Prosecution Insights
Last updated: October 02, 2026
Application No. 18/631,653

SECURE EXPOSURE OF ACCESS POLICIES FOR PROTECTED RESOURCES

Non-Final OA §103
Filed
Apr 10, 2024
Examiner
WILCOX, JAMES J
Art Unit
2439
Tech Center
2400 — Computer Networks
Assignee
SAP SE
OA Round
3 (Non-Final)
70%
Grant Probability
Favorable
3-4
OA Rounds
9m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 70% — above average
70%
Career Allowance Rate
437 granted / 623 resolved
+12.1% vs TC avg
Strong +61% interview lift
Without
With
+61.2%
Interview Lift
resolved cases with interview
Typical timeline
3y 2m
Avg Prosecution
25 currently pending
Career history
659
Total Applications
across all art units

Statute-Specific Performance

§101
15.0%
-25.0% vs TC avg
§103
58.6%
+18.6% vs TC avg
§102
14.5%
-25.5% vs TC avg
§112
7.1%
-32.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 623 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION This Office Action is in response to the Amendment filed 07/24/2026. In the instant Amendment, claims 1, 9 and 16 are amended; claims 2, 10 and 17 are cancelled; claims 1, 9 and 16 are independent claims. Claims 1, 3-9, 11-16 and 18-20 are pending in this application. Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 07/24/2026 has been entered. Response to Arguments Applicant’s arguments with respect to claim(s) 1, 9 and 16 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1, 9 and 16 are rejected under 35 U.S.C. 103 as being unpatentable over Xing et al (“Xing,” US 20160036860) in view of Pedroza et al (“Pedroza,” US 20140282831). Regarding claim 1, Xing discloses a computer-implemented method, the method comprising: receiving, by an access policy manager and from an automation tool, a first request to obtain access policy metadata of a first resource, wherein the first resource is provided at a first data storage; (Xing discloses [0059], [0063], [0079], [0091] receiving, by an access policy manager and from an automation tool, a first request to obtain access policy metadata of a first resource, wherein the first resource is provided at a first data storage [attributes such as resource tags, identity, time, location are access policy metadata] see [0100], [0085]; access policy metadata is described in [0085], [0089]-[0091], [0106]) sending, by the access policy manager, the second request to access an interface at the first data storage to obtain the access policy metadata, (Xing discloses [0091], [0057], [0079] sending, by the access policy manager, the second request to access an interface at the first data storage to obtain the access policy metadata; [attributes such as resource tags, identity, time, location are access policy metadata] see [0100], [0085]; access policy metadata is described in [0085], [0089]-[0091], [0106])) and obtaining the access policy metadata relevant for the first resource to provide the access policy metadata to the automation tool, (Xing discloses [0063], [0059], [0079], [0052] and obtaining the access policy metadata relevant for the first resource to provide the access policy metadata to the automation tool; [attributes such as resource tags, identity, time, location are access policy metadata] see [0100], [0085]; access policy metadata is described in [0085], [0089]-[0091], [0106]) Xing further discloses an access policy manager (See Xing discloses [0059], [0062]-[0063], [0079], [0091] Xing fails to explicitly disclose identifying, by the access policy manager and based on the first request received from the automation tool, a type of the first data storage; in response to identifying the type of the first data storage, generating by an access policy schema creator of the access policy manager, a second request according to a metadata schema defining a predefined syntax and parameters relevant to the type of the first data storage to obtain the access policy metadata. However, in an analogous art, Pedroza discloses identifying, by the access policy manager (Pedroza, [0051], [0055]-[0056], FIG 4-5 describe the PDP receives XAMCL policy queries and implements policy decisions. The dynamic-query functionality is implemented in the PDP or another authorization engine) and based on the first request received from the automation tool, (Pedroza, [0056]-[0057], FIG 5 describes application 500 sends entitlement request 501 to PDP 502. The query is generated at runtime during processing of that entitlement request and upon receipt of it) a type of the first data storage; (Pedroza, [0056], [0059], FIG 7, step 702 describes the external repository may be one or many different types and that those repositories may differ in structure, design and query language. The preferred query generation process normalizes the rule for consistency across back-end data store types including DB2 and LDAP) in response to identifying the type of the first data storage, (Pedroza, [0067], FIG 7, steps 702-704 translates a generic/intermediary query into a native query specific to the type of data repository to be queried. In the SQL example, because the repository is a SQL database, the normalized query is translated into SQL) generating by an access policy schema creator of