Prosecution Insights
Last updated: August 15, 2026
Application No. 18/475,266

Cloud computer credential theft detection

Non-Final OA §102§103
Filed
Sep 27, 2023
Examiner
WON, MICHAEL YOUNG
Art Unit
2443
Tech Center
2400 — Computer Networks
Assignee
Palo Alto Networks (Israel Analytics) Ltd.
OA Round
5 (Non-Final)
80%
Grant Probability
Favorable
5-6
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 80% — above average
80%
Career Allowance Rate
676 granted / 847 resolved
+21.8% vs TC avg
Strong +28% interview lift
Without
With
+28.4%
Interview Lift
resolved cases with interview
Typical timeline
2y 11m
Avg Prosecution
32 currently pending
Career history
874
Total Applications
across all art units

Statute-Specific Performance

§101
8.6%
-31.4% vs TC avg
§103
47.7%
+7.7% vs TC avg
§102
31.1%
-8.9% vs TC avg
§112
8.7%
-31.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 847 resolved cases

Office Action

§102 §103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION 2. This action is in response to the amendment filed April 21, 2026. 3. Claims 1, 11, and 21 have been amended. 4. Claims 1-21 have been examined and are pending with this action. Response to Arguments 5. Applicant's arguments filed April 21, 2026 have been fully considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. Ramos (US 2024/0330899 A1) has been cited to better teach the presently pending claims as newly amended. Please see rejections below. For at least these reasons above and the rejections set forth below, claims 1-21 have been rejected remain pending. Claim Rejections - 35 USC § 102 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. 6. Claims 1-2, 4-12, and 14-21 are rejected under 35 U.S.C. 102(a)(1) and 102(a)(2) as being anticipated by Ramos (US 2024/0330899 A1). INDEPENDENT: As per claim 1, Ramos teaches a method comprising: detecting that a security token was received by a cloud-based service, over a network, from a cloud-based computer in conjunction with a request from the cloud-based computer to access the cloud-based service, wherein the security token was previously issued to one or more computers physically located within or associated with a specific geographic region and grants the one or more computers to which it was issued access to the cloud-based service upon the one or more computers conveying the security token to the cloud-based service (see Ramos, Abstract: “In some embodiments, the techniques include an encoding schema that encodes physical location coordinates to the unique identifier of a blockchain token. For example, the location coordinates may include the latitude and longitude of a physical space on earth. Blockchain tokens that have unique token identifiers represented by encoded geospatial information are referred to herein as location-encoded blockchain tokens. By encoding the physical location coordinates of a geographic location, the token owner or renter may populate the geographic space with curated content.”; [0002]: “Blockchain tokens are digital assets that are issued and transferred over a blockchain network. There are different types of blockchain tokens including fungible and nonfungible tokens (NFTs). Fungible tokens, such as cryptocurrency coins, are interchangeable and typically have the same value. In contrast, NFTs are unique and cannot be replicated or exchanged for another NFT having an identical value. NFTs may correspond to unique digital assets, such as a piece of artwork, collectible, music file, or other content item.”; [0018]: “In some embodiments, the techniques described herein are implemented by or as part of a blockchain service. A blockchain service refers to a network service, such as a platform-as-a-service (PaaS) or other cloud service, for maintaining blockchain-based distributed ledgers”; [0025]: “Digital wallets 108a-n interact with blockchain network 110 to store, manage, and transfer digital assets, including location-encoded blockchain tokens.”; [0137]: “The client may communicate requests to the computer network using a communications protocol, such as Hypertext Transfer Protocol (HTTP). The requests are communicated through an interface, such as a client interface (such as a web browser), a program interface, or an API.”; and [0138]: “Network resources assigned to each request and/or client may be scaled up or down based on, for example, (a) the computing services requested by a particular client, (b) the aggregated computing services requested by a particular tenant, and/or (c) the aggregated computing services requested of the computer network. Such a computer network may be referred to as a “cloud network.””); identifying a first geographic region being the specific geographic region of the one or more computers to which the security token was previously issued (see Ramos, [0051]: “The chaincode may allow authorized users to create new location-enabled tokens based on predefined rules and conditions.”; and [0122]: “Encoding location data as a blockchain token's ID allows for quick and efficient location-based retrieval of blockchain tokens that represent a physical location… The token IDs also allow for efficient location-based retrieval of tokens that fall within a geographic area as the determination may be made based on the values of the token ID itself.”); identifying a second geographic region with which the cloud-based computer from which the security token was received is physically located or associated (see Ramos, [0126]: “In some embodiments, a client application (e.g., an AR or VR application) extracts current latitude and longitude coordinates of the device host (operation 502). As previously mentioned, geographical coordinates may be extracted using one or more device sensors, such as reading the GPS coordinates from a GPS receiver or triangulating the user's position based on cellular or Wi-Fi signals received by the device hardware.”; and [0128]: “The distance may be computed based on a comparison of the blockchain token ID and the encoding generated as a function of the device's current location.”); and generating an alert upon detecting that the second geographic region does not match the first geographic region, wherein the alert indicates potential unauthorized use of the security token by the cloud-based computer from which the security token was received (see Ramos, [0097]: “In the event that the blockchain transaction is unsuccessful, then one or more nodes in blockchain network 110 deny the request (operation 214). A request denied message may be returned to the client application, and the blockchain transaction may be aborted.”; [0128]: “In some embodiments, the client application queries the blockchain using the encoding to identify blockchain tokens with matching token IDs or with token IDs that are within a threshold range of the current device position (operation 506). In some cases, the query may request an exact match.”; and [0131]: “In some cases, the application may render the content as a function of the device's current position relative to the content's position. The relative position may be determined based on a comparison of the token ID and the encoding generated from the device's current coordinates. The relative position may be used to determine the size, distance, angle, direction of movement, sound volume and/or other render attributes of the content. In other cases, the content may be rendered without computing the relative position. In these scenarios, the location-based encoding of the devices current coordinates may be resolved to the content populating the geographic space.”). As per claim 11, Ramos teaches a computer software product, the product comprising a non-transitory computer-readable medium, in which program instructions are stored, which instructions, when read by a computer, cause the computer: to detect that a security token was received by a cloud-based service, over a network, from a cloud-based computer in conjunction with a request from the cloud-based computer to access the cloud-based service, wherein the security token was previously issued to one or more computers physically located within or associated with a specific geographic region and grants the one or more computers to which it was issued access to the cloud-based service upon the one or more computers conveying the security token to the cloud-based service (see Claim 1 rejection above); to identify a first geographic region being the specific geographic region of the one or more computers to which the security token was previously issued (see Claim 1 rejection above); to identify a second geographic region with which the cloud-based computer from which the security token was received is physically located or associated (see Claim 1 rejection above); and to generate an alert upon detecting that the second geographic region does not match the first geographic region, wherein the alert indicates potential unauthorized use of the security token by the cloud-based computer from which the security token was received (see Claim 1 rejection above). As per claim 21, Ramos teaches a cloud-based resource, comprising: a memory (see Ramos, [0150]: “Such instructions, when stored in non-transitory storage media accessible to processor 604, render computer system 600 into a special-purpose machine that is customized to perform the operations specified in the instructions.”); and one or more processors (see Ramos, [0150]) configured: to detect, in the memory, that a security token was received by a cloud-based service, over a network, from a cloud-based computer, in conjunction with a request from the cloud-based computer to access the cloud-based service, wherein the security token was previously issued to one or more computers physically located within or associated with a specific geographic region and grants the one or more computers to which it was issued access to the cloud-based service upon the one or more computers conveying the security token to the cloud-based service (see Claim 1 rejection above), to identify a first geographic region being the specific geographic region of the one or more computers to which the security token was previously issued (see Claim 1 rejection above), to identify a second geographic region with which the cloud-based computer from which the security token was received is physically located or associated (see Claim 1 rejection above), and to generate an alert upon detecting that the second geographic region does not match the first geographic region, wherein the alert indicates potential unauthorized use of the security token by the cloud-based computer from which the security token was received (see Claim 1 rejection above). DEPENDENT: As per claim 2 and 12, which respectively depend on claims 1 and 11, Ramos further teaches wherein the cloud-based service executes on a cloud-based resource managed by a cloud service provider, and wherein detecting the security token comprises detecting, by an endpoint security agent executing on the cloud-based resource, the security token, and conveying a notification to a security server (see Ramos, [0138]: “Clients request computing services from a computer network independently of each other. Network resources are dynamically assigned to the requests and/or clients on an on-demand basis. Network resources assigned to each request and/or client may be scaled up or down based on, for example, (a) the computing services requested by a particular client, (b) the aggregated computing services requested by a particular tenant, and/or (c) the aggregated computing services requested of the computer network. Such a computer network may be referred to as a “cloud network.””; and [0147]: “The original packet is transmitted from the second encapsulation tunnel endpoint to the destination device in the same particular overlay network.”). As per claim 4 and 14, which respectively depend on claims 2 and 12, Ramos further teaches wherein the steps of identifying the first and the second geographic regions, and generating the alert are performed by the security server (see Ramos, [0022]: “Device hosts 102a-n are computing devices that host applications connected to blockchain network 112. In some embodiments, each device host is a digital device, which generally refers to any hardware device that includes one or more hardware processors. Examples of device hosts include computers, tablets, laptops, desktops, netbooks, servers… ”; and [0134]: “Such nodes (also referred to as “hosts”) may execute a client process and/or a server process. A client process makes a request for a computing service (such as, execution of a particular application, and/or storage of a particular amount of data). A server process responds by executing the requested service and/or returning corresponding data.”). As per claim 5 and 15, which respectively depend on claims 4 and 14, Ramos teaches further comprising defining, by the security server, prior to identifying the first geographic region, a set of geographic regions comprising the first and the second geographic regions (see Ramos, [0016]: “The protocols may enforce constraints on valid latitude and longitude integer ranges to restrict the geospatial locations”; [0028]: “As another