Prosecution Insights
Last updated: August 15, 2026
Application No. 18/503,347

METHOD FOR PROTECTING SENSITIVE DATA IN A THREAT DETECTION NETWORK AND THREAT DETECTION NETWORK

Non-Final OA §101§103
Filed
Nov 07, 2023
Priority
Nov 10, 2022 — GB 2216750.6
Examiner
DHARIA, RUPAL
Art Unit
2434
Tech Center
2400 — Computer Networks
Assignee
Withsecure Corporation
OA Round
1 (Non-Final)
76%
Grant Probability
Favorable
1-2
OA Rounds
0m
Est. Remaining
73%
With Interview

Examiner Intelligence

Grants 76% — above average
76%
Career Allowance Rate
16 granted / 21 resolved
+18.2% vs TC avg
Minimal -3% lift
Without
With
+-3.3%
Interview Lift
resolved cases with interview
Typical timeline
2y 3m
Avg Prosecution
7 currently pending
Career history
39
Total Applications
across all art units

Statute-Specific Performance

§101
10.1%
-29.9% vs TC avg
§103
46.5%
+6.5% vs TC avg
§102
14.0%
-26.0% vs TC avg
§112
16.3%
-23.7% vs TC avg
Black line = Tech Center average estimate • Based on career data from 21 resolved cases

