DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 1/29/2026 has been entered.
Response to Arguments
Applicant’s arguments, see page(s) 7, filed 6/12/2026, with respect to the rejection of claim(s) 5-7, 12-14, 19, and 20 under 35 U.S.C. 112(d) have been fully considered and are persuasive. The associated rejection(s) to the listed claim(s) has/have been withdrawn.
Applicant’s arguments, see page(s) 7-13, filed 6/12/2026, with respect to the rejection of claim(s) 1-20 under 35 U.S.C. 103 have been fully considered and are persuasive. Therefore, the rejection has been withdrawn. However, upon further consideration, a new ground(s) of rejection is made in view of MAIMAN et al (Doc ID US 20220407893 A1).
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 8, and 15 are rejected under 35 U.S.C. 103 as being unpatentable over MAIMAN et al (Doc ID US 20220407893 A1), and further in view of REITSMA et al (Doc ID US 20170353308 A1) and PRICE et al (Doc ID US 20200195693 A1).
Regarding claim 1:
MAIMAN teaches:
A method comprising: identifying an elevated risk factor of an endpoint device on a computing network according to one or more characteristics of the endpoint device ([0017] "… The module may be configured to track and count the number of failed password attempts. And each one of those failed attempts would modify a calculated risk score that is assigned at the device level. …");
updating an inventory database with inventory information of the endpoint device indicating the elevated risk factor of the endpoint device that was identified ([0049] "... the server 120 may store the determined first risk score in the database 130.");
automatically updating, responsive to updating the inventory database with the inventory information of the endpoint device, group membership of a dynamic group of endpoint devices having an elevated risk level to include the endpoint device identified as having the elevated risk factor ([0050] "... The first risk score threshold may a neutral number .... The first user device 110 ... may be categorized as a high risk device if the determined first risk score is equal to or greater than the neutral number.");
restricting access, in response to updating the group membership, by the dynamic group of endpoint devices identified as having the elevated risk level to one or more computing systems and/or computing applications accessible on the computing network based on the elevated risk level ([0019] "... when the risk score of that device is above a certain risk score threshold, restricted network settings can be enforced on that device. The restriction settings may include, but not be limited to, throttling the network connection of that device so that its network connection is slow and it is ... impossible to perform certain actions ...").
REITSMA teaches the following limitation(s) not taught by MAIMAN:
identifying a user associated with the endpoint device having the elevated risk factor ([0033] "Upon determining that its security is compromised, the first communication device 105 generates a security status (at block 415) .... The security status may include … a user identifier …");
identifying one or more additional endpoint devices on the computing network associated with the identified user ([0033] "… the first and second communication devices 105, 110 may include the same user identifier but different device identifiers.");
Determining a device’s risk level, updating a database with the device’s risk information, including the device in a group of devices with a similar risk factor, and restricting access to a group of devices based on the risk factor are known techniques in the art, as demonstrated by MAIMAN. Further, identifying a user associated with a device and identifying other devices associated with that user are known techniques in the art, as demonstrated by REITSMA. It would have been obvious to a person having ordinary skill in the art (PHOSITA) before the effective filing date of the claimed invention to modify the security policy for elevated-risk devices of MAIMAN with the user-associated device identification of REITSMA with the motivation to extend the risk score of a device to other devices used by the same user, which may also be at risk of compromise.
PRICE teaches the following limitations not taught by the combination of MAIMAN and REITSMA:
updating the group membership of the dynamic group of endpoint devices having the elevated risk level to include the one or more additional endpoint devices associated with the identified user ([0160] "… User “D” has a security risk score of 75, at time t0. The policy assignment system has determined that User “D” has a security score falling within a third predetermined range (e.g., 61-79). ... Accordingly, Group Policy III is communicated for enforcement at the devices associated with User “D”."); and
Including other devices associated with a user in a group governed by a policy based on a risk score associated with the user is a known technique in the art, as demonstrated by PRICE. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the security policy for elevated-risk devices of MAIMAN and REITSMA with the extended device grouping of PRICE with the motivation to group any devices, which are associated with a compromised device through their user, into a single group to prevent any user-originated actions from compromising further devices.
Regarding claim 8:
MAIMAN teaches:
An apparatus comprising: a processor; and a memory configured to store instructions that, when executed by the processor, cause the processor to ([0005] "… The security system comprises: a processor; and a memory storing instructions executable by the processor."):
The remainder of this claim’s limitations are mapped and rejected with the same justification, mutatis mutandis, as its counterpart claim 1.
Regarding claim 15:
This claim is rejected with the same justification, mutatis mutandis, as its counterpart claims 1 and 8 above.
Claims 2, 9, and 16 are rejected under 35 U.S.C. 103 as being unpatentable over MAIMAN et al (Doc ID US 20220407893 A1), REITSMA et al (Doc ID US 20170353308 A1), and PRICE et al (Doc ID US 20200195693 A1) as applied to claims 1, 8, and 15 above, and further in view of ABRAMOWITZ (Doc ID US 20160112445 A1).
Regarding claim 2:
The combination of MAIMAN, REITSMA, and PRICE teaches:
The method of claim 1,
ABRAMOWITZ teaches the following limitations not taught by the combination of MAIMAN, REITSMA, and PRICE:
wherein the one or more characteristics of the endpoint device includes a version of an installed operating system being out of date ([0052] "... the technology can determine that an asset with an old version of an operating system having known vulnerabilities ... has a high risk assessment value (e.g., 0.95) …").
