Prosecution Insights
Last updated: October 02, 2026
Application No. 18/477,632

SELECTIVE FILTERING OF DATA BASED ON DATA RULES

Final Rejection §103
Filed
Sep 29, 2023
Examiner
JHAVERI, JAYESH M
Art Unit
2433
Tech Center
2400 — Computer Networks
Assignee
International Business Machines Corporation
OA Round
3 (Final)
83%
Grant Probability
Favorable
4-5
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 83% — above average
83%
Career Allowance Rate
461 granted / 556 resolved
+24.9% vs TC avg
Strong +31% interview lift
Without
With
+30.8%
Interview Lift
resolved cases with interview
Typical timeline
2y 5m
Avg Prosecution
9 currently pending
Career history
564
Total Applications
across all art units

Statute-Specific Performance

§101
11.2%
-28.8% vs TC avg
§103
44.5%
+4.5% vs TC avg
§102
20.2%
-19.8% vs TC avg
§112
13.6%
-26.4% vs TC avg
Black line = Tech Center average estimate • Based on career data from 556 resolved cases

Office Action

§103
DETAILED ACTION Claims 1-28 are pending in this office action. Claims 3, 10 and 17 are canceled. Claim 28 has been newly added. Applicants’ arguments, filed 07/01/2026, have been fully considered but they are not persuasive. Response to Arguments Applicant presents arguments regarding the presence or absence of claimed limitations in the prior art. However, applicant has amended certain claims and added new claims. The responses as well as any applicable new grounds of rejection are outlined below. Applicant argues: Applicant notes that Snellman does not teach the limitations of amended claims 1, 8, 15, 22, and 24. While Snellman was cited as allegedly teaching the pre-amended limitation "determining a set of data rules from the one or more data regulation requirements," Applicant notes that Snellman does not perform "determining, by parsing the one or more data regulation requirements using artificial intelligence, a set of data rules from the one or more data regulation requirements. Regarding claim 26, paragraph 236 of Snellman was cited as allegedly teaching "wherein determining the access state to the subset of data for the user is completed by a trained machine learning model based on a description of the subset of data." See Office Action, page 8. Applicant respectfully asserts that paragraph 236 of Snellman does not relate to "wherein determining the access state to the subset of data for the user is completed by a trained machine learning model based on a description of the subset of data." paragraph 236 of Snellman relates to using a "machine learning algorithm... to predict the likelihood of various types of access requests." Such predictions can be used to "determine a risk metric based on the likelihood." However, Snellman is silent on "determining the access state to the subset of data for the user" by a "trained machine learning model based on a description of the subset of data. Examiner Response: Regarding argument (a), examiner respectfully disagrees with applicant. As to claimed limitation, “determining the access state to the data subset for the user” may be construed as determining whether a request for data access will lead to permitted or denied data access. As disclosed in the cited section and other continuation paragraphs in Snellman, training of model and risk matrix calculations are based on historical requests and various request attributes such as type or description and are also applicable to future requests. Although used for determining likelihood, they also determine evidence of malicious behavior, blocking of requests, allowing data access etc. (para 00238-0239) based on model/matrix, and thus using the model directly or indirectly to achieve determining data access or access state of the data. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-2, 4, 6-9, 11, 13-16, 18, 20-26, 28 are rejected under 35 U.S.C. 103 as being unpatentable over Snellman et al. (US 2021/0209077 A1, Snellman hereinafter), in view of Good et al. (US 2020/0410170 A1, Good hereinafter). For claim 1, Snellman teaches a processor-implemented method, the method comprising: identifying two or more users (Abstract; para 0006, 0008, 0035 - plurality of system or application users); identifying one or more data regulation requirements (para 0006-0007, 0010-0011, 0063 - data policy as data regulation requirement); determining, a set of data rules from the one or more data regulation requirements (Abstract; para 0054, 0063 - rules associated with regulation requirements); identifying a data set (Abstract; para 0011, 0054 - identifying data for accessing); determining, in response to a request for a subset of data from the data set, an access state to the subset of data for a user from the two or more users based on one or more data rules from the set of data rules (para 0009, 0011, 0040, 0288, 0304 - accessing data subset from the data set with rules pertaining to access regulations or permissions associated with users); and generating filtered data based on the subset of data according to the determined access state (Abstract; para 0079, 0290, 0304, 0343, 0345 - permission state determining access state and determining filtered/masked data based on regulatory rules associated with permission levels). Although parsing or analyzing the regulation requirements is implied in determination of rules as those are derived from the regulation requirements for data access application, Snellman does not appear to explicitly disclose, however Good discloses parsing the one or more data regulation requirements using artificial intelligence to determine data rules (Good – Abstract; para 0006, 0028, 0035, 0045 – translating access policy text using natural language processing algorithms to access control code or rules). Based on Snellman in view of Good, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to utilize teachings of Good in the system of Snellman, thereby incorporating widely known techniques of artificial intelligence including natural language processing to make data access security enforcement more dynamic and efficient in Snellman’s system. For claim 2, Snellman in view of Good teaches the claimed subject matter as discussed above. Snellman further teaches providing the filtered data to the user from the two or more users (Abstract; para 0290, 0304, 0343, 0345). For claim 4, Snellman in view of Good teaches the claimed subject matter as discussed above. Snellman further teaches the claimed subject matter as discussed above. Snellman further teaches identifying a change in at least one data regulation requirement, wherein a change may include introduction of a new data regulation requirement or removal of an existing data regulation requirement; and modifying at least one data rule based on the change (para 0308-0310, 0351, 0355 - policy or data regulation update, and application-level user rules are specified to be applied based on the policy update). For claim 6, Snellman in view of Good teaches the claimed subject matter as discussed above. Snellman further teaches preparing evidence of authenticity of the filtered data (para 0063, 0079, 0111, 0115, 0245 - data validator, authenticity and utilizing mechanisms such as hash comparison for data integrity or correctness). For claim 7, Snellman in view of Good teaches the claimed subject matter as discussed above. Snellman further teaches wherein the data regulation requirements include at least one agreement between at least two of the two or more users (para 0080, 0115, 0117, 0155 - consensus or agreement among parties with regards to regulations rules or permissions). As to claim 8, the claim limitations are similar to those of claim 1, except claim 8 is drawn to a computer system, the computer system comprising: one or more processors, one or more computer-readable memories, one or more computer-readable tangible storage media, and program instructions stored on at least one of the one or more tangible storage media for execution by at least one of the one or more processors via at least one of the one or more memories (Snellman - Fig. 1, 15; para 0013, 0098, 0365-0366), wherein the computer system is capable of performing the method of claim 1. Therefore claim 8 is rejected according to claim 1. As to claims 9, 11, 13-14, the claim limitations are similar to those of claims 2, 4, 