the access policy manager, a second request according to a metadata schema defining a predefined syntax and parameters relevant to the type of the first data storage to obtain the access policy metadata, (Pedroza, [0058]-[0059]; FIG’s 6-7 describes each applicable XACML rule, the PDP dynamically generates a query to an external data repository; FIG 7 shows the formulation sequence: determine rule then map to specific query format then populate request-derived values; [0059], [0082], FIG 7 the PDP performs the query-generation function by mapping XACML rule logic into an intermediary representation and then into a repository-specific query representation; [0058]-[0059], [0067]-[0070], FIG 7, steps 704; 706 describe the intermediary representation is mapped to a specific query format appropriate to the repository. The SQL syntax is distinguished from an LDAP search filter then populate the resulting query using known fields/values and mappings; [0059], [0063], [0070], FIG 4 & 7 describes the generated query to obtain a candidate set of entitlement values that is then evaluated values that is then evaluated against the security policy. Policy-related attributes are fetched from external sources, including LDAP/PIP and database tables) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claim invention to combine the teachings of Pedroza with Xing to include identifying, by the access policy manager and based on the first request received from the automation tool, a type of the first data storage; in response to identifying the type of the first data storage, generating by an access policy schema creator of the access policy manager, a second request according to a metadata schema defining a predefined syntax and parameters relevant to the type of the first data storage to obtain the access policy metadata.. One would have been motivated to evaluate context-based policies for authorization and entitlements processing (Pedroza, [0002]). Regarding claim 9, claim 9 is a directed to a non-transitory computer-readable storage medium. Claim 9 is similar in scope to claim 1 and is therefore rejected under the same rationale. Regarding claim 16, claim 16 is a directed to a system. Claim 16 is similar in scope to claim 1 and is therefore rejected under the same rationale. Claims 3, 7, 11, 15 and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Xing et al (“Xing,” US 2016036860) in view of Pedroza et al (“Pedroza,” US 20140282831) and further in view of Desai et al (“Desai,” US 8,326,882). Regarding claim 3, Xing and Pedroza disclose the method of claim 1. Xing and Pedroza fail to explicitly disclose comprising: instantiating one or more validator components, each validator component being associated with a type of a data storage and being configured to generate requests according to a respective metadata schema associated with the respective type of the data storage; wherein sending the second request comprises: identifying a validator component corresponding to an identified type of the first data storage, and wherein the second request is generated at the validator component However, in an analogous art, Desai discloses comprising: instantiating one or more validator components, each validator component being associated with a type of a data storage and being configured to generate requests according to a respective metadata schema associated with the respective type of the data storage; (Desai discloses Col. 3, Lines 13-44; Col. 4, Lines 1-10; comprising: instantiating one or more validator components, each validator component being associated with a type of a data storage and being configured to generate requests according to a respective metadata schema associated with the respective type of the data storage) wherein sending the second request comprises: identifying a validator component corresponding to an identified type of the first data storage, (Desai discloses Col. 3, Lines 13-44; Col. 4, Lines 1-10 wherein sending the second request comprises: identifying a validator component corresponding to an identified type of the first data storage “discloses selecting the correct adapter”) and wherein the second request is generated at the validator component (Desai discloses Col. 3, Lines 13-44; Col. 4, Lines 1-10; and wherein the second request is generated at the validator component) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claim invention to combine the teachings of Desai with Xing and Pedroza to include comprising: instantiating one or more validator components, each validator component being associated with a type of a data storage and being configured to generate requests according to a respective metadata schema associated with the respective type of the data storage; wherein sending the second request comprises: identifying a validator component corresponding to an identified type of the first data storage, and wherein the second request is generated at the validator component. One would have been motivated to provide an environment management interface for management of a heterogeneous storage environment (Desai, Col. 1, Lines 59-60) Regarding claim 7, Xing and Pedroza disclose the method of