example, membership service 118 may define access policies for different user roles.”; [0029]: “In some embodiments, membership service 118 may define and enforce different access policies for founding members and participant members.”; and [0052]: “The chaincode may allow authorized users to create new location-enabled tokens based on predefined rules and conditions. For example, the rules may constrain the tokens based on a range of valid latitudinal and longitudinal values. Additionally or alternatively, the rules may constrain the tokens to recognized resolutions, which correspond to a geographic span of an individual token.”). As per claim 6 and 16, which respectively depend on claims 5 and 15, Ramos further teaches wherein defining the set of geographic regions comprises conveying, by the security server, a query to the cloud service provider, and receiving, by the security server, a response comprising the set of geographic regions (see Ramos, [0015]: “Content retrieval may be performed efficiently by converting location data into the encoded token identifier format and querying the blockchain for the curated content.”; and [0024]: “Location services 106a-n may provide the location data to augmented reality applications 104a-n and/or digital wallets 108a-n, which may use the data to query blockchain network for digital assets populating one or more geospatial positions within a threshold range of the device.”). As per claim 7 and 17, which respectively depend on claims 5 and 15, Ramos teaches further comprising mapping a set of geolocations to the set of geographic regions, and wherein identifying the second an IP address to which the security token was deployed, and mapping the IP address to the first geographic region comprises identifying an Internet protocol (IP) address of the cloud-based computer, mapping the IP address to a given geolocation (see Ramos, [0016]: “Other protocols include a transfer protocol for transferring ownership of location-encoded blockchain tokens, an update protocol for populating location-encoded blockchain tokens with content, and a rental protocol for granting permissions to wallet addresses to maintain the token content for a finite amount of time. The protocols may enforce constraints on valid latitude and longitude integer ranges to restrict the geospatial locations and/or resolutions for which blockchain tokens may be minted, recorded, and transferred within the blockchain network.”; [0095]: “If the blockchain token is successful, then the location-enabled blockchain token is linked to the digital wallet of the owner or renter (operation 210). In some embodiments, the link is established by writing the digital wallet address in the token ownership data field on the blockchain. Thus, the wallet address is stored in the tamper-proof distributed ledger within on-chain storage 136. In the case of rentals, there may be two digital wallet addresses associated with the same token: one corresponding to the token owner and one corresponding to the renter.”; and Claim 1 rejection above). As per claim 8 and 18, which respectively depend on claims 4 and 14, Ramos further teaches wherein the cloud-based resource manages an event log, and wherein identifying the first geographic region comprises querying the event log and detecting, in the event log, an IP address to which the security token was deployed, and mapping the IP address to the first geographic region (see Ramos, [0045]: “State database 124 may store a record of all the transactions that have been validated and added to the blockchain, current balances, and other data associated with each account or digital wallet address on the network. State database 124 may be updated as new transactions are added to the blockchain.”; and Claims 1 & 7 rejections above). As per claim 9 and 19, which respectively depend on claims 4 and 14, although Ramos further teaches wherein identifying the first geographic region comprises conveying a deployment query to the cloud provider, receiving, from the cloud provider, a response comprising an IP address and mapping the IP address to the first geographic region (see Ramos, [0099]: “For example, the user may input an address or name of a location. In response, the client application may identify a matching location and update map interface 300 to present the NFT tokens available in the geographic space.”; and Claims 1 & 7 rejections above). As per claim 10 and 20, which respectively depend on claims 1 and 11, Ramos further teaches wherein the cloud-based computer comprises a physical host computer (see Ramos, [0015]: “the application may convert a host device's global positioning system (GPS) coordinates to a location encoding, which may be used to find blockchain tokens with matching values corresponding to the location and/or token identifiers within a threshold range from the encoding”; and [0022]: “Device hosts 102a-n are computing devices that host applications connected to blockchain network 112.”). Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 7. Claims 3 and 13 are rejected under 35 U.S.C. 103 as being unpatentable over Ramos (US 2024/0330899 A1) in view of Official Notice. As per claim 3 and 13, which respectively depend on claims 2 and 12, Ramos does not explicitly teach wherein the cloud-based resource comprises a first cloud-based resource, and wherein the security server comprises a second cloud-based resource. The examiner takes Official Notice. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the invention to modify the system of Ramos view of Official Notice so that the cloud-based resource comprises a first cloud-based resource, and wherein the security server comprises a second cloud-based resource. One would be motivated to do so because Ramos teaches in paragraph [0018], “Distributed ledgers may be replicated, shared, and/or synchronized across multiple peer nodes within a blockchain network.”, and further teaches in paragraph [0138], “Network resources assigned to each request and/or client may be scaled up or down”, emphasis added. Conclusion 8. For the reasons above, claims 1-21 have been rejected and remain pending. 9. Any inquiry concerning this communication or earlier communications from the examiner should be directed to MICHAEL Y WON whose telephone number is (571)272-3993. The examiner can normally be reached on Wk.1: M-F: 8-5 PST & Wk.2: M-Th: 8-7 PST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Nicholas R Taylor can be reached on 571-272-3889. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /Michael Won/Primary Examiner, Art Unit 2443
Read full office action

