Prosecution Insights
Last updated: October 02, 2026
Application No. 18/615,793

TESTING ROLE-BASED ACCESS CONTROL POLICIES FOR IMPLEMENTATION CONSISTENCY USING SYMBOLIC ABSTRACTION MODELS AND SATISFIABILITY SOLVER MODELS

Non-Final OA §102§112
Filed
Mar 25, 2024
Priority
Feb 26, 2024 — provisional 63/558,003
Examiner
SHOLEMAN, ABU S
Art Unit
2496
Tech Center
2400 — Computer Networks
Assignee
Microsoft Technology Licensing, LLC
OA Round
3 (Non-Final)
78%
Grant Probability
Favorable
3-4
OA Rounds
5m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 78% — above average
78%
Career Allowance Rate
623 granted / 796 resolved
+20.3% vs TC avg
Strong +28% interview lift
Without
With
+27.6%
Interview Lift
resolved cases with interview
Typical timeline
3y 0m
Avg Prosecution
26 currently pending
Career history
832
Total Applications
across all art units

Statute-Specific Performance

§101
14.2%
-25.8% vs TC avg
§103
54.6%
+14.6% vs TC avg
§102
4.4%
-35.6% vs TC avg
§112
18.9%
-21.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 796 resolved cases

Office Action

§102 §112
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Arguments The allowance mailed on 04/15/2026 has been withdrawn based on the IDS filed on 05/15/2026. Applicant’s arguments with respect to claim(s) under 103 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. Claim Rejections - 35 USC § 112 The following is a quotation of the first paragraph of 35 U.S.C. 112(a): (a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention. The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112: The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention. Claims 1-20 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. As per claims 1,14 and 19, those claim recited the phase “ satisfiability function representation..” speciation does not provide enough explanation about how the function was define and determined. Thus, specification is failing to comply with the written description requirement. As per all dependent claims, those claims are rejected based on the same rational set forth in the clams 1,14 and 19 respectively. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 1-20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. As per claims 1,14 and 19, those claim recited the phase “ satisfiability function representation..” speciation does not provide enough explanation about how the function was define and determined. So, because of that reason it is not clear the boundary of the limitations, Thus, those claims are indefinite. As per all dependent claims, those claims are rejected based on the same rational set forth in the clams 1,14 and 19 respectively. Claim Rejections - 35 USC § 102 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. Claim(s) 1-20 are rejected under 35 U.S.C. 102(a)(2) as being anticipated by Simonetti et al US 2022/0385668 As per claim 1. Simonetti discloses A computer-implemented method for determining an implementation consistency check for one or more role-based access control (RBAC) policies comprising: generating an abstract policy model (fig.1 a set of security rules 124 )of a first RBAC policy using a symbolic abstraction model (0028 0028 a security governance guideline 114, ) to determine a set of execution paths for the first RBAC policy(fig.1 a set of security rules 124. Environment 100 can include enterprise system 110, policy engine 120, and IAM system 131, which can reside in a cloud computing system 130. Policy engine 120 can generate the set of effective access permissions 125. Based on the set of effective access permissions 125, environment 100 can be used to determine a compliance status of a principal of the IAM system with respect to a set of security rules 124. In addition, enterprise system 110 can be communicatively coupled to a computing device 140 that can be used by a person 142); determining a first satisfiability function representation ( [0030] Enterprise system 110 can be communicatively coupled to policy engine 120, where effective policy generator 121 and compliance engine 122 can be implemented to perform operations about security policies and access permissions. In some embodiments, policy database 112 can be implemented separately from enterprise system 110, such as in policy engine 120 and/or IAM system 131 coupled to enterprise system 110. In some other embodiments, policy engine 120 can be implemented as a part of enterprise system 110. determine whether there is over-privileged access permission 128) for a first execution path of the set of execution paths using the symbolic abstraction model ([0029] In some embodiments, security governance guideline 114 can define a set of security rules 124 including various security rules, e.g., security rule 126. Security rule 126 can set up a permissible scope of a name for role 113 or a permissible scope of a name for system resources 133 being specified by any security policies. Compliance engine 122 , i.e. satisfiability function representation, can be configured to receive the effective policy 123 indicating the set of effective access permissions 125 from effective policy generator 121, and security rule 126, and determine whether there is over-privileged access permission 128. If the set of effective access permissions 125 contains over-privileged access permission 128, role 113 has a compliance status 153 as non-compliant. On the other hand, if compliance engine 122 cannot detect any over-privileged access permission for the set of effective access permissions 125, role 113 has compliance status 153 as compliant. Role 113 and its compliance status 153 can be displayed on GUI 119 of enterprise system 110); in response to providing the first satisfiability function representation to a satisfiability solver model, receiving a first input from the satisfiability solver model that is an example solution to the first execution path ([0045] The identify set can include more than more principal, and the system resource set can include more than one system resource. The identify set and the system resource set of a policy statement are both represented by various names. In some examples, a policy statement can include a name for a principal, e.g., name 221 within principal statement 213; a name for a system resource, e.g., name 223, name 225, name 227, within resource statement 217; or a name for an action, e.g., name 229 within action statement 215, or some other names. [0046] A name for a system resource can refer to one or more system resources. For example, name 223 includes only “*”, which is a wildcard referring to any system resources in the account. On the other hand, name 227 includes “example_bucket”, which refers to only one bucket stored in S3. In addition, name 225 includes “confidential-data/*”, which refers to a set of system resources within the folder “confidential-data.” Therefore, a name for a system resource can refer to system resource set of the IAM system of various sizes, as shown above For example, name 227 specifies only one system resource, “example_bucket”, while name 223 specifies every system resource of the account, “*”. The set of system resources referred by a name for a system resource defines a scope of the name for the system resource. When a scope of the name for a system resource in a security policy statement includes more than one system resource, the security policy statement can be applicable to any system resource whose name is included in the scope of the name for the system resource. And [0067] According to method 410, at 411, a user can enter a principal