6-7 respectively. Therefore claims 9, 11, 13-14 are rejected according to claims 2, 4, 6-7 respectively as above. As to claim 15, the claim limitations are similar to those of claim 1, except claim 15 is drawn to a computer program product, the computer program product comprising: one or more computer-readable tangible storage media and program instructions stored on at least one of the one or more tangible storage media (Snellman - Fig. 1, 15; para 0013, 0098, 0365-0366), the program instructions executable by a processor capable of performing the method of claim 1. Therefore claim 15 is rejected according to claim 1. As to claims 16, 18, 20-21, the claim limitations are similar to those of claims 2, 4, 6-7 respectively. Therefore claims 16, 18, 20-21 are rejected according to claims 2, 4, 6-7 respectively as above. For claim 22, Snellman teaches a processor-implemented method, the method comprising: identifying one or more data regulation requirements (para 0006-0007, 0010-0011, 0063 - data policy as data regulation requirement); determining a set of data rules from the one or more data regulation requirements (Abstract; para 0054, 0063 - rules associated with regulation requirements); identifying a data set (Abstract; para 0011, 0054 - identifying data for accessing); determining, based on one or more data rules from the set of data rules, an access state to a subset of data from the identified data set (para 0009, 0011, 0040, 0288, 0304 - accessing data subset from the data set with rules pertaining to access regulations or permissions associated with users); and generating filtered data according to the determined access state (Abstract; para 0079, 0290, 0304, 0343, 0345 - permission state determining access state and determining filtered/masked data based on regulatory rules associated with permission levels); preparing documentation of the generating (para 0220, 0278, 0280, 0290, 0352 - instructions based on comments (documented) pertaining to processing of the rules and generation of modified or filtered data, and also creating logs or audit logs pertaining to data modifications). Although parsing or analyzing the regulation requirements is implied in determination of rules as those are derived from the regulation requirements for data access application, Snellman does not appear to explicitly disclose, however Good discloses parsing the one or more data regulation requirements using artificial intelligence to determine data rules (Good – Abstract; para 0006, 0028, 0035, 0045 – translating access policy text using natural language processing algorithms to access control code or rules). Based on Snellman in view of Good, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to utilize teachings of Good in the system of Snellman, thereby incorporating widely known techniques of artificial intelligence including natural language processing to make data access security enforcement more dynamic and efficient in Snellman’s system. For claim 23, Snellman in view of Good teaches the claimed subject matter as discussed above. Snellman further teaches wherein the preparing includes identifying the underlying data regulation requirements that led to the data rules that in turn led to the determined access state (para 0205-0206, 0288-0290, 0351--0352 - rules based on policies, maintained by security driver, and providing comments, creating logs etc. as part of tracking applied policies/rules by security driver). As to claim 24, the claim limitations are similar to those of claim 22, except claim 24 is drawn to a computer program product, the computer program product comprising: one or more computer-readable tangible storage media and program instructions stored on at least one of the one or more tangible storage media (Snellman - Fig. 1, 15; para 0013, 0098, 0365-0366), the program instructions executable by a processor capable of performing the method of claim 22. Therefore claim 24 is rejected according to claim 22. As to claims 25, the claim limitations are similar to those of claim 23. Therefore claim 25 is rejected according to claim 23 as above. For claim 26, Snellman in view of Good teaches the claimed subject matter as discussed above. Snellman further teaches wherein determining the access state to the subset of data for the user is completed by a trained machine learning model based on a description of the subset of data (para 0236 - risk metrics based on access requests for entities, applications, devices etc., based on historical log events, to predict the likelihood of various types of access requests such as to particular units of content or data sets, types of data, amounts and frequencies of access requests etc. and predicting using the trained model, maliciousness and thus the access state of the request). For claim 28, Snellman in view of Good teaches the claimed subject matter as discussed above. Snellman further teaches identifying plurality of system or application users (Abstract; para 0006, 0008, 0035), wherein data access state is determined for a subset of data from the data set for a user from the two or more users based on one or more data rules from the set of data rules such that rules pertaining to access regulations or permissions associated with users are determined (para 0009, 0011, 0040, 0288, 0304), and although this implies underlying rules or conditions that are applied to data access requests based on requests associated with each of the users, Snellman does not appear to explicitly teach, however Good teaches wherein the set of data rules includes a first subset of data rules that apply to a first user of the two or more users based on data regulation requirements applicable to the first user and a second subset of data rules that apply to a second user of the two or more users based on data regulation requirements applicable to the second user (para 0026, 0037, 0046-0047, 0050 – data rules associated with different users based on regulatory requirements that are applied as specifically associated with, or enforceable for each user accessing the data). Based on Snellman in view of Good, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to utilize teachings of Good in the system of Snellman, in order to utilize user-specific data access rules, thereby providing granular control over data access per different users’ access states, as needed to retain data privacy and security in the system. Claims 5, 12, 19 are rejected under 35 U.S.C. 103 as being unpatentable over Snellman et al. (US 2021/0209077 A1, Snellman hereinafter), in view of Good et al. (US 2020/0410170 A1, Good hereinafter), and further in view of Roth et al. (SG-10201803844T-A, Roth hereinafter). For claims 5, 12 and 19, Snellman teaches the claimed subject matter as discussed above in claim 4. Snellman further teaches location-based rules wherein the requested data undergoes restriction or processing based on location of the requested object (para 0054). Snellman does not appear to explicitly disclose, however Roth discloses wherein the change is based on a change in a location of the identified data (para 0020, 0025, 0042, 0072, 0082, 0089, 0091 - policy generations/modifications associated with jurisdiction regulations and enforcement of data compliance). Based on Snellman in view of Roth, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to utilize teachings of Roth in the system of Snellman, in order to apply additional entity or data security mechanisms including criteria such as location or jurisdiction area-based conditions to enforce security features, thereby improving security robustness of Snellman’s system. Allowable Subject Matter Claim 27 is objected to as being dependent upon a rejected base claim and parent claim but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims in addition to overcoming the above-mentioned objections/rejections associated with their parent claims. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to JAYESH M JHAVERI whose telephone number is (571)270-7584. The examiner can normally be reached Mon-Fri 9 AM to 5 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, JEFFREY PWU can be reached on (571) 272-6798. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /JAYESH M JHAVERI/Primary Examiner, Art Unit 2433
Read full office action

