Prosecution Insights
Last updated: October 04, 2026
Application No. 18/426,614

R-GRAPH PROPAGATION OF DATA PROTECTION AND COMPLIANCE STATUSES

Non-Final OA §101§103
Filed
Jan 30, 2024
Priority
Jan 31, 2023 — provisional 63/442,139
Examiner
FARROW, FELICIA
Art Unit
2437
Tech Center
2400 — Computer Networks
Assignee
Hycu Inc.
OA Round
3 (Non-Final)
59%
Grant Probability
Moderate
3-4
OA Rounds
3m
Est. Remaining
94%
With Interview

Examiner Intelligence

Grants 59% of resolved cases
59%
Career Allowance Rate
160 granted / 273 resolved
+0.6% vs TC avg
Strong +36% interview lift
Without
With
+35.6%
Interview Lift
resolved cases with interview
Typical timeline
2y 11m
Avg Prosecution
34 currently pending
Career history
308
Total Applications
across all art units

Statute-Specific Performance

§101
7.5%
-32.5% vs TC avg
§103
61.0%
+21.0% vs TC avg
§102
7.8%
-32.2% vs TC avg
§112
18.6%
-21.4% vs TC avg
Black line = Tech Center average estimate • Based on career data from 273 resolved cases

Office Action

§101 §103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 26 May 2026 has been entered. Applicant amended claims 1, 4, and 7. Applicant canceled claims 10-11. Accordingly, claims 1-9 and 12 remain pending. Response to Amendment Applicant’s amendment to the abstract overcomes the abstract objection of 23 February 2026. Therefore, the abstract objection of 23 February 2023 is withdrawn. Applicant’s cancellation of claims 10-11 results in the 35 USC 112(a) rejection to be moot. Response to Arguments 35 USC 101 rejection: Applicant's arguments filed 26 May 2026 have been fully considered but they are not persuasive. Applicant’s remarks: Claim 1 is not directed merely to "assessing compliance" or "organizing information." Claim 1 now specifically recites a computer-implemented data-protection resilience architecture which leverages computerized propagation over a structured graph of resource and resource-group records in memory. In particular, claim 1 requires generating, in memory, an "R-graph" that comprises object records and dependency relationships;… . The Patent Office has not shown that the ordered combination of resource object records, resource-group object records, stored data-protection protected- status tiers, propagation of child resource values to a parent resource-group object record, and setting the parent compliance state based on child protected-status values was well- understood, routine, and conventional. The amended claim therefore does not merely add generic computer components to an abstract idea; it recites a specific data-structure-driven computation pipeline for data-protection resilience status propagation. Independent claims 4 and 7 recite analogous limitations in apparatus and computer-program- product form and are patent eligible for at least the same reasons. The dependent claims are eligible for at least the same reasons and further limit the claimed R-graph implementation and domain-specific presentation. Accordingly, the rejection under 35 U.S.C. § 101 should be withdrawn. Applicant’s support: It is true that a person might draw a simplified illustrative graph on paper, but that is not the claimed invention. The claim requires machine-maintained object records in memory, stored data-protection status attributes, dependency relationships among resource and resource- group object records, and machine-implemented propagation operations that update parent resource-group object states based on child resource object states. These are operations on a particular computer data structure representing data-processing resources, not mental observations, judgments, or opinions. The practical application is not the business result of knowing whether an enterprise is compliant. Rather, the practical application is the claimed R-graph mechanism for computing data-protection resilience status across nested machine-resource relationships. The claim has the technical effect of improving operation of a data-protection management system by replacing isolated resource-level status reporting with propagated resource-group status computation based on child-resource compliance, criticality, and protected-status attributes. That is the technological mechanism recited in the claim. The claim recites the particular implementation that provides the improvement: the R-graph object-record structure, the protected/protected-with- warnings/not-protected data-protection status tiers, and the child-to-parent propagation logic that changes the parent resource-group compliance state. The specification support already identified by Applicants likewise describes resource-group objects, nested groups, propagation logic applied to the R-graph, propagation of statuses from child members of a hierarchy or group, and protected-status tiers including "Protected," "Protected-With- Warnings," and "Not-Protected." Examiner’s remarks: The mental process abstract idea involves the limitations of “generating a model of data processing resources within the data processing environment, the model identifying resources, resource groups each comprising a plurality of the resources, and nested group relationships among the resource groups; generating a data resilience graph (R-graph) based on the model, the R- graph comprising a plurality of object records and dependency relationships between the object records, the plurality of object records including: a resource object record for each resource, and a resource-group object record for each resource group; applying compliance and criticality rules, including propagation logic, to the object records in the R-graph based on the dependency relationships nested group relationships, the applying comprising: propagating compliance values and, criticality values, and protected-status values from resource object records representing child resources to a resource-group object record representing a parent resource group, determining, for the resource-group object record, a propagated compliance attribute and a propagated criticality attribute based at least in part on the compliance attributes, criticality attributes, and protected-status attributes of the child resources; and setting the propagated compliance attribute of the resource-group object record to a non-compliant value or a warning value when at least one child resource object record has a not-protected value or a protected-with-warnings value according to the propagation logic”. The combination of steps above recites an abstract idea Apart from citing generic computing components (such as data processor and memory), these steps are can be achieved in the human mind and/or using pencil and paper. If a claim recites a limitation that can practically be performed in the human mind, with or without the use of a physical aid such as pen and paper, the limitation falls within the mental processes grouping, and the claim recites an abstract idea. Claims can recite a mental process even if they are claimed as being performed on a computer. The examiner reviewed the specification and determine that the claimed invention involves a concept that is performed in the human mind and the applicant is merely claiming that concept is performed 1) on a generic computer, or 2) in a computer environment, or 3) is merely using a computer as a tool to perform the concept. In these situations, the claim is considered to recite a mental process The additional element are the (a) generic computing components; (b) the steps of record storing at least a compliance attribute and, a criticality attribute, and a protected-status attribute for the corresponding resource; and the step of (c) displaying a domain-specific view of the R-graph; for an operational scope of the data processing environment, the domain-specific view including the resource-group object record and visually indicating the propagated compliance attribute and the propagated