name. At 412, effective policy generator 121 can gather all the security policies from the IAM attached to the principal. In some examples, all the security policies attached to the principal can be a large number of security policies, e.g., millions of security policies. For each security policy 413, which can be similar to security policy 210, method 410 can perform iteration 420. The iteration 420 can be operated multiple times, one for each policy. Iteration 420 can include operations performed at 414, 415, 416, 418, 419, and 421. ); identifying, for the first execution path, a first implementation instance implemented in a first programming application for the first execution path of the first RBAC policy; ( 0018 an over-privileged access permission is detected by comparing permissible scopes of access permissions defined by a set of security rules with a set of effective access permissions defined by a set of security policies associated with the principal. Based on the set of effective access permissions, an enterprise system can perform preemptive evaluation of access permissions associated with a principal to identify any over-privileged access permission of the principal to system resources. Hence, the enterprise system can detect over-privileged access permissions associated with a principal in an IAM system without having to submit any requests to the IAM system) identifying, for the first execution path, a second implementation instance implemented in a second programming application for the first execution path of the first RBAC policy, wherein the first programming application is different from the second programming application([0048] Accordingly, for a system resource, the name of the system resource can be included in multiple policy statements of multiple security policies, either explicitly or implicitly as shown above. In some examples, a first security policy can include a first policy statement applicable to the system resource, and a second security policy can include a second policy statement applicable to the same system resource. Moreover the first policy statement may grant access to the system resource while the second policy statement may deny access to the system resource by the same principal. Accordingly, a conflict between the first security policy and the second security policy occurs when the first policy statement and the second policy statement have conflicting effects on the system resource or the role. Depending on the kind of policy statements and the kind of security policies, different conflict can be resolved in different ways. And [0062] In 404, effective policy generator 121 can identify a second policy statement, where the second policy statement specifies that members of a second identity set are denied access to a second system resource set of the IAM system. For example, as shown in FIGS. 1 and 2A, effective policy generator 121 can identify policy statement 214 specifying that members of a second identity set are denied access to a second system resource set of the IAM system. and [0065] In 409, when the second policy statement is determined to overlap with the first policy statement, effective policy generator 121 can place the second policy statement into a list of policy statements associated with the first policy statement with respect to the effective access permissions. For example, when policy statement 214 is determined to overlap with policy statement 212, effective policy generator 121 can place policy statement 214 into a list of policy statements associated with policy statement 212 with respect to the effective access permissions. ); and determining that the first RBAC policy is inconsistently implemented for the first execution path by ( 0076 effective policy generator 121 can determine whether or not there is a shared system resource belonging to both the system resource set of allow policy statement 432 and the system resource set of the selected deny policy statement, and whether or not the identity set of the selected deny policy statement includes the principal. If the identity set of the selected deny statement does not include the principal, or there is no shared system resource belonging to both the system resource set of allow policy statement 432 and the system resource set of the selected deny policy statement, the selected deny policy statement does not overlap with allow policy statement 432. Hence, the selected deny policy statement is not added to list 441 of deny policy statements associated with the allow policy statement 432 with respect to the effective access permissions. ): applying the first input( fig. 2A, first input 213 ) to the first implementation instance ( fig.2a 229 first instance ) of the first execution path of the first RBAC policy (0045 a policy statement can include a name for a principal, e.g., name 221 within principal statement 213; a name for a system resource, e.g., name 223, name 225, name 227, within resource statement 217; or a name for an action, e.g., name 229 within action statement 215, or some other names. ); and applying the first input to the second implementation instance ( fig.2, 229 second instance ) of the first execution path of the first RBAC policy( 0046 name 223 includes only “*”, which is a wildcard referring to any system resources in the account. On the other hand, name 227 includes “example_bucket”, which refers to only one bucket stored in S3. In addition, name 225 includes “confidential-data/*”, which refers to a set of system resources within the folder “confidential-data.” Therefore, a name for a system resource can refer to system resource set of the IAM system of various sizes, as shown above For example, name 227 specifies only one system resource, “example_bucket”, while name 223 specifies every system resource of the account, “*”. The set of system resources referred by a name for a system resource defines a scope of the name for the system resource. When a scope of the name for a system resource in a security policy statement includes more than one system resource, the security policy statement can be applicable to any system resource whose name is included in the scope of the name for the system resource). As per claim 14. Simonetti discloses A computer-implemented method for determining an implementation consistency check for one or more role-based access control (RBAC) policies comprising: generating an abstract policy model (fig.1 a set of security rules 124 )of a first RBAC policy using a symbolic abstraction model (0028 0028 a security governance guideline 114, ) to determine a set of execution paths for the first RBAC policy(fig.1 a set of security rules 124. Environment 100 can include enterprise system 110, policy engine 120, and IAM system 131, which can reside in a cloud computing system 130. Policy engine 120 can generate the set of effective access permissions 125. Based on the set of effective access permissions 125, environment 100 can be used to determine a compliance status of a principal of the IAM system with respect to a set of security rules 124. In addition, enterprise system 110 can be communicatively coupled to a computing device 140 that can be used by a person 142); determining a first satisfiability function representation ( [0030] Enterprise system 110 can be communicatively coupled to policy engine 120, where effective policy generator 121 and compliance engine 122 can be implemented to perform operations about security policies and access permissions. In some embodiments, policy database 112 can be implemented