Prosecution Timeline

Show 4 earlier events
Dec 16, 2025
Response Filed
Apr 03, 2026
Non-Final Rejection mailed — §103
Jun 16, 2026
Applicant Interview (Telephonic)
Jun 16, 2026
Examiner Interview Summary
Jun 19, 2026
Examiner Interview Summary
Jul 01, 2026
Response Filed
Sep 09, 2026
Final Rejection mailed — §103
Sep 30, 2026
Interview Requested

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12730890
Cyberattack Signature Generation Using Host Level Data Analytics
2y 9m to grant Granted Sep 08, 2026
Patent 12724893
ANALYSING OPERATING SYSTEM CONFIGURATIONS
2y 9m to grant Granted Sep 01, 2026
Patent 12717958
IMPLEMENTING INHERITED GRANTS USING SECURE SCHEMAS
1y 11m to grant Granted Aug 25, 2026
Patent 12689512
SIGNAL PROTECTION AND RETRIEVAL BY NON-LINEAR ANALOG MODULATION
1y 9m to grant Granted Jul 21, 2026
Patent 12682088
POLICY CONSISTENCY VERIFICATION APPARATUS, POLICY CONSISTENCY VERIFICATION METHOD, AND POLICY CONSISTENCY VERIFICATION PROGRAM
2y 6m to grant Granted Jul 14, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

4-5
Expected OA Rounds
83%
Grant Probability
99%
With Interview (+30.8%)
2y 5m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 556 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month