criticality attribute for the operational scope. It has been determined that the generic computing components (data processor and memory) are merely instructions to apply an exception/abstract idea. As explained by the Supreme Court, in order to make a claim directed to a judicial exception patent-eligible, the additional element or combination of elements must do "‘more than simply stat[e] the [judicial exception] while adding the words ‘apply it’” (or an equivalent). Alice Corp. v. CLS Bank, 573 U.S. 208, 221, 110 USPQ2d 1976, 1982-83 (2014) (quoting Mayo Collaborative Servs. V. Prometheus Labs., Inc., 566 U.S. 66, 72, 101 USPQ2d 1961, 1965). Thus, for example, claims that amount to nothing more than an instruction to apply the abstract idea using a generic computer do not render an abstract idea eligible. Alice Corp., 573 U.S. at 223, 110 USPQ2d at 1983. See also 573 U.S. at 224, 110 USPQ2d at 1984. Implementing an abstract idea on a generic computer does not integrate the abstract idea into a practical application or add significantly more. The steps of storing the attributes and displaying the domain specific view of the R-graph are considered to be activities that are well-known/well-understood, routine, and conventional. Therefore these additional elements, as a combination, do not integrate the abstract idea into a practical application and do not add an inventive concept to the claims because they do not amount to significantly more than the judicial exception. Therefore, in response to Applicant’s remarks “The Patent Office has not shown that the ordered combination of resource object records, resource-group object records, stored data-protection protected- status tiers, propagation of child resource values to a parent resource-group object record, and setting the parent compliance state based on child protected-status values was well- understood, routine, and conventional”, the steps of “propagation of child resource values to a parent resource-group object record” and “setting the parent compliance state based on child protected-status values” were determined to be an abstract idea and not activity that is routine, conventional, and well-understood. “Storing data” is the additional element that is well-understood, routine, and conventional, wherein in combination with other additional components (see 101 rejection) do not amount to significantly more than the abstract idea. 35 USC 103 rejection Applicant’s arguments with respect to independent claims have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-9 and 12 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea (mental process) without significantly more. The independent claim(s) recite(s) “generating a model of data processing resources within the data processing environment, the model identifying resources, resource groups each comprising a plurality of the resources, and nested group relationships among the resource groups; generating a data resilience graph (R-graph) based on the model, the R- graph comprising a plurality of object records and dependency relationships between the object records, the plurality of object records including: a resource object record for each resource, and a resource-group object record for each resource group; applying compliance and criticality rules, including propagation logic, -to the object records in the R-graph based on the dependency relationships nested group relationships, the applying comprising: propagating compliance values and, criticality values, and protected-status values from resource object records representing child resources to a resource-group object record representing a parent resource group, determining, for the resource-group object record, a propagated compliance attribute and a propagated criticality attribute based at least in part on the compliance attributes, criticality attributes, and protected-status attributes of the child resources; and setting the propagated compliance attribute of the resource-group object record to a non-compliant value or a warning value when at least one child resource object record has a not-protected value or a protected-with-warnings value according to the propagation logic”. The limitations above pertain to the method for assessing data protection resilience status of a data processing environment which is a process that under its broadest reasonable interpretation covers performance of the limitations being an abstract idea of a mental process. The method can be performed mentally by a human using pencil and paper, but for the recitation of generic computer components such as “data processing environment” (claims 1, 4, and 7), “generating in memory”, a data processor and computer readable media (claim 4), and non-transient medium and data processing system (claim 7). Therefore, nothing in the claimed elements preclude the steps from being practically performed manually by a human via a mental process or by a human using pencil or paper. If a claim under its broadest reasonable interpretation covers performance in the human mind or by a human using pencil and paper, but for the recitation of generic computer components, then if falls within the mental processing grouping of abstract ideas. Thus, claims 1, 4, and 7 recite an abstract idea. This judicial exception is not integrated into a practical application. The independent claims recite additional elements of within the data processing environment, additional generic computer components, and displaying a domain specific view of the R-graph. The generic computer components (including the data processing environment) are recited at a high level of generality such that it amounts to no more than mere instructions to apply the judicial exception using generic computing components. Accordingly, such additional elements do not integrate the abstract idea into a practical application because it does not impose meaningful limits on practicing the abstract idea. In addition, the processing environment is merely linking the judicial exception to a particular environment or field of use and does not qualify as significantly more than the judicial exception. The additional element of “each resource object record storing at least at compliance attribute, criticality attribute, and a protected status attribute for the corresponding resource” is determined to be merely storage of data that is well-understood, routine, and conventional activity (MPEP 2106.05(d)). The additional element of “displaying a domain-specific view of the R-graph; for an operational scope of the data processing environment, the domain-specific view including the resource-group object record and visually indicating the propagated compliance attribute and the propagated criticality attribute for the operational scope” is determined to be post solution activity/insignificant extra solution activity that involves selecting a particular data source or type of data to be manipulated and displayed (see MPEP 2106.05(g)) and activity that is well-understood, routine, and conventional activity (MPEP 2106.05(d)). Therefore the additional element does not integrate the abstract idea into a practical application and do not add an inventive concept to the claims. The additional elements above evaluated individually and in combination do not amount to significantly more than the abstract idea. For the reasons above, the independent claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception. Thus, claims 1, 4, 7 are ineligible under 35 U.S.C 101. Claims 2, 5, and 8 provide limitations that under the broadest reasonable interpretation further narrow the R-graph, which is activity that can be perform by a human using pencil and paper. The generation of the domain specific view by applying inheritance attributes of the compliance and criticality rules to the hierarchy of object appear to be an additional element that is not enough to qualify as significantly more than the abstract idea because the limitations is adding the words apply it with the judicial exception (MPEP 2106.05(d)). In addition, applying attributes/settings/rules to a display objects is determined to be well-understood, routine, conventional activity. Thus, claims 2, 5, and 8 are not eligible under 35 USC 101. Claims 3, 6, and 9 provide limitations that under the broadest reasonable interpretation further narrow the domain specific view to a particular environment or field of use and does not qualify as significantly more than the judicial exception. Thus, claims 3, 6, and 9 are not eligible under 35 USC 101. Claim 12 provides limitations that under the broadest reasonable interpretation further narrow the domain specific view and does not qualify as significantly more than the judicial exception. Thus, claim 12 is not eligible under 35 USC 101. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-9 and 12 is/are rejected under 35 U.S.C. 103 as being unpatentable over Sylor et al US 20020186238 (hereinafter Sylor) in view of Maes US 20190140914 (hereinafter Maes). As to claim 1, Sylor teaches a computer-implemented method for assessing data-protection resilience status of a data processing environment (Abstract discloses method for displaying the status of network resources. Paragraph 2 discloses the method relates to network monitoring. Paragraph 3 discloses network monitoring software detects problems and potential problems with network resources. The network monitoring software is therefore concerned with how problems can propagate from one resource to the next) , the method comprising, by one or more data processors (Paragraph 23 discloses the invention features a computing apparatus which includes a processor and main memory): generating a model of data processing resources within the data processing environment, the model identifying resources, resource groups each comprising a plurality of the resources, and nested group relationships among the resource groups (Paragraph 82 discloses a logical hierarchy offers a tree-based data model describing a web of dependency relationships between resource profiles. Paragraph 88 discloses by using its tree-based data model, logical hierarchy 30 can organize information into tiers, with parent-child relationships between entities of adjacent tiers. The parent-child relationships are based on dependency relationships: for instance, parent resource profiles can be dependent upon child resource profiles. Alternatively, parent resource profiles can provide to multiple child resource profiles, as with a server that provides multiple networked services, while each of the networked services (for instance, DNS, file sharing, and network security) provides its features to multiple software applications); generating, in memory (Paragraph 23 discloses the invention features a computing apparatus which includes a processor and main memory), a data resilience graph (R-graph) based on the model, the R- graph comprising a plurality of object records and dependency relationships between the object records (Paragraph 49 discloses a hierarchical status display process arranges the resources for display in a visual hierarchy (thus a graph). The visual hierarchy derives from a logical hierarchy containing resources in dependency relationships with one another. The logical hierarchy is a data model, while the visual hierarchy is a graphical representation of a logical hierarchy), the plurality of object records including: a resource object record for each resource (Paragraph 82 discloses a logical hierarchy offers a tree-based data model describing a web of dependency relationships between resource profiles. Paragraph 88 discloses by using its tree-based data model, logical hierarchy 30 can organize information into tiers, with parent-child relationships between entities of adjacent tiers. The parent-child relationships are based on dependency relationships: for instance, parent resource profiles can be dependent upon child resource profiles. Alternatively, parent resource profiles can provide to multiple child resource profiles. The child resource profiles are the resource object record for the child resource), each resource object further including record storing at least a compliance attribute and, a criticality attribute, and a protected-status attribute for the corresponding resource; the protected-status attribute having a value selected from at least protected, protected-with-warnings, and not-protected (Paragraph 182 reveals each rendered object for resource profile contains information such as rendering database ID specifying its referenced resource profile, severity level, positional information, and other attributes necessary. Paragraphs 19-20 reveal the resource profile includes a status and associating the status with a severity. Associating the status with a severity includes a using a status metric associated with the monitored resource profile. The method include acquiring notice of a change in the status, updating the severity; and re-rendering the hierarchy in a fishbone layout, to include rendering the monitored resource profile to indicate the updated severity. The severity includes applying an application-wide override to deviate from a behavior indicated by the status metric. The deviation includes suppressing a change in severity. Paragraph 17 discloses the status includes acquiring information about properties of the monitored resource that have changed in the most recent interval. Paragraphs 64-65 the status of an example resource can be trouble-free, warning, or error. Therefore, the reference resource profile can be the compliance attribute, the severity level is the criticality attribute, and the protected status attribute is the status (where warning label can be selected)); and a resource-group object record for each resource group (Paragraph 82 discloses a logical hierarchy offers a tree-based data model describing a web of dependency relationships between resource profiles. Paragraph 88 discloses by using its tree-based data model, logical hierarchy 30 can organize information into tiers, with parent-child relationships between entities of adjacent tiers. The parent-child relationships are based on dependency relationships: for instance, parent resource profiles can be dependent upon child resource profiles. Alternatively, parent resource profiles can provide to multiple child resource profiles. Therefore, the parent resource profiles are the resource group object record for the parent resource); applying compliance and criticality rules, including propagation logic, to the object records in the R-graph based on the dependency relationships and the nested group relationships (Paragraph 17 discloses the monitored resource profile includes a propagation rule for how the acquired status should propagate to dependent resource profiles that are in dependency relationships (this relationship include nested group relationship, see also paragraphs 76-78) with the monitored resource profile), the applying comprising: propagating compliance values and, criticality values, and protected-status values from resource object records representing child resources to and a resource-group object record representing a parent resource group (Paragraphs 17, 71, and 200 disclose the monitored resource profile includes a propagation rule for how the acquired status should propagate to dependent resource profiles that are in dependency relationships with the monitored resource profile. Thus, the prior art discloses how a status (or multiple statuses) should propagate from dependent resource profile/child to the monitored resource profile/parent); determining, for the resource-group object record, a propagated compliance attribute and a propagated criticality attribute based at least in part on the