separately from enterprise system 110, such as in policy engine 120 and/or IAM system 131 coupled to enterprise system 110. In some other embodiments, policy engine 120 can be implemented as a part of enterprise system 110. determine whether there is over-privileged access permission 128) for a first execution path of the set of execution paths using the symbolic abstraction model ([0029] In some embodiments, security governance guideline 114 can define a set of security rules 124 including various security rules, e.g., security rule 126. Security rule 126 can set up a permissible scope of a name for role 113 or a permissible scope of a name for system resources 133 being specified by any security policies. Compliance engine 122 , i.e. satisfiability function representation, can be configured to receive the effective policy 123 indicating the set of effective access permissions 125 from effective policy generator 121, and security rule 126, and determine whether there is over-privileged access permission 128. If the set of effective access permissions 125 contains over-privileged access permission 128, role 113 has a compliance status 153 as non-compliant. On the other hand, if compliance engine 122 cannot detect any over-privileged access permission for the set of effective access permissions 125, role 113 has compliance status 153 as compliant. Role 113 and its compliance status 153 can be displayed on GUI 119 of enterprise system 110); in response to providing the first satisfiability function representation to a satisfiability solver model, receiving a first input from the satisfiability solver model that is an example solution to the first execution path ([0045] The identify set can include more than more principal, and the system resource set can include more than one system resource. The identify set and the system resource set of a policy statement are both represented by various names. In some examples, a policy statement can include a name for a principal, e.g., name 221 within principal statement 213; a name for a system resource, e.g., name 223, name 225, name 227, within resource statement 217; or a name for an action, e.g., name 229 within action statement 215, or some other names. [0046] A name for a system resource can refer to one or more system resources. For example, name 223 includes only “*”, which is a wildcard referring to any system resources in the account. On the other hand, name 227 includes “example_bucket”, which refers to only one bucket stored in S3. In addition, name 225 includes “confidential-data/*”, which refers to a set of system resources within the folder “confidential-data.” Therefore, a name for a system resource can refer to system resource set of the IAM system of various sizes, as shown above For example, name 227 specifies only one system resource, “example_bucket”, while name 223 specifies every system resource of the account, “*”. The set of system resources referred by a name for a system resource defines a scope of the name for the system resource. When a scope of the name for a system resource in a security policy statement includes more than one system resource, the security policy statement can be applicable to any system resource whose name is included in the scope of the name for the system resource. And [0067] According to method 410, at 411, a user can enter a principal name. At 412, effective policy generator 121 can gather all the security policies from the IAM attached to the principal. In some examples, all the security policies attached to the principal can be a large number of security policies, e.g., millions of security policies. For each security policy 413, which can be similar to security policy 210, method 410 can perform iteration 420. The iteration 420 can be operated multiple times, one for each policy. Iteration 420 can include operations performed at 414, 415, 416, 418, 419, and 421. ); identifying, for the first execution path, a first implementation instance implemented in a first programming application for the first execution path of the first RBAC policy; ( 0018 an over-privileged access permission is detected by comparing permissible scopes of access permissions defined by a set of security rules with a set of effective access permissions defined by a set of security policies associated with the principal. Based on the set of effective access permissions, an enterprise system can perform preemptive evaluation of access permissions associated with a principal to identify any over-privileged access permission of the principal to system resources. Hence, the enterprise system can detect over-privileged access permissions associated with a principal in an IAM system without having to submit any requests to the IAM system. ) identifying, for the first execution path, a second implementation instance implemented in a second programming application for the first execution path of the first RBAC policy, wherein the first programming application is different from the second programming application([0048] Accordingly, for a system resource, the name of the system resource can be included in multiple policy statements of multiple security policies, either explicitly or implicitly as shown above. In some examples, a first security policy can include a first policy statement applicable to the system resource, and a second security policy can include a second policy statement applicable to the same system resource. Moreover the first policy statement may grant access to the system resource while the second policy statement may deny access to the system resource by the same principal. Accordingly, a conflict between the first security policy and the second security policy occurs when the first policy statement and the second policy statement have conflicting effects on the system resource or the role. Depending on the kind of policy statements and the kind of security policies, different conflict can be resolved in different ways. And [0062] In 404, effective policy generator 121 can identify a second policy statement, where the second policy statement specifies that members of a second identity set are denied access to a second system resource set of the IAM system. For example, as shown in FIGS. 1 and 2A, effective policy generator 121 can identify policy statement 214 specifying that members of a second identity set are denied access to a second system resource set of the IAM system. and [0065] In 409, when the second policy statement is determined to overlap with the first policy statement, effective policy generator 121 can place the second policy statement into a list of policy statements associated with the first policy statement with respect to the effective access permissions. For example, when policy statement 214 is determined to overlap with policy statement 212, effective policy generator 121 can place policy statement 214 into a list of policy statements associated with policy statement 212 with respect to the effective access permissions. ); and determining that the first RBAC policy is inconsistently implemented for the first execution path by ( 0076 effective policy generator 121 can determine whether or not there is a shared system resource belonging to both the system resource set of allow policy statement 432 and the system resource set of the selected deny policy statement, and whether or not the identity set of the selected deny policy statement includes the principal. If the identity set of the selected deny statement does not include the principal, or there is no shared system resource