claim 1. Xing further discloses an access policy manager (Xing discloses [0079] an access policy manager; [attributes such as resource tags, identity, time, location are access policy metadata] see [0100], [0085]) Xing and Pedroza fail to explicitly disclose wherein the access policy manager is communicatively coupled to a plurality of data storages, at least two data storages being of different type and associated with a different metadata schema However, in an analogous art, Desai discloses wherein the access policy manager is communicatively coupled to a plurality of data storages, at least two data storages being of different type and associated with a different metadata schema, (Desai discloses Col. 3, Lines 13-44; Col. 4, Lines 1-10 wherein the access policy manager is communicatively coupled to a plurality of data storages, at least two data storages being of different type and associated with a different metadata schema) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claim invention to combine the teachings of Desai with Xing and Pedroza to include wherein the access policy manager is communicatively coupled to a plurality of data storages, at least two data storages being of different type and associated with a different metadata schema. One would have been motivated to provide an environment management interface for management of a heterogeneous storage environment (Desai, Col. 1, Lines 59-60) Regarding claim 11, claim 11 is directed to the non-transitory computer-readable medium of claim 9. Claim 11 is similar in scope to claim 3 and is therefore rejected under the same rationale. Regarding claim 15, claim 15 is directed to the non-transitory computer-readable medium of claim 9. Claim 15 is similar in scope to claim 7 and is therefore rejected under the same rationale. Regarding claim 18, claim 18 is a directed to the system of 16. Claim 18 is similar in scope to claim 3 and is therefore rejected under the same rationale. Claims 4, 12 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Xing et al (“Xing,” US 2016036860) in view of Pedroza et al (“Pedroza,” US 20140282831) and further in view of Kerametlian et al (“Kerametlian,” US 20170208075). Regarding claim 4, Xing and Pedroza disclose the method of claim 1. Xing further discloses wherein the executed resource management operations are pre-evaluated based on processing obtained access policy metadata from the access policy manager, (Xing discloses [0051]-[0054], [0059] wherein the executed resource management operations are pre-evaluated based on processing obtained access policy metadata from the access policy manager, and wherein the obtained access policy metadata includes a threshold lock policy value for the first resource; [attributes such as resource tags, identity, time, location are metadata] see [0100], [0085]) Xing and Pedroza fail to explicitly disclose wherein the automation tool is configured to execute resource management operations over resources comprising the first resource. However, in an analogous art, Kruse discloses wherein the automation tool is configured to execute resource management operations over resources comprising the first resource, (Kruse discloses [0014], [0018]-[0019] wherein the automation tool is configured to execute resource management operations over resources comprising the first resource) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claim invention to combine the teachings of Kruse with Xing and Pedroza to include wherein the automation tool is configured to execute resource management operations over resources comprising the first resource.. One would have been motivated to providing an automated mechanism through which new credentials for a calling application may be created and locally stored, and old credentials may be Deactivated (Kruse, [0014]). Xing, Pedroza and Kruse fail to explicitly disclose and wherein the obtained access policy metadata includes a threshold lock policy value for the first resource. However, in an analogous art Kerametlian discloses and wherein the obtained access policy metadata includes a threshold lock policy value for the first resource, (Kerametlian discloses [0035], and wherein the obtained access policy metadata includes a threshold lock policy value for the first resource; also see [0008]-[0012]) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claim invention to combine the teachings of Kerametlian with Xing and Pedroza to include and wherein the obtained access policy metadata includes a threshold lock policy value for the first resource. One would have been motivated to provide a smart password system that mitigates issues found in prior password systems and provide a better user experience without compromising security (Kerametlian, [0008]). Regarding claim 12, claim 12 is directed to the non-transitory computer-readable medium of claim 9. Claim 12 is similar in scope to claim 4 and is therefore rejected under the same rationale. Regarding claim 19, claim 19 is a directed to the system of 16. Claim 19 is similar in scope to claim 4 and is therefore rejected under the same rationale. Claims 5, 8, 13 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Xing