Office Action

§101 §103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claims 1-13 and 15-21 have been examined. Claim 14 is cancelled. Drawings The drawings filed on 11/07/2023 are acceptable for examination proceedings. Specification The specification filed on 11/07/2023 is acceptable for examination proceedings. Priority Application 18503347 filed 11/07/2023 claims foreign priority to 2216750.6, filed 11/10/2022. Therefore, the effective filling date for the subject matter defined in the pending claims of this application is 11/10/2022. Information Disclosure Statement The information disclosure statement (IDS) submitted on 11/07/2023. Accordingly, the information disclosure statement is being considered by the examiner. Claim Rejections – 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claim 15 is rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter as follows. Claim 15 as a whole define “ A computer-readable medium, having a computer program stored thereon, ….”. The specification in paragraphs [0011] states “the encryption keys are generated and/or stored inside a secure hardware module such as USB device or an HSM module. The above statement of the specification may include transitory and non- transitory propagation signals, and “a transitory, propagating signal … is not a “process, machine, manufacture, or composition of matter.” Those four categories define the explicit scope and reach of subject matter patentable under 35 U.S.C. § 101; thus, such a signal cannot be patentable subject matter.” Therefore, the examiner suggests: Amending the claim to embody the program on “non- transitory computer-readable storage medium” or equivalent that excludes computer readable medium as a “signal”, “carrier wave”, or “transmission medium” which are deemed non-statutory. Claim Interpretation The following is a quotation of 35 U.S.C. 112(f): (f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. The claims in this application are given their broadest reasonable interpretation using the plain meaning of the claim language in light of the specification as it would be understood by one of ordinary skill in the art. The broadest reasonable interpretation of a claim element (also commonly referred to as a claim limitation) is limited by the description in the specification when 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is invoked. As explained in MPEP § 2181, subsection I, claim limitations that meet the following three-prong test will be interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph: (A) the claim limitation uses the term “means” or “step” or a term used as a substitute for “means” that is a generic placeholder (also called a nonce term or a non-structural term having no specific structural meaning) for performing the claimed function; (B) the term “means” or “step” or the generic placeholder is modified by functional language, typically, but not always linked by the transition word “for” (e.g., “means for”) or another linking word or phrase, such as “configured to” or “so that”; and (C) the term “means” or “step” or the generic placeholder is not modified by sufficient structure, material, or acts for performing the claimed function. Use of the word “means” (or “step”) in a claim with functional language creates a rebuttable presumption that the claim limitation is to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites sufficient structure, material, or acts to entirely perform the recited function. Absence of the word “means” (or “step”) in a claim creates a rebuttable presumption that the claim limitation is not to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is not interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites function without reciting sufficient structure, material or acts to entirely perform the recited function. Claim limitations in this application that use the word “means” (or “step”) are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. Conversely, claim limitations in this application that do not use the word “means” (or “step”) are not being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. This application includes one or more claim limitations that do not use the word “means,” but are nonetheless being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, because the claim limitation(s) uses a generic placeholder that is coupled with functional language without reciting sufficient structure to perform the recited function and the generic placeholder is not preceded by a structural modifier. Such claim limitations are: “ a means for storing encryption keys” in claim 1. “ a means for storing encryption keys,” in claim 10. Because this/these claim limitation(s) is/are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, it/they is/are being interpreted to cover the corresponding structure described in the specification as performing the claimed function, and equivalents thereof. The corresponding structures interpreted from the specification for the above limitations are as follows: “a means for storing encryption keys” (fig. 3 element [0047] The endpoint sends the encryption key to the means for storing encryption keys. When the endpoint records an event, it checks the event related information for identifying sensitive data. The endpoint uses the encryption key to encrypt the event related information identified as sensitive data). If applicant does not intend to have this/these limitation(s) interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, applicant may: (1) amend the claim limitation(s) to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph (e.g., by reciting sufficient structure to perform the claimed function); or (2) present a sufficient showing that the claim limitation(s) recite(s) sufficient structure to perform the claimed function so as to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. Internet Communications Applicant is encouraged to submit a written authorization for Internet communications (PTO/SB/439, http://www.uspto.gov/sites/defauit/files/documents/sb0439.pdf) in the instant patent application to authorize the examiner to communicate with the applicant via email. The authorization will allow the examiner to better practice compact prosecution. The written authorization can be submitted via one of the following methods only. (1) Central Fax which can be found in the Conclusion section of this Office action; (2) regular postal mail; (3) EFS WEB; or (4) the service window on the Alexandria campus. EFS web is the recommended way to submit the form since this allows the form to be entered into the file wrapper within the same day (system dependent). Written authorization submitted via other methods, such as direct fax to the examiner or email, will not be accepted. See MPEP § 502.03. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of pre-AIA 35 U.S.C. 103(a) which forms the basis for all obviousness rejections set forth in this Office action: (a) A patent may not be obtained though the invention is not identically disclosed or described as set forth in section 102, if the differences between the subject matter sought to be patented and the prior art are such that the subject matter as a whole would have been obvious at the time the invention was made to a person having ordinary skill in the art to which said subject matter pertains. Patentability shall not be negatived by the manner in which the invention was made. Claims 1-13 and 16-20 are rejected under 35 U.S.C. 103 as being unpatentable over Collier (US 2022/0129551, A1, hereinafter refer as to Collier) and in view of Stahlberg et al. (US Pub. No.: US 2022/0191224 A1, hereinafter refer as to Stahlberg). As per claims 1, Collier discloses method for protecting sensitive data in a threat detection network (figs. 3 and 4 depicts an illustrative network-threat detection, for example), which threat detection network includes at least one end point (fig. 3 shows a system 300 for enterprise network threat detection and a number of endpoints such as the endpoint 302 , for example), at least one server and a means for storing encryption keys, wherein in the method: the endpoint generates a data encryption key to be used for encrypting sensitive data (fig. 3 and 4 depicted the system may include an endpoint 402, a firewall 404, a server 406 and a threat management facility 408 coupled to one another directly or indirectly through a data network 405, for example). Collier discloses the security agent modules, 6a-6h, 4a collect various types of data at the nodes 5a-5h or gateway 4 including, for example, program or file hashes, files stored at the nodes 5a-5h, l , however, Collier failed to expressly discloses the endpoint sends the encryption key to the means for storing encryption keys, when the endpoint records an event, the endpoint checks the event related information for identifying sensitive data, the endpoint uses the encryption key to encrypt the event related information identified as sensitive data, the endpoint sends at least part of the event related information with encrypted sensitive data to the at least one server. Stahlberg discloses the endpoint sends the encryption key to the means for storing encryption keys (fig. 1 depicted a security agent module 4a has been installed on the gateway 4. The security agent modules, 6a-6h, 4a collect various types of data at the nodes 5a-5h or gateway 4 including, for example, program or file hashes, files stored at the nodes 5a-5h, logs of network traffic, process logs, binaries or files carved from memory (e.g. DLL, EXE, or memory forensics artefacts), and/or logs from monitoring actions executed by programs or scripts running on the nodes 5a-5h or gateway 4 (e.g. tcp dumps) and para. 0012 discloses threat detection in a threat detection network and para. 0021 discloses network node of a threat detection network, the network comprising interconnected network nodes and a backend system. The network node comprises at least one security agent module which is configured to collect data related to the respective network node and the network node is configured to collect and/or analyze data related to the network node the threat detection network and para. 0039, for example) when the endpoint records an event, the endpoint checks the event related information for identifying sensitive data (paras. 0075-0076, 0084 discloses a suspicious event among the monitored events may be detected by one or more detection mechanisms used, for example) the endpoint uses the encryption key to encrypt the event related information identified as sensitive data, the endpoint sends at least part of the event related information with encrypted sensitive data to the at least one server (para. 0012 discloses a computer implemented method, of threat detection in a threat detection network, the threat detection network comprising interconnected network nodes and a backend system. At least part of the nodes comprise security agent modules which collect data related to the respective network node. The method comprises collecting and/or analyzing at the network node data related to a network node, for example). Stahlberg as modified and Collier are analogous art because they both are directed to threat detection network and a threat detection network, and one of ordinary skill in the art would have had a reasonable expectation of success to modify the teachings of Stahlberg with the specified features of Collier because they are from the same field of endeavor. In view of the above, having the method for protecting sensitive data in a threat detection network of Stahlberg and the well- established teaching of Collier, it would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention was made to modify the teachings of Stahlberg with the teachings of Collier order for to detect threats and anomalies in computers and networks [Collier: para. 0003]. Regarding claim 2, the combination of Collier as modified by Stahlberg discloses