Prosecution Timeline

Show 6 earlier events
Nov 02, 2025
Response after Non-Final Action
Dec 01, 2025
Non-Final Rejection mailed — §102, §103
Jan 21, 2026
Response Filed
Feb 12, 2026
Final Rejection mailed — §102, §103
Feb 22, 2026
Interview Requested
Apr 21, 2026
Request for Continued Examination
Apr 30, 2026
Response after Non-Final Action
Jun 10, 2026
Non-Final Rejection mailed — §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12689969
TRANSPORT MECHANISM SELECTION FOR MULTI-ACCESS POINT COORDINATION GROUP (CG)
1y 8m to grant Granted Jul 21, 2026
Patent 12689678
DETERMINING PROCESSING WEIGHTS OF RULE VARIABLES FOR RULE PROCESSING OPTIMIZATION
1y 7m to grant Granted Jul 21, 2026
Patent 12676789
SELF-ADAPTIVE HEALTH MONITORING SYSTEMS INCLUDING NETWORKS OF TENSOR NETWORKS
1y 8m to grant Granted Jul 07, 2026
Patent 12676799
METHODS AND SYSTEMS FOR OBJECT-AWARE FUZZY PROCESSING BASED ON ANALOGIES
1y 6m to grant Granted Jul 07, 2026
Patent 12665909
Federated Learning Process
2y 0m to grant Granted Jun 23, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
80%
Grant Probability
99%
With Interview (+28.4%)
2y 11m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 847 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month