compliance attributes, criticality attributes, and protected-status attributes of the child resources (Paragraph 71 discloses obtaining status values that are derived from states of the associated resource representation. The derivation is given by a status metric. Status metric determines the states that status value represents and how their values are weighed, status metric can represent a context through its choice of states and through the outputs that it assigns. Paragraph 200 discloses monitored agent determines, based on resource profiles, if a condition exists for which it should raise alarm); and setting the propagated compliance attribute of the resource-group object record to a non-compliant value or a warning value…(Paragraphs 64-65 disclose the status of an example resource can be trouble-free, warning, or error. Therefore, propagated compliance attribute is set to warning status or error status );and displaying a domain-specific view of the R-graph ,for an operational scope of the data processing environment, the domain-specific view including the resource-group object record and visually indicating the propagated compliance attribute and the propagated criticality attribute for the operational scope (Paragraph 21 discloses displaying the status (which can be the propagated compliance attribute and the propagated criticality attribute) of networked resources. The method includes acquiring a logical hierarchy that includes resource profiles, as well as dependency relationships among the resource profiles. The resource profiles represent networked resources. The method also includes deriving a visual hierarchy from the logical hierarchy, where components of the visual hierarchy correspond to components of the logical hierarchy, such that the visual hierarchy is a tree. The method includes rendering the visual hierarchy in a fishbone. Paragraph 24 discloses the fishbone layouts each feature a hierarchy with resource profiles and dependency relationships among the resource profiles, where the resource profiles represent networked resources. Each hierarchy shares a common root. Preferred embodiments with regards to one or more fishbone layouts in the snowflake layout include one or more of the features already described with regards to a fishbone layout). PNG media_image1.png 406 462 media_image1.png Greyscale PNG media_image2.png 481 464 media_image2.png Greyscale Figure 9 of Maes Figure 10 of Maes Sylor does not teach, but Maes teaches setting a propagated compliance attribute of the resource-group object record to a non-compliant value or a warning value when at least one child resource object record has a not-protected value or a protected-with-warnings value according to the propagation logic (Figure 9 and paragraphs 188-190 reveal a propagated compliance attribute of the parent/Service C 1004 has a critical warning notification associated with it. When the user selects service C, the user sees the child topology represented by Figure 10, where there is a warning value associated a node of the child graph). It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify Sylor’s teaching of monitoring software detected problems and potential problems with network resources with Maes’s teachings of setting a propagated compliance attribute of the resource-group object record to a warning value when at least one child resource object has-warnings value according to the propagation logic such that the system can autonomously or semi-autonomously remediate any events or incidents that may be detected from the monitoring of the instantiated service or provided via an information technology service management system (ITSM) (Paragraph 28 of Maes). As to claim 2, the combination of Sylor in view of Maes teaches additionally wherein the R-graph consists of a hierarchy of objects, and the domain-specific view is further generated by applying inheritance attributes of the compliance and criticality rules to the hierarchy of objects (Sylor: Paragraph 49 discloses a hierarchical status display process arranges the resources for display in a visual hierarchy (thus a graph). The visual hierarchy derives from a logical hierarchy containing resources in dependency relationships with one another. The logical hierarchy is a data model, while the visual hierarchy is a graphical representation of a logical hierarchy. Paragraph 82 discloses a logical hierarchy offers a tree-based data model describing a web of dependency relationships between resource profiles. Paragraph 88 discloses by using its tree-based data model, logical hierarchy 30 can organize information into tiers, with parent-child relationships between entities of adjacent tiers. The parent-child relationships are based on dependency relationships: for instance, parent resource profiles can be dependent upon child resource profiles. Paragraph 21 discloses displaying the status (which can be the propagated compliance attribute and the propagated criticality attribute) of networked resources. The method includes acquiring a logical hierarchy that includes resource profiles, as well as dependency relationships among the resource profiles. The resource profiles represent networked resources. The method also includes deriving a visual hierarchy from the logical hierarchy, where components of the visual hierarchy correspond to components of the logical hierarchy, such that the visual hierarchy is a tree. The method includes rendering the visual hierarchy in a fishbone. Paragraph 24 discloses the fishbone layouts each feature a hierarchy with resource profiles and dependency relationships among the resource profiles, where the resource profiles represent networked resources. Each hierarchy shares a common root. Preferred embodiments with regards to one or more fishbone layouts in the snowflake layout include one or more of the features already described with regards to a fishbone layout). As to claim 3, the combination of Sylor in view of Maes teaches wherein the domain-specific view is for an entire enterprise, a department within the enterprise, an application, or a service (Sylor: Paragraph 49 discloses a hierarchical status display process arranges the resources for display in a visual hierarchy (thus a graph). Paragraph 51 reveals resources include hardware, applications, services, business processes, organizational structures (such as business units within an enterprise, or departments within a university), paths within a network, and other network resources. Hardware resources include clients, servers, routers, switches, and NIC's, as well as peripheral devices (such as disk drives) and networked devices (such as printers and networked storage)). As to claim 4, Sylor teaches an apparatus for assessing data-protection resilience status of a data processing environment (Paragraph 23 discloses the invention features a computing apparatus which includes a processor and main memory; abstract discloses method for displaying the status of network resources. Paragraph 2 discloses the method relates to network monitoring. Paragraph 3 discloses network monitoring software detects problems and potential problems with network resources. The network monitoring software is therefore concerned with how problems can propagate from one resource to the next), the apparatus comprising: one or more data processors (Paragraph 23 discloses the invention features a computing apparatus which includes a processor and main memory); and one or more computer readable storage media storing instructions that, when executed by the one or more data processors, cause the one or more data processors to perform operations comprising (Paragraphs 56-57 disclose computer instructions resident in main memory. A processor can access main memory to execute the computer instructions for operating system. Claim 29 and paragraphs 25 and 59 disclose a computer usable medium having