et al (“Xing,” US 2016036860), Pedroza et al (“Pedroza,” US 20140282831) in view of Kerametlian et al (“Kerametlian,” US 20170208075) and further in view of Kruse et al (“Kruse,” US 20160357955). Regarding claim 5, Xing and Pedroza disclose the method of claim 1. Xing further discloses comprising: obtaining, by the automation tool, the access policy metadata relevant for the first resource; (Xing discloses [0091], [0051]-[0052], [0054] comprising: obtaining, by the automation tool, the access policy metadata relevant for the first resource; [attributes such as resource tags, identity, time, location are access policy metadata] see [0100], [0085]) Xing and Pedroza fail to explicitly disclose and determining, by the automation tool, whether to validate new credentials provided for accessing the first resource at the automation tool by using a threshold lock policy value for the first resource as obtained from the access policy metadata for the first resource, However, in an analogous art, Kerametlian discloses and determining, by the automation tool, whether to validate new credentials provided for accessing the first resource at the automation tool by using a threshold lock policy value for the first resource as obtained from the access policy metadata for the first resource, (Kermetlian discloses [0035], and determining, by the automation tool, whether to validate new credentials provided for accessing the first resource at the automation tool by using a threshold lock policy value for the first resource as obtained from the access policy metadata for the first resource; also see [0008]-[0012]) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claim invention to combine the teachings of Kermetlian with Xing and Pedroza to include and determining, by the automation tool, whether to validate new credentials provided for accessing the first resource at the automation tool by using a threshold lock policy value for the first resource as obtained from the access policy metadata for the first resource. One would have been motivated to provide a smart password system that mitigates issues found in prior password systems and provide a better user experience without compromising security (Kerametlian, [0008]). Xing, Pedroza and Kermetlian fail to explicitly disclose wherein the automation tool is configured to send the first request to the access policy manager responsive to a received request from an entity to change account credentials to be used when authenticating the entity for accessing the first resource at the first data storage. However, in analogous art, Kruse discloses wherein the automation tool is configured to send the first request to the access policy manager responsive to a received request from an entity to change account credentials to be used when authenticating the entity for accessing the first resource at the first data storage (Kruse discloses [0014]-[0017], [0020], wherein the automation tool is configured to send the first request to the access policy manager responsive to a received request from an entity to change account credentials to be used when authenticating the entity for accessing the first resource at the first data storage) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claim invention to combine the teachings of Kruse with Xing, Pedroza and Kermetlian to include wherein the automation tool is configured to send the first request to the access policy manager responsive to a received request from an entity to change account credentials to be used when authenticating the entity for accessing the first resource at the first data storage. One would have been motivated to providing an automated mechanism through which new credentials for a calling application may be created and locally stored, and old credentials may be deactivated (Kruse, [0014]). Regarding claim 8, Xing and Pedroza disclose the method of claim 1. Xing and Pedroza fail to explicitly disclose comprising: obtaining, at the automation tool and based on provided access policy metadata for resource from the access policy manager, one or more threshold lock policy value for one or more respective resource by extracting a respective threshold lock policy value from a respective access policy metadata; determining, at the automation tool, whether to validate the new log-in credential by determining whether a tracked number of attempts to access the resource by the account has reached a threshold lock policy value for the resource, wherein the threshold lock policy value is identified as relevant for the resource that is associated with the third request to change the old log-in credential to a new log-in credential for the account; and in response to invalidating the new log-in credential by determining that the tracked number of attempts to access the resource exceeds the threshold lock policy value, denying, by the automation tool, changing the old log-in credential to the new log-in credential. However, in an analogous art, Kermetlian discloses comprising: obtaining, at the automation tool and based on provided access policy metadata for resource from the access policy manager, one or more threshold lock