belonging to both the system resource set of allow policy statement 432 and the system resource set of the selected deny policy statement, the selected deny policy statement does not overlap with allow policy statement 432. Hence, the selected deny policy statement is not added to list 441 of deny policy statements associated with the allow policy statement 432 with respect to the effective access permissions. ): applying the first input( fig. 2A, first input 213 ) to the first implementation instance ( fig.2a 229 first instance ) of the first execution path of the first RBAC policy (0045 a policy statement can include a name for a principal, e.g., name 221 within principal statement 213; a name for a system resource, e.g., name 223, name 225, name 227, within resource statement 217; or a name for an action, e.g., name 229 within action statement 215, or some other names. ); and applying the first input to the second implementation instance ( fig.2, 229 second instance ) of the first execution path of the first RBAC policy( 0046 name 223 includes only “*”, which is a wildcard referring to any system resources in the account. On the other hand, name 227 includes “example_bucket”, which refers to only one bucket stored in S3. In addition, name 225 includes “confidential-data/*”, which refers to a set of system resources within the folder “confidential-data.” Therefore, a name for a system resource can refer to system resource set of the IAM system of various sizes, as shown above For example, name 227 specifies only one system resource, “example_bucket”, while name 223 specifies every system resource of the account, “*”. The set of system resources referred by a name for a system resource defines a scope of the name for the system resource. When a scope of the name for a system resource in a security policy statement includes more than one system resource, the security policy statement can be applicable to any system resource whose name is included in the scope of the name for the system resource. ) . As per claim 19. Simonetti discloses aA system for determining policy equivalence in role-based access control (RBAC) policies comprising: a processing system (0004 system, apparatus, device, method and/or computer program product ); and a computer memory comprising instructions that, when executed by the processing system ( 0006 one or more processors configured to read instructions from the computer readable device to perform ), cause the system to perform operations of: generating an abstract policy model (fig.1 a set of security rules 124 )of a first RBAC policy using a symbolic abstraction model (0028 0028 a security governance guideline 114, ) to determine a set of execution paths for the first RBAC policy(fig.1 a set of security rules 124. Environment 100 can include enterprise system 110, policy engine 120, and IAM system 131, which can reside in a cloud computing system 130. Policy engine 120 can generate the set of effective access permissions 125. Based on the set of effective access permissions 125, environment 100 can be used to determine a compliance status of a principal of the IAM system with respect to a set of security rules 124. In addition, enterprise system 110 can be communicatively coupled to a computing device 140 that can be used by a person 142); determining a first satisfiability function representation ( [0030] Enterprise system 110 can be communicatively coupled to policy engine 120, where effective policy generator 121 and compliance engine 122 can be implemented to perform operations about security policies and access permissions. In some embodiments, policy database 112 can be implemented separately from enterprise system 110, such as in policy engine 120 and/or IAM system 131 coupled to enterprise system 110. In some other embodiments, policy engine 120 can be implemented as a part of enterprise system 110. determine whether there is over-privileged access permission 128) for a first execution path of the set of execution paths using the symbolic abstraction model ([0029] In some embodiments, security governance guideline 114 can define a set of security rules 124 including various security rules, e.g., security rule 126. Security rule 126 can set up a permissible scope of a name for role 113 or a permissible scope of a name for system resources 133 being specified by any security policies. Compliance engine 122 , i.e. satisfiability function representation, can be configured to receive the effective policy 123 indicating the set of effective access permissions 125 from effective policy generator 121, and security rule 126, and determine whether there is over-privileged access permission 128. If the set of effective access permissions 125 contains over-privileged access permission 128, role 113 has a compliance status 153 as non-compliant. On the other hand, if compliance engine 122 cannot detect any over-privileged access permission for the set of effective access permissions 125, role 113 has compliance status 153 as compliant. Role 113 and its compliance status 153 can be displayed on GUI 119 of enterprise system 110); in response to providing the first satisfiability function representation to a satisfiability solver model, receiving a first input from the satisfiability solver model that is an example solution to the first execution path ([0045] The identify set can include more than more principal, and the system resource set can include more than one system resource. The identify set and the system resource set of a policy statement are both represented by various names. In some examples, a policy statement can include a name for a principal, e.g., name 221 within principal statement 213; a name for a system resource, e.g., name 223, name 225, name 227, within resource statement 217; or a name for an action, e.g., name 229 within action statement 215, or some other names. [0046] A name for a system resource can refer to one or more system resources. For example, name 223 includes only “*”, which is a wildcard referring to any system resources in the account. On the other hand, name 227 includes “example_bucket”, which refers to only one bucket stored in S3. In addition, name 225 includes “confidential-data/*”, which refers to a set of system resources within the folder “confidential-data.” Therefore, a name for a system resource can refer to system resource set of the IAM system of various sizes, as shown above For example, name 227 specifies only one system resource, “example_bucket”, while name 223 specifies every system resource of the account, “*”. The set of system resources referred by a name for a system resource defines a scope of the name for the system resource. When a scope of the name for a system resource in a security policy statement includes more than one system resource, the security policy statement can be applicable to any system resource whose name is included in the scope of the name for the system resource. And [0067] According to method 410, at 411, a user can enter a principal name. At 412, effective policy generator 121 can gather all the security policies from the IAM attached to the principal. In some examples, all the security policies attached to the principal can be a large number of security policies, e.g., millions of security policies. For each security policy 413, which can be similar to security policy 210, method 410 can perform iteration 420. The iteration 420 can be operated multiple times, one for each policy. Iteration 420 can include operations performed at 414, 415, 416, 418, 419, and 421. ); identifying, for