computer readable program code means embodied therein, including a processor, a main memory, a visual display, a storage device, and a network connection, the program code means comprising: computer readable program code means for causing a computer to represent a hierarchy including a plurality of resource profiles and a plurality of dependency relationships among resource profiles in the plurality of resource profiles, where the resource profiles represent networked resources; computer readable program code means for causing the computer to acquire a status of a monitored resource profile in the plurality of resource profiles; and computer readable program code means for causing the computer to render the hierarchy in a fishbone layout, including rendering a visual representation of the status of the monitored resource profile): generating a model of data processing resources within the data processing environment, the model identifying resources, resource groups each comprising a plurality of the resources, and nested group relationships among the resource groups (Paragraph 82 discloses a logical hierarchy offers a tree-based data model describing a web of dependency relationships between resource profiles. Paragraph 88 discloses by using its tree-based data model, logical hierarchy 30 can organize information into tiers, with parent-child relationships between entities of adjacent tiers. The parent-child relationships are based on dependency relationships: for instance, parent resource profiles can be dependent upon child resource profiles. Alternatively, parent resource profiles can provide to multiple child resource profiles, as with a server that provides multiple networked services, while each of the networked services (for instance, DNS, file sharing, and network security) provides its features to multiple software applications); generating, in memory (Paragraph 23 discloses the invention features a computing apparatus which includes a processor and main memory), a data resilience graph (R-graph) based on the model, the R- graph comprising a plurality of object records and dependency relationships between the object records (Paragraph 49 discloses a hierarchical status display process arranges the resources for display in a visual hierarchy (thus a graph). The visual hierarchy derives from a logical hierarchy containing resources in dependency relationships with one another. The logical hierarchy is a data model, while the visual hierarchy is a graphical representation of a logical hierarchy), the plurality of object records including: a resource object record for each resource (Paragraph 82 discloses a logical hierarchy offers a tree-based data model describing a web of dependency relationships between resource profiles. Paragraph 88 discloses by using its tree-based data model, logical hierarchy 30 can organize information into tiers, with parent-child relationships between entities of adjacent tiers. The parent-child relationships are based on dependency relationships: for instance, parent resource profiles can be dependent upon child resource profiles. Alternatively, parent resource profiles can provide to multiple child resource profiles. The child resource profiles are the resource object record for the child resource), each resource object further including record storing at least a compliance attribute and, a criticality attribute, and a protected-status attribute for the corresponding resource; the protected-status attribute having a value selected from at least protected, protected-with-warnings, and not-protected (Paragraph 182 reveals each rendered object for resource profile contains information such as rendering database ID specifying its referenced resource profile, severity level, positional information, and other attributes necessary. Paragraphs 19-20 reveal the resource profile includes a status and associating the status with a severity. Associating the status with a severity includes a using a status metric associated with the monitored resource profile. The method include acquiring notice of a change in the status, updating the severity; and re-rendering the hierarchy in a fishbone layout, to include rendering the monitored resource profile to indicate the updated severity. The severity includes applying an application-wide override to deviate from a behavior indicated by the status metric. The deviation includes suppressing a change in severity. Paragraph 17 discloses the status includes acquiring information about properties of the monitored resource that have changed in the most recent interval. Paragraphs 64-65 the status of an example resource can be trouble-free, warning, or error. Therefore, the reference resource profile can be the compliance attribute, the severity level is the criticality attribute, and the protected status attribute is the status (where warning label can be selected)); and a resource-group object record for each resource group (Paragraph 82 discloses a logical hierarchy offers a tree-based data model describing a web of dependency relationships between resource profiles. Paragraph 88 discloses by using its tree-based data model, logical hierarchy 30 can organize information into tiers, with parent-child relationships between entities of adjacent tiers. The parent-child relationships are based on dependency relationships: for instance, parent resource profiles can be dependent upon child resource profiles. Alternatively, parent resource profiles can provide to multiple child resource profiles. Therefore, the parent resource profiles are the resource group object record for the parent resource); applying compliance and criticality rules, including propagation logic, to the object records in the R-graph based on the dependency relationships and the nested group relationships (Paragraph 17 discloses the monitored resource profile includes a propagation rule for how the acquired status should propagate to dependent resource profiles that are in dependency relationships (this relationship include nested group relationship, see also paragraphs 76-78) with the monitored resource profile), the applying comprising: propagating compliance values and, criticality values, and protected-status values from resource object records representing child resources to and a resource-group object record representing a parent resource group (Paragraphs 17, 71, and 200 disclose the monitored resource profile includes a propagation rule for how the acquired status should propagate to dependent resource profiles that are in dependency relationships with the monitored resource profile. Thus, the prior art discloses how a status (or multiple statuses) should propagate from dependent resource profile/child to the monitored resource profile/parent); determining, for the resource-group object record, a propagated compliance attribute and a propagated criticality attribute based at least in part on the compliance attributes, criticality attributes, and protected-status attributes of the child resources (Paragraph 71 discloses obtaining status values that are derived from states of the associated resource representation. The derivation is given by a status metric. Status metric determines the states that status value represents and how their values are weighed, status metric can represent a context through its choice of states and through the outputs that it assigns. Paragraph 200 discloses monitored agent determines, based on resource profiles, if a condition exists for which it should raise alarm); and setting the propagated compliance attribute of the resource-group object record to a non-compliant value or a warning value…(Paragraphs 64-65 disclose the status of an example resource can be trouble-free, warning, or error. Therefore, propagated compliance attribute is set to warning status or error status );and displaying a domain-specific view of the R-graph ,for an operational scope of the data processing environment, the domain-specific view including the resource-group object record and visually indicating the propagated compliance attribute and the propagated criticality attribute for the operational scope (Paragraph 21 discloses displaying the status (which can be the propagated compliance attribute and the propagated criticality attribute) of networked resources. The method includes acquiring a logical hierarchy that includes resource profiles, as well as dependency relationships among the resource profiles. The resource profiles represent networked resources. The method also includes deriving a visual hierarchy from the logical hierarchy, where components of the visual hierarchy correspond to components of the logical hierarchy, such that the visual hierarchy is a tree. The method includes rendering the visual hierarchy in a fishbone. Paragraph 24 discloses the fishbone layouts each feature a hierarchy with resource profiles and dependency relationships among the resource profiles, where the resource profiles represent networked resources. Each hierarchy shares a common root. Preferred embodiments with regards to one or more fishbone layouts in the snowflake layout include one or more of the features already described with regards to a fishbone layout). Sylor does not teach, but Maes teaches setting a propagated compliance attribute of the resource-group object record to a non-compliant value or a warning value when at least one child resource object record has a not-protected value or a protected-with-warnings value according to the propagation logic (Figure 9 and paragraphs 188-190 reveal a propagated compliance attribute of the parent/Service C 1004 has a critical warning notification associated with it. When the user selects service C, the user sees the child topology represented by Figure 10, where there is a warning value associated a node of the child graph). It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify Sylor’s teaching of monitoring software detected problems and potential problems with network resources with Maes’s teachings of setting a propagated compliance attribute of the resource-group object record to a warning value when at least one child resource object has-warnings value according to the propagation logic such that the system can autonomously or semi-autonomously remediate any events or incidents that may be detected from the monitoring of the instantiated service or provided via an information technology service management system (ITSM) (Paragraph 28 of Maes). As to claim 5, the combination of Sylor in view of Maes teaches additionally wherein the R-graph consists of a hierarchy of objects, and the domain-specific view is further generated by applying inheritance attributes of the compliance and criticality rules to the hierarchy of objects (Sylor: Paragraph 49 discloses a hierarchical status display process arranges the resources for display in a visual hierarchy (thus a graph). The visual hierarchy derives from a logical hierarchy containing resources in dependency relationships with one another. The logical hierarchy is a data model, while the visual hierarchy is a graphical representation of a logical hierarchy. Paragraph 82 discloses a logical hierarchy offers a tree-based data model describing a web of dependency relationships between resource profiles. Paragraph 88 discloses by using its tree-based data model, logical hierarchy 30 can organize information into tiers, with parent-child relationships between entities of adjacent tiers. The parent-child relationships are based on dependency relationships: for instance, parent resource profiles can be dependent upon child resource profiles. Paragraph 21 discloses displaying the status (which can be the propagated compliance attribute and the propagated criticality attribute) of networked resources. The method includes acquiring a logical hierarchy that includes resource profiles, as well as dependency relationships among the resource profiles. The resource profiles represent networked resources. The method also includes deriving a visual hierarchy from the logical hierarchy, where components of the visual hierarchy correspond to components of the logical hierarchy, such that the visual hierarchy is a tree. The method includes rendering the visual hierarchy in a fishbone. Paragraph 24 discloses the fishbone layouts each feature a hierarchy with resource profiles and dependency relationships among the resource profiles, where the resource profiles represent networked resources. Each hierarchy shares a common root. Preferred embodiments with regards to one or more fishbone layouts in the snowflake layout include one or more of the features already described with regards to a fishbone layout). As to claim 6, the combination of Sylor in view of Maes teaches wherein the domain-specific view is for an entire enterprise, a department within the enterprise, an application, or a service (Sylor: Paragraph 49 discloses a hierarchical status display process arranges the resources for display in a visual hierarchy (thus a graph). Paragraph 51 reveals resources include hardware, applications, services, business processes, organizational structures (such as business units within an enterprise, or departments within a university), paths within a network, and other network resources. Hardware resources include clients, servers, routers, switches, and NIC's, as well as peripheral devices (such as disk drives) and networked devices (such as printers and networked storage)). As to claim 7, Sylor teaches a computer program product embodied in one or more non-transitory computer readable storage media, the computer program product storing computer program instructions that (Claim 29 and paragraphs 25 and 59 disclose a computer usable medium having computer readable program code means embodied therein, including a processor, a main memory, a visual display, a storage device, and a network connection, the program code means comprising: computer readable program code means for causing a computer to represent a hierarchy including a plurality of resource profiles and a plurality of dependency relationships among resource profiles in the plurality of resource profiles, where the resource profiles represent networked resources; computer readable program code means for causing the computer to acquire a status of a monitored resource profile in the plurality of resource profiles; and computer readable program code means for causing the computer to render the hierarchy in a fishbone layout, including rendering a visual representation of the status of the monitored resource profile. Paragraphs 56-57 disclose computer instructions resident in main memory. A processor can access main memory to execute the computer instructions for operating system), when executed by a data processing system cause the data processing system to perform operations for assessing data protection resilience status of a data processing environment (Paragraph 23 discloses the invention features a computing apparatus which includes a processor and main memory; abstract discloses method for displaying the status of network resources. Paragraph 2 discloses the method relates to network monitoring. Paragraph 3 discloses network monitoring software detects problems and potential problems with network resources. The network monitoring software is therefore concerned with how problems can propagate from one resource to the next), the operation comprising: generating a model of data processing resources within the data processing environment, the model identifying resources, resource groups each comprising a plurality of the resources, and nested group relationships among the resource groups (Paragraph 82 discloses a logical hierarchy offers a tree-based data model describing a web of dependency relationships