wherein the at least one endpoint collects threat detection related data from the endpoint by a security agent module installed at the endpoint (para. 0021 of Stahlberg discloses a network node of a threat detection network, the network comprising interconnected network nodes and a backend system. The network node comprises at least one security agent module which is configured to collect data related to the respective network node and the network node is configured to collect and/or analyze data related to the network node, for example). Regarding claim 3, the combination of Collier as modified by Stahlberg discloses wherein based on an identified or determined security incident the data decryption key for sensitive data is retrieved from the means for storing encryption keys for the affected endpoints for the affected time period (para. Stahlberg discloses the behavior or activity is still considered to be anomalous or even suspected to be an attacker, the system can raise an alert or send an instruction so that network nodes, the system and/or e.g. incident responders can investigate and react to the anomaly, for example) and at least part of the sensitive data is decrypted with the retrieved encryption key (para. 0067 of Stahlberg discloses the sensor collects events for a few seconds and then sends these collected events in one transmission to reduce the number of network connections and/or requests. The submission processing components can be responsible for an initial pre-processing of all data submissions that are received from various kinds of endpoint sensors, for example). Regarding claim 4, the combination of Collier as modified by Stahlberg discloses wherein the means for storing encryption keys is arranged in the network in which threat detection related data is collected or to a separate network and/or a separate organization in which case the encryption keys will be stored in encrypted format (fig. 1 of Stahlberg and para. 0037 of Stahlberg discloses The backend/server 2 forms a node on the security service computer network relative to the first computer network. The security service computer network can be managed by an EDR system provider and may be separated from the cloud 3 by a gateway or other interface or other network elements appropriate for the backend 2. The first computer network 1 may also be separated from the cloud 3 by a gateway 4 or other interface. Other network structures are also possible, for example). Regarding claim 5, the combination of Collier as modified by Stahlberg discloses wherein the encryption keys are generated and/or stored inside a secure hardware module (para. 0072 of Stahlberg at least one common model of normal user behavior can be generated on the basis of the local behavior models related to multiple network nodes. The common model of normal behavior may be generated by the security server backend of the computer network and/or by any network node, for example). Regarding claim 6, the combination of Collier as modified by Stahlberg discloses wherein the encryption key is a symmetric or a public/private key pair (para. 0033 Collier discloses the compute instances 10-26 may communicate with an unprotected server such as a web site or a third-party application through an internetwork 154 such as the Internet or any other public network, private network, or combination of these, for example). Regarding claim 7, the combination of Collier as modified by Stahlberg discloses wherein the new encryption key is generated periodically, and the endpoint uses the currently active encryption key to encrypt the event related information that is identified as sensitive data (fig. 8 of Collier An event vector 810, or individual events 806 therein, may also or instead be encrypted in order to secure the contents against malicious interception, for example). Regarding claim 8, the combination of Collier as modified by Stahlberg discloses wherein the sensitive data is identified by keyword matching, by regular expressions (para. 0018 of Stahlberg identifies shared accounts used at the nodes and/or in the network and links multiple behavioral models to the identified shared account, for example), reading pre-defined content classification fields from document or other files and/or querying file confidentiality status from a content classification system (para. 0038 of Stahlberg discloses the security agent modules, 6a-6h, 4a collect various types of data at the nodes 5a-5h or gateway 4 including, for example, program or file hashes, files stored at the nodes 5a-5h, logs of network traffic, process logs, binaries or files carved from memory (e.g. DLL, EXE, or memory forensics artefacts), and/or logs from monitoring actions executed by programs or scripts running on the nodes 5a-5h or gateway 4 (e.g. tcp dumps), for example). Regarding claim 9, the combination of Collier as modified by Stahlberg discloses wherein the at least one endpoint and/or a user of the at least one endpoint uploads the relevant decryption keys to a service which has collected detection related data (para. 0122 of Collier discloses the types of changes include at least one of a file read, a file write, a file copy, a file encrypt, a file decrypt, a network communication, a registry update, a software installation, a change in permissions, and a query to a remote resource, for example). As per claims 10 and 11, Collier discloses an endpoint of a threat detection network (figs. 3 and 4 depicts an illustrative network-threat detection, for example), the network including at least one endpoint and at least one server (fig. 4 depicted 4 illustrates a threat management system. In general, the system may include an endpoint 402, a firewall 404, a server 406 and a threat management facility 408 coupled to one another directly or indirectly through a data network 405, for example), wherein the endpoint includes at least one or more processors and at least one security agent module which is configured to