the first execution path, a first implementation instance implemented in a first programming application for the first execution path of the first RBAC policy; ( 0018 an over-privileged access permission is detected by comparing permissible scopes of access permissions defined by a set of security rules with a set of effective access permissions defined by a set of security policies associated with the principal. Based on the set of effective access permissions, an enterprise system can perform preemptive evaluation of access permissions associated with a principal to identify any over-privileged access permission of the principal to system resources. Hence, the enterprise system can detect over-privileged access permissions associated with a principal in an IAM system without having to submit any requests to the IAM system. ) identifying, for the first execution path, a second implementation instance implemented in a second programming application for the first execution path of the first RBAC policy, wherein the first programming application is different from the second programming application([0048] Accordingly, for a system resource, the name of the system resource can be included in multiple policy statements of multiple security policies, either explicitly or implicitly as shown above. In some examples, a first security policy can include a first policy statement applicable to the system resource, and a second security policy can include a second policy statement applicable to the same system resource. Moreover the first policy statement may grant access to the system resource while the second policy statement may deny access to the system resource by the same principal. Accordingly, a conflict between the first security policy and the second security policy occurs when the first policy statement and the second policy statement have conflicting effects on the system resource or the role. Depending on the kind of policy statements and the kind of security policies, different conflict can be resolved in different ways. And [0062] In 404, effective policy generator 121 can identify a second policy statement, where the second policy statement specifies that members of a second identity set are denied access to a second system resource set of the IAM system. For example, as shown in FIGS. 1 and 2A, effective policy generator 121 can identify policy statement 214 specifying that members of a second identity set are denied access to a second system resource set of the IAM system. and [0065] In 409, when the second policy statement is determined to overlap with the first policy statement, effective policy generator 121 can place the second policy statement into a list of policy statements associated with the first policy statement with respect to the effective access permissions. For example, when policy statement 214 is determined to overlap with policy statement 212, effective policy generator 121 can place policy statement 214 into a list of policy statements associated with policy statement 212 with respect to the effective access permissions. ); and determining that the first RBAC policy is inconsistently implemented for the first execution path by ( 0076 effective policy generator 121 can determine whether or not there is a shared system resource belonging to both the system resource set of allow policy statement 432 and the system resource set of the selected deny policy statement, and whether or not the identity set of the selected deny policy statement includes the principal. If the identity set of the selected deny statement does not include the principal, or there is no shared system resource belonging to both the system resource set of allow policy statement 432 and the system resource set of the selected deny policy statement, the selected deny policy statement does not overlap with allow policy statement 432. Hence, the selected deny policy statement is not added to list 441 of deny policy statements associated with the allow policy statement 432 with respect to the effective access permissions. ): applying the first input( fig. 2A, first input 213 ) to the first implementation instance ( fig.2a 229 first instance ) of the first execution path of the first RBAC policy (0045 a policy statement can include a name for a principal, e.g., name 221 within principal statement 213; a name for a system resource, e.g., name 223, name 225, name 227, within resource statement 217; or a name for an action, e.g., name 229 within action statement 215, or some other names. ); and applying the first input to the second implementation instance ( fig.2, 229 second instance ) of the first execution path of the first RBAC policy( 0046 name 223 includes only “*”, which is a wildcard referring to any system resources in the account. On the other hand, name 227 includes “example_bucket”, which refers to only one bucket stored in S3. In addition, name 225 includes “confidential-data/*”, which refers to a set of system resources within the folder “confidential-data.” Therefore, a name for a system resource can refer to system resource set of the IAM system of various sizes, as shown above For example, name 227 specifies only one system resource, “example_bucket”, while name 223 specifies every system resource of the account, “*”. The set of system resources referred by a name for a system resource defines a scope of the name for the system resource. When a scope of the name for a system resource in a security policy statement includes more than one system resource, the security policy statement can be applicable to any system resource whose name is included in the scope of the name for the system resource). As per claim 2. Simonetti discloses the computer-implemented method of claim 1, wherein the first RBAC policy is determined to be inconsistently implemented by determining that a first output of the first implementation instance differs from a second output from the second implementation instance(0004 evaluating effective access permissions defined by a set of security policies for a principal, where the principal can be an identity and access management (IAM) user, an IAM role, or an application. A security policy can include multiple policy statements. Hence, there can be many security policy statements associated with a principal in an IAM system. Some policy statements may allow access to a system resource set of the IAM system, while some other policy statements may deny access to a system resource set of the IAM system. The effective access permissions for the principal is the overall access permissions defined by all the policy statements of the entire set of security policies. In order to evaluate the effective access permissions for a principal, embodiments herein classify the policy statements of the security policies into a set of allow policy statements, and a set of deny policy statements. The set of allow policy statements includes policy statements that specify that members of an identity set including the principal are allowed to access a system resource set of the IAM system. The set of deny policy statements includes policy statements that specify that members of an identity set are denied access to a system resource set of the IAM system. For an allow policy statement of the set of allow policy statements, embodiments determine a list of deny policy statements associated with the allow policy statement with respect to the effective access permissions. A deny policy statement is included in the list of deny policy statements associated with the allow policy