between resource profiles. Paragraph 88 discloses by using its tree-based data model, logical hierarchy 30 can organize information into tiers, with parent-child relationships between entities of adjacent tiers. The parent-child relationships are based on dependency relationships: for instance, parent resource profiles can be dependent upon child resource profiles. Alternatively, parent resource profiles can provide to multiple child resource profiles, as with a server that provides multiple networked services, while each of the networked services (for instance, DNS, file sharing, and network security) provides its features to multiple software applications); generating, in memory (Paragraph 23 discloses the invention features a computing apparatus which includes a processor and main memory), a data resilience graph (R-graph) based on the model, the R- graph comprising a plurality of object records and dependency relationships between the object records (Paragraph 49 discloses a hierarchical status display process arranges the resources for display in a visual hierarchy (thus a graph). The visual hierarchy derives from a logical hierarchy containing resources in dependency relationships with one another. The logical hierarchy is a data model, while the visual hierarchy is a graphical representation of a logical hierarchy), the plurality of object records including: a resource object record for each resource (Paragraph 82 discloses a logical hierarchy offers a tree-based data model describing a web of dependency relationships between resource profiles. Paragraph 88 discloses by using its tree-based data model, logical hierarchy 30 can organize information into tiers, with parent-child relationships between entities of adjacent tiers. The parent-child relationships are based on dependency relationships: for instance, parent resource profiles can be dependent upon child resource profiles. Alternatively, parent resource profiles can provide to multiple child resource profiles. The child resource profiles are the resource object record for the child resource), each resource object further including record storing at least a compliance attribute and, a criticality attribute, and a protected-status attribute for the corresponding resource; the protected-status attribute having a value selected from at least protected, protected-with-warnings, and not-protected (Paragraph 182 reveals each rendered object for resource profile contains information such as rendering database ID specifying its referenced resource profile, severity level, positional information, and other attributes necessary. Paragraphs 19-20 reveal the resource profile includes a status and associating the status with a severity. Associating the status with a severity includes a using a status metric associated with the monitored resource profile. The method include acquiring notice of a change in the status, updating the severity; and re-rendering the hierarchy in a fishbone layout, to include rendering the monitored resource profile to indicate the updated severity. The severity includes applying an application-wide override to deviate from a behavior indicated by the status metric. The deviation includes suppressing a change in severity. Paragraph 17 discloses the status includes acquiring information about properties of the monitored resource that have changed in the most recent interval. Paragraphs 64-65 the status of an example resource can be trouble-free, warning, or error. Therefore, the reference resource profile can be the compliance attribute, the severity level is the criticality attribute, and the protected status attribute is the status (where warning label can be selected)); and a resource-group object record for each resource group (Paragraph 82 discloses a logical hierarchy offers a tree-based data model describing a web of dependency relationships between resource profiles. Paragraph 88 discloses by using its tree-based data model, logical hierarchy 30 can organize information into tiers, with parent-child relationships between entities of adjacent tiers. The parent-child relationships are based on dependency relationships: for instance, parent resource profiles can be dependent upon child resource profiles. Alternatively, parent resource profiles can provide to multiple child resource profiles. Therefore, the parent resource profiles are the resource group object record for the parent resource); applying compliance and criticality rules, including propagation logic, to the object records in the R-graph based on the dependency relationships and the nested group relationships (Paragraph 17 discloses the monitored resource profile includes a propagation rule for how the acquired status should propagate to dependent resource profiles that are in dependency relationships (this relationship include nested group relationship, see also paragraphs 76-78) with the monitored resource profile), the applying comprising: propagating compliance values and, criticality values, and protected-status values from resource object records representing child resources to and a resource-group object record representing a parent resource group (Paragraphs 17, 71, and 200 disclose the monitored resource profile includes a propagation rule for how the acquired status should propagate to dependent resource profiles that are in dependency relationships with the monitored resource profile. Thus, the prior art discloses how a status (or multiple statuses) should propagate from dependent resource profile/child to the monitored resource profile/parent); determining, for the resource-group object record, a propagated compliance attribute and a propagated criticality attribute based at least in part on the compliance attributes, criticality attributes, and protected-status attributes of the child resources (Paragraph 71 discloses obtaining status values that are derived from states of the associated resource representation. The derivation is given by a status metric. Status metric determines the states that status value represents and how their values are weighed, status metric can represent a context through its choice of states and through the outputs that it assigns. Paragraph 200 discloses monitored agent determines, based on resource profiles, if a condition exists for which it should raise alarm); and setting the propagated compliance attribute of the resource-group object record to a non-compliant value or a warning value…(Paragraphs 64-65 disclose the status of an example resource can be trouble-free, warning, or error. Therefore, propagated compliance attribute is set to warning status or error status );and displaying a domain-specific view of the R-graph ,for an operational scope of the data processing environment, the domain-specific view including the resource-group object record and visually indicating the propagated compliance attribute and the propagated criticality attribute for the operational scope (Paragraph 21 discloses displaying the status (which can be the propagated compliance attribute and the propagated criticality attribute) of networked resources. The method includes acquiring a logical hierarchy that includes resource profiles, as well as dependency relationships among the resource profiles. The resource profiles represent networked resources. The method also includes deriving a visual hierarchy from the logical hierarchy, where components of the visual hierarchy correspond to components of the logical hierarchy, such that the visual hierarchy is a tree. The method includes rendering the visual hierarchy in a fishbone. Paragraph 24 discloses the fishbone layouts each feature a hierarchy with resource profiles and dependency relationships among the resource profiles, where the resource profiles represent networked resources. Each hierarchy shares a common root. Preferred embodiments with regards to one or more fishbone