declarative security policy is at a high level of abstraction (e.g., compared to a firewall rule set), rules between each and every single entity in a network are not needed ( or desired). Instead, a statement/model in the high-level declarative security policy can be applicable to several entities in the network (e.g., in a group); See also fig. 8, Col. 10, lines 28-50, The network entities 800 are associated with Group A (denoted by "A") or Group B (denoted by "B"). Communications between Group A and Group B are more restricted ( e.g., for security reasons) and communications within Group B are less restricted ( e.g., for business purposes). As shown in FIG. 8, entities in Group B can be disposed throughout network entities 800 without limitation. For example, entities in Group B need not be limited to entities connected to the same network server, running on the same VM, running in the same physical server, running in physical servers in the same rack, running in the same data center, and the like. Communication between Group A and Group B, and communication within Group B can still be controlled, regardless of where entities associated with Group B are disposed.; Col. 10, lines 66-67, “analytics 630 analyze log 640 for malicious behave, and the like; abstract, metadata associated with containers), and wherein a perimeter crossing corresponds to a change in a structural relationship or segment membership of an entity within the network state representation (Woolward: Col. 11, lines 40-50, intent-driven model which defines groups of bare metal servers …and describes permitted connectivity, security, and network services between groups). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Woolward the method and system of Sharda and Kaciulis to include “to maintain a network state representation of the IT infrastructure, the network state representation modeling entities and relationships between the entities as a structural configuration of the IT infrastructure based on the telemetry data;” “wherein the ADP defines a segmentation boundary within the network state representation that partitions the modeled entities into at least a first segment and a second segment based on analytics performed over the network state representation, and wherein a perimeter crossing corresponds to a change in a structural relationship or segment membership of an entity within the network state representation; when a perimeter crossing has been determined to have occurred based on the segmentation boundary defined in the network state representation and prior to application of a policy enforcement rule, applying a policy to determine whether, and what, action should be taken with respect to the perimeter crossing One would have been motivated to utilize a high-level declarative security policy in order to manage network-security complexity and automatically generate lower-level firewall rules (Woolward: Col. 2, line 63 to Col. 3, line 3). Regarding claim 2, the combination of Sharda, Kaciulis, and Woolward teaches the method as recited in claim 1. The combination of Sharda, Kaciulis, and Woolward further teaches, wherein the ADP crossing is verified directly through the policy (Sharda: par. 0044, In some cases, the predictive models 114 include an incident model that determines ( e.g., based on alert features generated by the alert model) whether each alert is an incident as determined based on predefined incident definition criteria; Woolward; abstract; Col. 11, lines 40-50). Regarding claim 3, the combination of Sharda, Kaciulis, and Woolward teaches the method as recited in claim 1. The combination of Sharda, Kaciulis, and Woolward further teaches, wherein the perimeter defines a segment of the IT infrastructure (Sharda: par. 0003, monitoring data from different security domains associated with different monitoring components; processes events across heterogeneous monitoring components 102 to uncover attacks spanning multiple monitoring domains; Woolward; abstract; Col. 11, lines 40-50). Regarding claim 4, the combination of Sharda, Kaciulis, and Woolward teaches the method as recited in claim 1. The combination of Sharda, Kaciulis, and Woolward further teaches wherein the ADP is defined without use of direct intervention in the IT infrastructure (Woolward: Col. 2, line 63 - Col. 3, line 3., Some embodiments of the present technology may autonomically generate a reliable declarative security policy at a high level of abstraction. Abstraction is a technique for managing complexity by establishing a level of complexity which suppresses the more complex details below the current level. The high-level declarative policy may be compiled to produce a firewall rule set at a low level of abstraction.). Regarding claim 5, the combination of Sharda, Kaciulis, and Woolward teaches the method as recited in claim 1. The combination of Sharda, Kaciulis, and Woolward further teaches wherein the ADP determines a conditional access authorization for the entity based on a network state representation (Woolward: Col. 11, lines 40-50, intent-driven model which defines groups of bare metal servers …and describes permitted connectivity, security, and network services between groups). Regarding claim 6, the combination of Sharda, Kaciulis, and Woolward teaches the method as recited in claim 1. The combination of Sharda, Kaciulis, and Woolward further teaches wherein the ADP is defined without use of a policy enforcement point (PEP) (Sharda: pars. 0026, 0046; Woolward: Col. 2, line 63 - Col. 3, line 3., Some embodiments of the present technology may autonomically generate a reliable declarative security policy at a high level of abstraction. Abstraction is a technique for managing complexity by establishing a level of complexity which suppresses the more complex details below the current level. The high-level declarative policy may be compiled to produce a firewall rule set at a low level of abstraction; Woolward: Col. 11, lines 40-50, intent-driven model which defines groups of bare metal servers …and describes permitted connectivity, security, and network services between groups; Col. 10, lines 41-14, a low-level firewall rule set is used by enforcement point 250 to determine when the high-level security policy is (possibly) violated). Regarding claim 7, the combination of Sharda, Kaciulis, and Woolward teaches the method as recited in claim 1. The combination of Sharda, Kaciulis, and Woolward further teaches, wherein the rule and policy are represented as data in a database (Woolward: Col. 10, lines 4-14, According to some embodiments, a low-level firewall rule set is used by enforcement point 250 to determine when the high-level security policy is (possibly) violated. For example, a database (e.g., in a container of containers 3401 1-340wz) serving web pages using the Hypertext Transfer Protocol (HTTP) and/or communicating with external networks (e.g., network 110 of FIG. 1) could violate a high-level declarative security policy for that database container. In various embodiments, enforcement point 250 is an enforcement point (e.g., in a container of containers 3401 1 -340 wz; Col. 11, lines 40-50, intent-driven model which defines groups of bare metal servers .., and describes permitted connectivity, security, and network services between groups). Regarding claim 10, the combination of Sharda, Kaciulis, and Woolward teaches the method as recited in claim 1 The the combination of Sharda, Kaciulis, and Woolward further teaches, wherein the action is implemented by a policy enforcement point (PEP) (Sharda: pars. 0026, 0046; Woolward: Col. 10, lines 4-14, a low-level firewall rule set is used by enforcement point 250 to determine when the high-level security policy is (possibly) violated. For example, a database (e.g., in a container of containers 3401 1-340wz) serving web pages using the HypertextTransfer Protocol (HTTP) and/or communicating with external networks (e.g., network 110 of FIG. 1) could violate a high-level declarative security policy for that database container. In various embodiments, enforcement point 250 is an enforcement point (e.g., in a container of containers 3401 1 -340 wz;). Regarding claim 11, claim 11 is directed to a non-transitory storage medium (Sharda: pars. 0081, 0085) having stored therein instructions that are executable by one or more hardware processors (Sharda: par. 0077) to perform operations associated with the method claimed in claim 1; claim 11 is similar in scope to claim1, and is therefore rejected under similar rationale. Regarding claim 12, claim 12 is similar in scope to claim 2, and is therefore rejected under similar rationale. Regarding claim 13, claim 13 is similar in scope to claim 3, and is therefore rejected under similar rationale. Regarding claim 14, claim 14 is similar in scope to claim 4, and is therefore rejected under similar rationale. Regarding claim 15, claim 15 is similar in scope to claim 5, and is therefore rejected under similar rationale. Regarding claim 16, claim 16 is similar in scope to claim 6, and is therefore rejected under similar rationale. Regarding claim 17, claim 17 is similar in scope to claim 7, and is therefore rejected under similar rationale. Regarding claim 20, claim 20 is similar in scope to claim 10, and is therefore rejected under similar rationale. Regarding claim 21, the combination of Sharda, Kaciulis, and Woolward teaches the method as recited in claim 1. The combination of Sharda, Kaciulis, and Woolward further teaches wherein the ADP is defined as a part of the policy (Woolward: abstract: Col. 11, lines 40-50, At step 720, metadata is received. For example, security 40 director 610 (FIG. 6) received metadata from orchestration layer 410 (FIG. 4). At step 730, a (high-level) declarative security policy is received. As explained above with respect to FIG. 4, the high-level declarative security policy is an intent-driven model which defines groups of bare metal servers… , and describes permitted connectivity, security, and network services between groups) Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to CANH LE whose telephone number is (571)270-1380. The examiner can normally be reached on Monday to Friday 6:00AM to 3:30PM other Friday off. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Luu Pham, can be reached at telephone number 571-270-5002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from Patent Center and the Private Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from Patent Center or Private PAIR. Status information for unpublished applications is available through Patent Center and Private PAIR for authorized users only. Should you have questions about access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) Form at https://www.uspto.gov/patents/uspto-automated- interview-request-air-form. /Canh Le/ Examiner, Art Unit 2439 May 14th, 2026 /LUU T PHAM/Supervisory Patent Examiner, Art Unit 2439
Read full office action

Prosecution Timeline

Jan 23, 2024
Application Filed
Jul 08, 2025
Non-Final Rejection mailed — §103
Oct 08, 2025
Response Filed
Dec 17, 2025
Final Rejection mailed — §103
Mar 16, 2026
Request for Continued Examination
Apr 04, 2026
Response after Non-Final Action
May 26, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12683779
CALCULATION SYSTEM, CALCULATION METHOD, AND INFORMATION STORAGE MEDIUM
3y 2m to grant Granted Jul 14, 2026
Patent 12683971
MONITORING APPARATUS AND CONTROL METHOD THEREOF
2y 8m to grant Granted Jul 14, 2026
Patent 12626227
DYNAMIC MEETING SPACE CONFIGURATION BASED ON CONTENT
3y 1m to grant Granted May 12, 2026
Patent 12627651
SECURE PASSWORD LESS CRITICAL COMPUTING INFRASTRUCTURE ACCESS COMMUNICATION NETWORK PROTOCOL
2y 2m to grant Granted May 12, 2026
Patent 12621301
SCALABLE ARCHITECTURE OF SERVERS PROVIDING ACCESS TO DATA CONTENT
5y 4m to grant Granted May 05, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
73%
Grant Probability
99%
With Interview (+72.4%)
3y 9m (~1y 2m remaining)
Median Time to Grant
High
PTA Risk
Based on 423 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month