collect data related to the respective network node (fig. 3 shows a system 300 for enterprise network threat detection and a number of endpoints such as the endpoint 302 , for example), and the endpoint is configured to generate a data encryption key to be used for encrypting sensitive data, the endpoint is configured to send the encryption key to a means for storing encryption keys (figs 4-6 depicted the security agent modules, 6a-6h, 4a collect various types of data at the nodes 5a-5h or gateway 4 including, for example, program or file hashes, files stored at the nodes 5a-5h, for example). Collier failed to expressly discloses when the endpoint records an event, the endpoint is configured to check the event related information for identifying sensitive data, and to encrypt the event related information identified as sensitive data with the encryption key, and the endpoint is configured to send at least part of the event related information with encrypted sensitive data to the at least one server. Stahlberg discloses when the endpoint records an event, the endpoint is configured to check the event related information for identifying sensitive data (paras. 0075-0076, 0084 discloses a suspicious event among the monitored events may be detected by one or more detection mechanisms used, for example), and to encrypt the event related information identified as sensitive data with the encryption key, and the endpoint is configured to send at least part of the event related information with encrypted sensitive data to the at least one server (para. 0012 discloses a computer implemented method, of threat detection in a threat detection network, the threat detection network comprising interconnected network nodes and a backend system. At least part of the nodes comprises security agent modules which collect data related to the respective network node. The method comprises collecting and/or analyzing at the network node data related to a network node, for example). Stahlberg as modified and Collier are analogous art because they both are directed to threat detection network and a threat detection network, and one of ordinary skill in the art would have had a reasonable expectation of success to modify the teachings of Stahlberg with the specified features of Collier because they are from the same field of endeavor. In view of the above, having the method for protecting sensitive data in a threat detection network of Stahlberg and the well- established teaching of Collier, it would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention was made to modify the teachings of Stahlberg with the teachings of Collier order for to detect threats and anomalies in computers and networks [Collier: para. 0003]. Regarding claim 12, the combination of Collier as modified by Stahlberg discloses a threat detection network (para. 0021-0023 discloses a threat detection network, for example). Regarding the remaining limitations of claim 12, the limitations are similar to claim 10. Thus, all remaining limitations are set forth and rejected as per discussion for claim 10. Regarding claim 13, the combination of Collier as modified by Stahlberg discloses a threat detection network wherein the threat detection network is (para. 0021-0023 discloses a threat detection network, for example). Regarding the remaining limitations of claim 13, the limitations are similar to claim 2. Thus, all remaining limitations are set forth and rejected as per discussion for claim 2. Regarding claim 15, the combination of Collier as modified by Stahlberg discloses a computer-readable medium on which is stored a computer program including instructions which, when executed by a computer (para, 0025 of Stahlberg discloses a computer-readable medium comprising the computer program, for example). Regarding the remaining limitations of claim 15, the limitations are similar to claim 1. Thus, all remaining limitations are set forth and rejected as per discussion for claim 1. Regarding claim 16, the combination of Collier as modified by Stahlberg discloses wherein based on an identified or determined security incident the data decryption key for sensitive data is retrieved from the means for storing encryption keys for the affected endpoints for the affected time period (para. Stahlberg discloses the behavior or activity is still considered to be anomalous or even suspected to be an attacker, the system can raise an alert or send an instruction so that network nodes, the system and/or e.g. incident responders can investigate and react to the anomaly, for example) and at least part of the sensitive data is decrypted with the retrieved encryption key (para. 0067 of Stahlberg discloses the sensor collects events for a few seconds and then sends these collected events in one transmission to reduce the number of network connections and/or requests. The submission processing components can be responsible for an initial pre-processing of all data submissions that are received from various kinds of endpoint sensors, for example). Regarding claim 17, the combination of Collier as modified by Stahlberg discloses wherein the means for storing encryption keys is arranged in the network in which threat detection related data is collected or to a separate network and/or a separate organization in which case the encryption keys will be stored in encrypted format (fig. 1 of Stahlberg and para. 0037 of Stahlberg discloses The backend/server 2 forms a node on the security service computer network relative to the first computer network. The security service computer network can be managed by an EDR system provider and may be separated from the cloud 3 by a gateway or other interface or other network elements appropriate for the backend 2. The first computer network 1 may also be separated from the cloud 3 by a gateway 4 or other interface. Other network structures are also possible, for example). Regarding claim 18, the combination of Collier as modified by Stahlberg discloses wherein