statement when there is a shared system resource belonging to the system resource set of the allow policy statement and the system resource set of the deny policy statement, and the identity set of the deny policy statement includes the principal. The effective access permissions associated with the principal are defined by a system resource included in the system resource set of the allow policy statement but not included in the system resource set of the deny policy statement. ). As per claim 3. Simonetti discloses The computer-implemented method of claim 1, wherein the abstract policy model of the first RBAC policy includes an abstraction tree having execution paths that progress through one or more decision nodes representing policy definition conditions([0005] In some examples, a computer-implemented method is presented for evaluating effective access permissions defined by security policies associated with a principal managed by an IAM system. The method includes identifying a first policy statement associated with the principal, and identifying a second policy statement. The first policy statement specifies that members of a first identity set including the principal are allowed to access a first system resource set of the IAM system, while the second policy statement specifies that members of a second identity set are denied access to a second system resource set of the IAM system. The method further includes determining whether or not there is a shared system resource belonging to both the first system resource set and the second system resource set, and whether or not the second identity set includes the principal. When the shared system resource belongs to the first system resource set and the second system resource set, and the second identity set includes the principal, the method includes determining that the second policy statement overlaps with the first policy statement with respect to the effective access permissions for the principal. The effective access permissions associated with the principal are defined by a system resource included in the first system resource set but not included in the second system resource set. The method further includes placing, when the second policy statement is determined to overlap with the first policy statement, the second policy statement into a list of policy statements associated with the first policy statement with respect to the effective access permissions. ). As per claim 4. Simonetti discloses The computer-implemented method of claim 1, further comprising generating the first execution path into a symbolic expression using the symbolic abstraction model before generating the first satisfiability function representation for the first execution path([0017] The features described in this disclosure allow for an enterprise system to monitor access permission compliance of principals with access control (AC) for accessing system resources of an IAM system without any requests being made. Access privileges or permissions to system resources by a principal are granted according to security policies. There are many kinds of security policies, which work together to provide effective access permissions for a principal to access system resources. However, due to the complexity of many security policies, sometimes a principal can have an unintended, improper, or over-privileged access permission to some system resources for which the principal should not have access to. For security reasons, it is important to prevent a principal from having an over-privileged access permission to system resources. In some embodiments, the enterprise system can detect over-privileged access permissions because the operations are performed by the enterprise system independent of the IAM system. Accordingly, the mechanisms discussed in the current disclosure are implemented by a machine with a specific arrangement, where the policy engine is separated from the IAM system to provide more security protection for the IAM system. In some embodiments, the enterprise system detecting over-privileged access permissions is separated from the IAM system. ). As per claim 5. Simonetti discloses The computer-implemented method of claim 1, further comprising receiving inputs from the satisfiability solver model for each execution path in the abstract policy model (0018 an over-privileged access permission is detected by comparing permissible scopes of access permissions defined by a set of security rules with a set of effective access permissions defined by a set of security policies associated with the principal. Based on the set of effective access permissions, an enterprise system can perform preemptive evaluation of access permissions associated with a principal to identify any over-privileged access permission of the principal to system resources. Hence, the enterprise system can detect over-privileged access permissions associated with a principal in an IAM system without having to submit any requests to the IAM system. ). As per claim 6. Simonetti discloses The computer-implemented method of claim 1, wherein the abstract policy model includes execution paths within the set of execution paths that cover all potential inputs to the first RBAC policy (0020 A security policy can include multiple policy statements. Instead of performing the evaluation for individual security policies, embodiments herein classify the policy statements of the security policies into a set of allow policy statements, and a set of deny policy statements. Such a classification can improve the efficiency of the effective access permissions evaluation compared to the evaluation based on security policies. In addition, the effective access permissions is represented by a specially designed structure, which further improves the efficiency of the computation, the compactness of the representation, and the readability of the resulting effective access permissions by a human user or administrator. For each allow policy statement of the set of allow policy statements, a list of deny policy statements associated with the allow policy statement with respect to the effective access permissions is identified. The effective access permissions associated with the principal related to the allow policy statement are defined by a system resource included in the system resource set of the allow policy statement but not included in the system resource set of the list of deny policy statements. The total effective access permissions associated with the principal is the union of all the effective access permissions associated with the principal related to the allow policy statements in the set of allow policy statements. ). As per claim 7. Simonetti discloses The computer-implemented method of claim 1, wherein: the first RBAC policy includes an allow effect and a deny effect; and the abstract policy model includes execution paths corresponding to the allow effect or the deny effect ( 0024] Cloud computing system 130 can include IAM system 131, which can manage system resources 133. IAM system 131 can receive a request 119 for access to system resources 133 from entities in enterprise system 110 such as principal 111. Principal 111 can be a user 116, a role 113, a machine 115, or an application 151. IAM system 131 can include a plurality of data storage systems for storing system resources 133 to be accessed by enterprise system 110. IAM system 131 can include a database management system or relational database tool. IAM system 131 can further include a message queue or stream processing platform