Considering an out-of-date operating system (OS) to be indicative of an elevated risk to a device is a known technique in the art, as demonstrated by ABRAMOWITZ. It would have been obvious to a person having ordinary skill in the art (PHOSITA) before the effective filing date of the claimed invention to modify the security policy for elevated-risk devices of MAIMAN, REITSMA, and PRICE with the current OS check of ABRAMOWITZ with the motivation to add specific functionality to the system which considers an out-of-date OS to indicate elevated risk for the device. It is obvious to use the currency of an OS as an indicator, as an out-of-date OS will often contain well-known vulnerabilities which may be exploited.
Regarding claims 9 and 16:
These claims are rejected with the same justification, mutatis mutandis, as their counterpart claim 2 above.
Claims 3, 5, 10, 12, 17, and 19 are rejected under 35 U.S.C. 103 as being unpatentable over MAIMAN et al (Doc ID US 20220407893 A1), REITSMA et al (Doc ID US 20170353308 A1), and PRICE et al (Doc ID US 20200195693 A1) as applied to claims 1, 8, and 15 above, and further in view of RICAFORT et al (Doc ID US 20160050224 A1).
Regarding claim 3:
The combination of MAIMAN, REITSMA, and PRICE teaches:
The method of claim 1,
RICAFORT teaches the following limitations not taught by the combination of MAIMAN, REITSMA, and PRICE:
wherein the one or more characteristics of the endpoint device includes a geolocation of the endpoint device ([0029] "… the risk score may be based on a mismatch between a geographic location of devices associated with the enterprise network 122 …").
Considering the geolocation of a device to be potentially indicative of an elevated risk to a device is a known technique in the art, as demonstrated by RICAFORT. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the security policy for elevated-risk devices of MAIMAN, REITSMA, and PRICE with the geolocation check of RICAFORT with the motivation to add specific functionality to the system which considers an whether a geolocation indicates elevated risk for the device. It is obvious to consider the geolocation of a device as a potential indicator, as many devices may have an expected location, where a deviation from this expectation is an indicator of compromise.
Regarding claim 5:
The combination of MAIMAN, REITSMA, and PRICE teaches:
The method of claim 1,
RICAFORT teaches the following limitations not taught by the combination of MAIMAN, REITSMA, and PRICE:
further comprising: disabling user credentials associated with the user on one or more computing systems and/or computing applications accessible on the computing network based on the elevated risk factor ([0040] "… The monitoring device 150 may also automatically restrict access to the resources of the enterprise network 122 and/or block communications from … the user of the user devices.").
Preventing a user of a compromised device from accessing network resources is a known technique in the art, as demonstrated by RICAFORT. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the security policy for elevated-risk devices of MAIMAN, REITSMA, and PRICE with the user-blocking policy of RICAFORT with the motivation to protect a network from compromise by additional untracked devices. It is obvious to block access of a user of a compromised device as they may also attempt access with a previously unidentified device which may also be compromised.
Regarding claims 10, 12, 17, and 19:
These claims are rejected with the same justification, mutatis mutandis, as their counterpart claims 3 and 5 above.
Claims 6, 7, 13, 14, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over MAIMAN et al (Doc ID US 20220407893 A1), REITSMA et al (Doc ID US 20170353308 A1), PRICE et al (Doc ID US 20200195693 A1), and RICAFORT et al (Doc ID US 20160050224 A1) as applied to claims 5, 12, and 19 above, and further in view of MAHABIR et al (Doc ID US 20170346824 A1).
Regarding claim 6:
The combination of MAIMAN, REITSMA, PRICE, and RICAFORT teaches:
The method of claim 5,
MAHABIR teaches the following limitations not taught by the combination of MAIMAN, REITSMA, PRICE, and RICAFORT:
further comprising: remediating the elevated risk factor associated with the dynamic group of endpoint devices ([0170] "The RAS 105 may also transmit notifications to the mobile device … when an updated device risk level is identified. These notifications to user may identify corrective actions for the user to reduce the updated device risk level …").
Allowing adjustment or remediation of a calculated risk factor is a known technique in the art, as demonstrated by MAHABIR. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the security policy for elevated-risk devices of MAIMAN, REITSMA, PRICE, and RICAFORT with the risk factor remediation of MAHABIR with the motivation to allow a decrease in a devices risk level. This is obvious to try, rather than a device which was assessed as risky being permanently restricted from a network.
Regarding claim 7:
The combination of MAIMAN, REITSMA, PRICE, RICAFORT, and MAHABIR teaches:
The method of claim 6,
MAHABIR teaches the following limitations not taught by the combination of MAIMAN, REITSMA, PRICE, RICAFORT, and MAHABIR:
The method of claim 6, further comprising: returning, in response to remediating the elevated risk factor, the dynamic group of endpoint devices to a membership status ([0170] "… Once the user has taken the corrective actions, the RAS 105 may again determine an updated device risk level, and may automatically approve the device to access the network if the updated device risk level is suitable.").
Removing restrictions from a device whose risk level was lowered is a known technique in the art, as demonstrated by MAHABIR. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the security policy for elevated-risk devices of MAIMAN, REITSMA, PRICE, RICAFORT, and MAHABIR with the risk factor remediation of MAHABIR with the motivation to allow a device with a lowered risk level back on the network. This is obvious to try, rather than a device which was assessed as risky being permanently restricted from a network.
Regarding claims 13, 14, and 20:
These claims are rejected with the same justification, mutatis mutandis, as their counterpart claims 6 and 7 above.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to BRANDON BINCZAK whose telephone number is (703)756-4528. The examiner can normally be reached M-F 0800-1700.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached on (571) 270-5143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/BB/Examiner, Art Unit 2437
/ALEXANDER LAGOR/Supervisory Patent Examiner, Art Unit 2437