the encryption keys are generated and/or stored inside a secure hardware module (para. 0072 of Stahlberg at least one common model of normal user behavior can be generated on the basis of the local behavior models related to multiple network nodes. The common model of normal behavior may be generated by the security server backend of the computer network and/or by any network node, for example). Regarding claim 19, the combination of Collier as modified by Stahlberg discloses wherein the encryption key is a symmetric or a public/private key pair (para. 0033 Collier discloses The compute instances 10-26 may communicate with an unprotected server such as a web site or a third-party application through an internetwork 154 such as the Internet or any other public network, private network, or combination of these, for example). Regarding claim 20, the combination of Collier as modified by Stahlberg discloses wherein the new encryption key is generated periodically, and the endpoint uses the currently active encryption key to encrypt the event related information that is identified as sensitive data (fig. 8 of Collier An event vector 810, or individual events 806 therein, may also or instead be encrypted in order to secure the contents against malicious interception, for example). Regarding claim 21, the combination of Collier as modified by Stahlberg discloses wherein the sensitive data is identified by keyword matching, by regular expressions (para. 0018 of Stahlberg identifies shared accounts used at the nodes and/or in the network and links multiple behavioral models to the identified shared account, for example), reading pre-defined content classification fields from document or other files and/or querying file confidentiality status from a content classification system (para. 0038 of Stahlberg discloses The security agent modules, 6a-6h, 4a collect various types of data at the nodes 5a-5h or gateway 4 including, for example, program or file hashes, files stored at the nodes 5a-5h, logs of network traffic, process logs, binaries or files carved from memory (e.g. DLL, EXE, or memory forensics artefacts), and/or logs from monitoring actions executed by programs or scripts running on the nodes 5a-5h or gateway 4 (e.g. tcp dumps), for example). Pertinent Art The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: Hockings et al. (US Patent US 9,998,470 B1) provide an approach to receiving user data, and monitoring a user data transaction. Monitoring a user data transaction. Identifying a plurality of attribute elements associated with the user data and the user data transaction. Creating benchmark data based on one or more identified attributes and user data gathered from a user data transaction, and storing, by the one or more processors, benchmark data. Burns et al. (US Patent No.: US 9,338,181 B1) provide a computer-implemented techniques for responding to attacks on computers and other elements of computer networks. The disclosure relates more specifically to computer-implemented techniques for responding to attacks in which a selected response is based upon the nature or value of the attacked asset. Ray et al. (US Patent No.: 2021/0400071 A1) provide an enterprise network is instrumented with sensors to detect security-related events occurring on the endpoint. Event data from these sensors is augmented with contextual information about, e.g., a source of each event in order to facilitate improved correlation, analysis, and visualization at a threat management facility for the enterprise network. Margolies et al. (US Pub. No.: US 2011/0225650 A1) provide a use of insider threat detection system, an enterprise insider who is a mid-level information technology application support technician may believe that the enterprise intends to downsize the information technology team. As a result, he intends to encrypt sensitive data and commit extortion against the enterprise if laid off. To do this, he must first locate the data and then encrypt the data with a unique key that only he can use to decrypt the files at some later point (e.g., upon payment of ransom by the enterprise), Ahn et al. (US Pub. No.: US 2021/0352094 A1), Chen et al. (US Pub. No.: US 2021/0352094 A1) and Pasquali et al. (US Patent No.: US 12,395,329 B1). Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to ABIY GETACHEW whose telephone number is (571)272-6932. The examiner can normally be reached Mon.-Fri. 9:00 AM - 5:30 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Kambiz Zand can be reached at (571) 272-3811. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. A.G. September 5, 2025 /ABIY GETACHEW/ Primary Examiner, Art Unit 2434
Read full office action

Prosecution Timeline

Nov 07, 2023
Application Filed
Sep 10, 2025
Non-Final Rejection mailed — §101, §103
Dec 10, 2025
Response Filed
Dec 10, 2025
Response after Non-Final Action

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 9338111
Electronic Message Recipient Handling System and Method with Media Component and Header Information Separation
1y 4m to grant Granted May 10, 2016
Patent 9313155
Electronic Message Send Device Handling System and Method with Separation of Message Content and Header Information
1y 3m to grant Granted Apr 12, 2016
Patent 9313156
Electronic Message Send Device Handling System and Method with Separated Display and Transmission of Message Content and Header Information
1y 3m to grant Granted Apr 12, 2016
Patent 9313157
ELECTRONIC MESSAGE RECIPIENT HANDLING SYSTEM AND METHOD WITH SEPARATION OF MESSAGE CONTENT AND HEADER INFORMATION
1y 3m to grant Granted Apr 12, 2016
Patent 9306885
Electronic Message Send Device Handling System and Method with Media Component and Header Information Separation
1y 3m to grant Granted Apr 05, 2016
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
76%
Grant Probability
73%
With Interview (-3.3%)
2y 3m (~0m remaining)
Median Time to Grant
Low
PTA Risk
Based on 21 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month