such as Apache Kafka or Apache Spark or other data storage systems like Apache Hadoop, Hadoop Distributed File System (HDFS), or Amazon S3, to name just some examples. IAM system 131 can be a data lake, data silo, semi-structured data system (comma-separated values file, logs, xml, etc.), unstructured data system, binary data repository, or other suitable repository. IAM system 131 can store thousands, millions, billions, or trillions (or more) of objects, rows, transactions, records, files, logs, etc. while allowing for the creation, modification, retrieval, archival, and management of this data. ). As per claim 8. Simonetti discloses The computer-implemented method of claim 7, wherein the abstract policy model includes a second first execution path corresponding to both the allow effect and the deny effect ([0028] In some embodiments, enterprise system 110 can include any number of principals, e.g., principal 111, a policy database 112, and a security governance guideline 114, which can be stored in memory device 118. Principal 111 can include role 113, which can be user 116 or machine 115, or application 151. In the following descriptions, role 113 can be used as an example of principal 111. Policy database 112 can include one or more security policies, which can be referred to as a policy, associated with roles or principals. For example, policy 113a, policy 113b, and policy 113c are associated with role 113. Combined, the security policies, e.g., policy 113a, policy 113b, or policy 113c, can generate an effective policy 123 for role 113, which can define a set of effective access permissions 125 by role 113 to access system resources 133. ). As per claim 9. Simonetti discloses The computer-implemented method of claim 7, wherein the abstract policy model includes a second execution path corresponding to both the allow effect and the deny effect ([0028] In some embodiments, enterprise system 110 can include any number of principals, e.g., principal 111, a policy database 112, and a security governance guideline 114, which can be stored in memory device 118. Principal 111 can include role 113, which can be user 116 or machine 115, or application 151. In the following descriptions, role 113 can be used as an example of principal 111. Policy database 112 can include one or more security policies, which can be referred to as a policy, associated with roles or principals. For example, policy 113a, policy 113b, and policy 113c are associated with role 113. Combined, the security policies, e.g., policy 113a, policy 113b, or policy 113c, can generate an effective policy 123 for role 113, which can define a set of effective access permissions 125 by role 113 to access system resources 133. ). As per claim 10. Simonetti discloses The computer-implemented method of claim 1, wherein the symbolic abstraction model generates symbolic expressions of execution paths using a common intermediate language that encodes semantics of multiple source languages ([0029] In some embodiments, security governance guideline 114 can define a set of security rules 124 including various security rules, e.g., security rule 126. Security rule 126 can set up a permissible scope of a name for role 113 or a permissible scope of a name for system resources 133 being specified by any security policies. Compliance engine 122 can be configured to receive the effective policy 123 indicating the set of effective access permissions 125 from effective policy generator 121, and security rule 126, and determine whether there is over-privileged access permission 128. If the set of effective access permissions 125 contains over-privileged access permission 128, role 113 has a compliance status 153 as non-compliant. On the other hand, if compliance engine 122 cannot detect any over-privileged access permission for the set of effective access permissions 125, role 113 has compliance status 153 as compliant. Role 113 and its compliance status 153 can be displayed on GUI 119 of enterprise system 110. ). As per claim 11. Simonetti discloses The computer-implemented method of claim 10, wherein the first implementation instance in the first programming application is obtained from a cloud computing system that stores multiple implementation instances of the first execution path ([0029] In some embodiments, security governance guideline 114 can define a set of security rules 124 including various security rules, e.g., security rule 126. Security rule 126 can set up a permissible scope of a name for role 113 or a permissible scope of a name for system resources 133 being specified by any security policies. Compliance engine 122 can be configured to receive the effective policy 123 indicating the set of effective access permissions 125 from effective policy generator 121, and security rule 126, and determine whether there is over-privileged access permission 128. If the set of effective access permissions 125 contains over-privileged access permission 128, role 113 has a compliance status 153 as non-compliant. On the other hand, if compliance engine 122 cannot detect any over-privileged access permission for the set of effective access permissions 125, role 113 has compliance status 153 as compliant. Role 113 and its compliance status 153 can be displayed on GUI 119 of enterprise system 110. ). As per claim 12. Simonetti discloses The computer-implemented method of claim 1, wherein the first programming application is C++ and the second programming application is C# ( [0041] In some examples, security policy 210 can be stored in a storage of cloud computing system 130. In some examples, security policy 210 can be specified by nature language. In some other examples, security policy 210 can be specified by one or more statements in a markup language or structured language. Security policy 210 can be contained in a document specified by a markup language, such as a JavaScript Object Notation (JSON) document, a XML document, a YAML document, or any other documents containing statements in structured languages. Natural language processing can be used to convert a security policy in natural language, e.g., English, to a structured language.). As per claim 13. Simonetti discloses The computer-implemented method of claim 1, wherein the first RBAC policy belongs to a set of RBAC policies maintained by a cloud computing system ( 0030] Enterprise system 110 can be communicatively coupled to policy engine 120, where effective policy generator 121 and compliance engine 122 can be implemented to perform operations about security policies and access permissions. In some embodiments, policy database 112 can be implemented separately from enterprise system 110, such as in policy engine 120 and/or IAM system 131 coupled to enterprise system 110. In some other embodiments, policy engine 120 can be implemented as a part of enterprise system 110.). As per claim 15. Simonetti discloses The computer-implemented method of claim 14, wherein determining whether the first RBAC policy is consistently implemented includes comparing a first output of the first implementation instance that applies the first input with a second output from the second implementation instance that applies the first input ([0031] In some examples, role 113 can be used to delegate access to users, applications, or services that do not normally have access to system resources 133. For example, role 113 can be used to delegate access by a mobile app on computing device 140 to use system resources 133, which would not be normally accessible by a mobile application. Role 113 can be