policy value for one or more respective resource by extracting a respective threshold lock policy value from a respective access policy metadata, (Kermetlian discloses [0035] comprising: obtaining, at the automation tool and based on provided access policy metadata for resource from the access policy manager, one or more threshold lock policy value for one or more respective resource by extracting a respective threshold lock policy value from a respective access policy metadata) determining, at the automation tool, whether to validate the new log-in credential by determining whether a tracked number of attempts to access the resource by the account has reached a threshold lock policy value for the resource, wherein the threshold lock policy value is identified as relevant for the resource that is associated with the third request to change the old log-in credential to a new log-in credential for the account; and in response to invalidating the new log-in credential by determining that the tracked number of attempts to access the resource exceeds the threshold lock policy value, denying, by the automation tool, changing the old log-in credential to the new log-in credential (Kermetlian discloses in [0035], [0056], [0046], FIG 2 determining, at the automation tool, whether to validate the new log-in credential by determining whether a tracked number of attempts to access the resource by the account has reached a threshold lock policy value for the resource, wherein the threshold lock policy value is identified as relevant for the resource that is associated with the third request to change the old log-in credential to a new log-in credential for the account; and in response to invalidating the new log-in credential by determining that the tracked number of attempts to access the resource exceeds the threshold lock policy value, denying, by the automation tool, changing the old log-in credential to the new log-in credential). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claim invention to combine the teachings of Kermetlian with Xing and Pedroza to include comprising: obtaining, at the automation tool and based on provided access policy metadata for resource from the access policy manager, one or more threshold lock policy value for one or more respective resource by extracting a respective threshold lock policy value from a respective access policy metadata; determining, at the automation tool, whether to validate the new log-in credential by determining whether a tracked number of attempts to access the resource by the account has reached a threshold lock policy value for the resource, wherein the threshold lock policy value is identified as relevant for the resource that is associated with the third request to change the old log-in credential to a new log-in credential for the account; and in response to invalidating the new log-in credential by determining that the tracked number of attempts to access the resource exceeds the threshold lock policy value, denying, by the automation tool, changing the old log-in credential to the new log-in credential. One would have been motivated to provide a smart password system that mitigates issues found in prior password systems and provide a better user experience without compromising security (Kerametlian, [0008]). Xing, Pedroza and Kerametlian fail to explicitly disclose receiving, at the automation tool, a third request to change an old log-in credential of an account for authenticating to access a resource to a new log-in credential, wherein the third request is received from an entity authenticated at the automation tool, and wherein the automation tool is configured to execute resource management operations over resources comprising the resource. However, in an analogous art, Kruse discloses receiving, at the automation tool, a third request to change an old log-in credential of an account for authenticating to access a resource to a new log-in credential, wherein the third request is received from an entity authenticated at the automation tool, and wherein the automation tool is configured to execute resource management operations over resources comprising the resource, (Kruse discloses in [0014], [0016]-[0017], [0021] receiving, at the automation tool, a third request to change an old log-in credential of an account for authenticating to access a resource to a new log-in credential, wherein the third request is received from an entity authenticated at the automation tool, and wherein the automation tool is configured to execute resource management operations over resources comprising the resource) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claim invention to combine the teachings of Kruse with Xing, Pedroza and Kermetlian to include receiving, at the automation tool, a third request to change an old log-in credential of an account for authenticating to access a resource to a new log-in credential, wherein the third request is received from an entity authenticated at the automation tool, and wherein the automation tool is configured to execute resource management operations over resources comprising the resource. One would have been motivated to