layouts in the snowflake layout include one or more of the features already described with regards to a fishbone layout). Sylor does not teach, but Maes teaches setting a propagated compliance attribute of the resource-group object record to a non-compliant value or a warning value when at least one child resource object record has a not-protected value or a protected-with-warnings value according to the propagation logic (Figure 9 and paragraphs 188-190 reveal a propagated compliance attribute of the parent/Service C 1004 has a critical warning notification associated with it. When the user selects service C, the user sees the child topology represented by Figure 10, where there is a warning value associated a node of the child graph). It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify Sylor’s teaching of monitoring software detected problems and potential problems with network resources with Maes’s teachings of setting a propagated compliance attribute of the resource-group object record to a warning value when at least one child resource object has-warnings value according to the propagation logic such that the system can autonomously or semi-autonomously remediate any events or incidents that may be detected from the monitoring of the instantiated service or provided via an information technology service management system (ITSM) (Paragraph 28 of Maes). As to claim 8, the combination of Sylor in view of Maes teaches additionally wherein the R-graph consists of a hierarchy of objects, and the domain-specific view is further generated by applying inheritance attributes of the compliance and criticality rules to the hierarchy of objects (Sylor: Paragraph 49 discloses a hierarchical status display process arranges the resources for display in a visual hierarchy (thus a graph). The visual hierarchy derives from a logical hierarchy containing resources in dependency relationships with one another. The logical hierarchy is a data model, while the visual hierarchy is a graphical representation of a logical hierarchy. Paragraph 82 discloses a logical hierarchy offers a tree-based data model describing a web of dependency relationships between resource profiles. Paragraph 88 discloses by using its tree-based data model, logical hierarchy 30 can organize information into tiers, with parent-child relationships between entities of adjacent tiers. The parent-child relationships are based on dependency relationships: for instance, parent resource profiles can be dependent upon child resource profiles. Paragraph 21 discloses displaying the status (which can be the propagated compliance attribute and the propagated criticality attribute) of networked resources. The method includes acquiring a logical hierarchy that includes resource profiles, as well as dependency relationships among the resource profiles. The resource profiles represent networked resources. The method also includes deriving a visual hierarchy from the logical hierarchy, where components of the visual hierarchy correspond to components of the logical hierarchy, such that the visual hierarchy is a tree. The method includes rendering the visual hierarchy in a fishbone. Paragraph 24 discloses the fishbone layouts each feature a hierarchy with resource profiles and dependency relationships among the resource profiles, where the resource profiles represent networked resources. Each hierarchy shares a common root. Preferred embodiments with regards to one or more fishbone layouts in the snowflake layout include one or more of the features already described with regards to a fishbone layout). As to claim 9, the combination of Sylor in view of Maes teaches wherein the domain-specific view is for an entire enterprise, a department within the enterprise, an application, or a service (Sylor: Paragraph 49 discloses a hierarchical status display process arranges the resources for display in a visual hierarchy (thus a graph). Paragraph 51 reveals resources include hardware, applications, services, business processes, organizational structures (such as business units within an enterprise, or departments within a university), paths within a network, and other network resources. Hardware resources include clients, servers, routers, switches, and NIC's, as well as peripheral devices (such as disk drives) and networked devices (such as printers and networked storage)). As to claim 12, the combination of Sylor in view of Maes teaches wherein the domain-specific view presents the propagated compliance attributes and criticality attributes color-coded according to protection tiers and policy thresholds (Sylor: paragraphs 19-20 disclose the monitored resource profile is rendered with a visual trait indicating the severity status. The visual trait includes a color selected from a plurality of colors representing a severity scale. See also paragraphs 134-135. Figure 9 and paragraphs 188-190 reveal a propagated compliance attribute of the parent/Service C 1004 has a critical warning notification associated with it. When the user selects service C, the user sees the child topology represented by Figure 10, where there is a warning value associated a node of the child graph). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: Maor et al US 20210203684 (hereinafter Maor). Maor teaches method for assessing data-protection resilience status of a data processing environment (Abstract discloses the detection of a risky edge in a lateral movement path is detected by determining the weakest point in the configuration of the user accounts, groups, and devices having access to the resources of a tenant of the cloud service); generating a data resilience graph, the R-graph comprising a plurality of object records and dependency relationships between object records (Paragraph 31 discloses LMP graph generation component generates a lateral movement graph, for each tenant, representing the relationships between the users, devices, groups associated with a tenant. In one aspect, the LMP graph generation component retrieves data from the management service regarding the relationships between the users, devices, and logon sessions of a tenant in order to construct the LMP graph for the tenant) as disclosed in claims 1, 4, and 7. Any inquiry concerning this communication or earlier communications from the examiner should be directed to FELICIA FARROW whose telephone number is (571)272-1856. The examiner can normally be reached M - F 7:30am-4:00pm (EST). Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached at (571)270-5143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /F.F/Examiner, Art Unit 2437 /ALI S ABYANEH/Primary Examiner, Art Unit 2437
Read full office action

Prosecution Timeline

Jan 30, 2024
Application Filed
Jul 30, 2025
Non-Final Rejection mailed — §101, §103
Dec 18, 2025
Response Filed
Feb 23, 2026
Final Rejection mailed — §101, §103
May 26, 2026
Request for Continued Examination
Jun 02, 2026
Response after Non-Final Action
Aug 10, 2026
Non-Final Rejection mailed — §101, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12748884
METHOD AND SYSTEM FOR ENSURING PRIVACY PROTECTION FOR DATASETS USING SPACE PARTITIONING TECHNIQUES
3y 3m to grant Granted Sep 29, 2026
Patent 12724865
Continuous Authentication in a Security Environment
3y 7m to grant Granted Sep 01, 2026
Patent 12724917
LOG COMPRESSION AND OBFUSCATION USING EMBEDDINGS
2y 10m to grant Granted Sep 01, 2026
Patent 12694149
SYSTEM AND METHOD FOR REDACTION OF DATA THAT IS INCIDENTALLY RECORDED
4y 7m to grant Granted Jul 28, 2026
Patent 12675579
Secure Systems of Guardrails for Securing the Use of Large Language Models (LLMS)
2y 3m to grant Granted Jul 07, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
59%
Grant Probability
94%
With Interview (+35.6%)
2y 11m (~3m remaining)
Median Time to Grant
High
PTA Risk
Based on 273 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month