used to grant access to resources in one account to a trusted principal in a different account. Instead of being uniquely associated with one person, role 113 is intended to be assumable by anyone who needs it. Also, role 113 may not have standard long term credentials such as a password or access keys associated with it. Instead, role 113 can be provided with temporary security credentials for a session when the role is effective or valid. ). As per claim 16. Simonetti discloses The computer-implemented method of claim 15, further comprising determining the first RBAC policy is not consistently implemented based on the first output of the first implementation instance differing from the second output from the second implementation instance (0032] Role 113 can include a machine 115 or a user 116. Machine 115 can be a representation of computing device 140, while user 116 can be a representation of person 142. User 116 can be an identity of person 142 in the service. Role 113 can be an identity that has specific access permissions. Role 113 can access system resources 133 based on access permissions defined by associated security policies, e.g., policy 113a, policy 113b, and policy 113c, which can be collectively referred as “policies 113.” ). As per claim 17. Simonetti discloses The computer-implemented method of claim 15, further comprising determining the first RBAC policy is consistently implemented based, at least in part, on the first output of the first implementation instance matching the second output from the second implementation instance ([0033] Principal 111, e.g., role 113, can submit request 119 for accessing system resources such as system resources 133 which are protected by IAM system 131. Request 119 can include a request context information, which is used to evaluate and authorize the request. The request context information can include actions or operations to be performed, resources upon which the actions or operations are performed, a principal that can be a person or an application that an entity to send request 119, environment data such as IP address, user agent, SSL enabled status, or the time of day; and resource data such as data related to the resource that is being requested. Information about the principal can include the policies that are associated with the entity that the principal used to sign in. Resource data can include information such as a database table name or a tag on an Amazon EC2 instance, for example. Request 119 can be allowed or denied based on the security policies, e.g., policy 113a, policy 113b, and policy 113c, associated with role 113. ). As per claim 18. Simonetti discloses The computer-implemented method of claim 17, further comprising determining the first RBAC policy is consistently implemented based on outputs matching across all inputs between implementation instances in the first programming application and the second programming application for each execution path in the abstract policy model of the first RBAC policy( 0092 , a tangible, non-transitory apparatus or article of manufacture comprising a tangible, non-transitory computer useable or readable medium having control logic (software) stored thereon may also be referred to herein as a computer program product or program storage device. This includes, but is not limited to, computer system 500, main memory 508, secondary memory 510, and removable storage units 518 and 522, as well as tangible articles of manufacture embodying any combination of the foregoing. Such control logic, when executed by one or more data processing devices (such as computer system 500), may cause such data processing devices to operate as described herein. For example, control logic may cause processor 504 to select a first role administered by an entity and a second role administered by the entity; identify a first set of security policies associated with the first role, and a second set of security policies associated with the second role, wherein the first set of security policies includes a first security policy and a second security policy; generate a first set of effective access permissions associated with the first role, and a second set of effective access permissions associated with the second role, wherein the first set of effective access permissions is generated based on the first set of security policies by resolving at least a conflict between the first security policy and the second security policy, and wherein the first set of effective access permissions defines a scope of a name for a system resource, or defines a scope of a name for a role; compare a permissible scope of the name for the system resource ). As per claim 20. Simonetti discloses The system of claim 19, wherein the satisfiability solver model is a satisfiability modulo theory (SMT) solver ([0090] Computer system 500 may be a client or server, accessing or hosting any applications and/or data through any delivery paradigm, including but not limited to remote or distributed cloud computing solutions; local or on-premises software (“on-premise” cloud-based solutions); “as a service” models (e.g., content as a service (CaaS), digital content as a service (DCaaS), software as a service (SaaS), managed software as a service (MSaaS), platform as a service (PaaS), desktop as a service (DaaS), framework as a service (FaaS), backend as a service (BaaS), mobile backend as a service (MBaaS), infrastructure as a service (IaaS), etc.); and/or a hybrid model including any combination of the foregoing examples or other services or delivery paradigms.). Conclusion Applicant's submission of an information disclosure statement under 37 CFR 1.97(c) with the timing fee set forth in 37 CFR 1.17(p) on 05/15/2026 prompted the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 609.04(b). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to ABU S SHOLEMAN whose telephone number is (571)270-7314. The examiner can normally be reached EST: 9am-5pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, JORGE ORTIZ CRIADO can be reached at 571-272-7624. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /ABU S SHOLEMAN/Primary Examiner, Art Unit 2496
Read full office action

Prosecution Timeline

Show 8 earlier events
Feb 26, 2026
Request for Continued Examination
Mar 14, 2026
Response after Non-Final Action
May 15, 2026
Request for Continued Examination
May 23, 2026
Response after Non-Final Action
Jul 14, 2026
Non-Final Rejection mailed — §102, §112
Sep 17, 2026
Interview Requested
Sep 24, 2026
Applicant Interview (Telephonic)
Sep 24, 2026
Examiner Interview Summary

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12739122
USER AUTHENTICATION FOR A RESOURCE USING CONTEXT BASED ENCRYPTION OF AUTHENTICATION TOKENS
2y 3m to grant Granted Sep 15, 2026
Patent 12730875
SYSTEMS AND METHODS FOR SOFTWARE AUTHENTICATION WITHOUT PROVIDING FULL SOFTWARE DISCLOSURE TO A SOFTWARE NOTARIZER
2y 9m to grant Granted Sep 08, 2026
Patent 12689513
LEVERAGING USER'S VIRTUAL INTERACTIONS TO INFLUENCE PREFERRED MESSAGE COMMUNICATION TIMING
2y 7m to grant Granted Jul 21, 2026
Patent 12683784
DATA ANALYSIS SYSTEMS AND METHODS FOR DETECTING ANOMALIES IN TOKENIZED DATASETS
2y 11m to grant Granted Jul 14, 2026
Patent 12659742
ENSURING SECURE ATTACHMENT IN SIZE CONSTRAINED AUTHENTICATION PROTOCOLS
5y 0m to grant Granted Jun 16, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
78%
Grant Probability
99%
With Interview (+27.6%)
3y 0m (~5m remaining)
Median Time to Grant
High
PTA Risk
Based on 796 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month