providing an automated mechanism through which new credentials for a calling application may be created and locally stored, and old credentials may be deactivated (Kruse, [0014]). Regarding claim 13, claim 13 is directed to the non-transitory computer-readable medium of claim 9. Claim 13 is similar in scope to claim 5 and is therefore rejected under the same rationale. Regarding claim 20, claim 20 is a directed to the system of 16. Claim 20 is similar in scope to claim 5 and is therefore rejected under the same rationale. Claims 6 and 14 are rejected under 35 U.S.C. 103 as being unpatentable over Xing et al (“Xing,” US 2016036860) in view of Pedroza et al (“Pedroza,” US 20140282831) and further in view of Kruse et al (“Kruse,” US 20160357955). Regarding claim 6, Xing and Pedroza disclose the method of claim 1. Xing further discloses and wherein the credentials are validated to determine whether the second request is associated with an entity authorized to access resources at the first data storage (Xing discloses [0052], [0059], [0079] and wherein the credentials are validated to determine whether the second request is associated with an entity authorized to access resources at the first data storage) Xing and Pedroza fail to explicitly disclose wherein the second request sent by the access policy manager to the first data storage is authenticated at the first data storage based on credentials provided by the access policy manager, wherein the credentials are obtained through the first request received from the automation tool, However, in an analogous art, Kruse discloses wherein the second request sent by the access policy manager to the first data storage is authenticated at the first data storage based on credentials provided by the access policy manager, wherein the credentials are obtained through the first request received from the automation tool, and wherein the credentials are validated to determine whether the second request is associated with an entity authorized to access resources at the first data storage, (Kruse discloses in [0020]-[0021], [0061], [0042]-[0043], wherein the second request sent by the access policy manager to the first data storage is authenticated at the first data storage based on credentials provided by the access policy manager, wherein the credentials are obtained through the first request received from the automation tool, and wherein the credentials are validated to determine whether the second request is associated with an entity authorized to access resources at the first data storage) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claim invention to combine the teachings of Kruse with Xing and Pedroza to include wherein the second request sent by the access policy manager to the first data storage is authenticated at the first data storage based on credentials provided by the access policy manager, wherein the credentials are obtained through the first request received from the automation tool, and wherein the credentials are validated to determine whether the second request is associated with an entity authorized to access resources at the first data storage. One would have been motivated to providing an automated mechanism through which new credentials for a calling application may be created and locally stored, and old credentials may be deactivated (Kruse, [0014]). Regarding claim 14, claim 14 is directed to the non-transitory computer-readable medium of claim 9. Claim 14 is similar in scope to claim 6 and is therefore rejected under the same rationale. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to JAMES J WILCOX whose telephone number is (571)270-3774. The examiner can normally be reached M-F: 8 A.M. to 5 P.M.. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Luu T. Pham can be reached at (571)270-5002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /JAMES J WILCOX/Examiner, Art Unit 2439 /LUU T PHAM/Supervisory Patent Examiner, Art Unit 2439
Read full office action

Prosecution Timeline

Apr 10, 2024
Application Filed
Jan 08, 2026
Non-Final Rejection mailed — §103
Apr 02, 2026
Response Filed
Apr 29, 2026
Final Rejection mailed — §103
Jul 24, 2026
Request for Continued Examination
Jul 27, 2026
Response after Non-Final Action
Aug 25, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750351
UNIQUE MACHINE-USER ID-SSH KEY FINGERPRINT
3y 4m to grant Granted Sep 29, 2026
Patent 12732357
SYSTEM AND METHOD SUPPORTING DATA RESIDENCY REQUIREMENT IN CLOUD HOSTED HARDWARE SECURITY MODULES
1y 5m to grant Granted Sep 08, 2026
Patent 12719868
METHOD, APPARATUS, AND COMPUTER-READABLE RECORDING MEDIUM FOR CONTROLLING ACCESS TO REMOTE SYSTEM IN HOME NETWORK ENVIRONMENT
3y 2m to grant Granted Aug 25, 2026
Patent 12719869
MULTI-TENANT SECRETS MANAGER
2y 7m to grant Granted Aug 25, 2026
Patent 12719871
SYSTEMS AND METHODS FOR DATA SEGREGATION AND SECURITY BASED ON ACCESS RIGHTS FOR ADDITIONAL SERVICES
2y 3m to grant Granted Aug 25, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
70%
Grant Probability
99%
With Interview (+61.2%)
3y 2m (~9m remaining)
Median Time to Grant
High
PTA Risk
Based on 623 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month