Prosecution Insights
Last updated: October 02, 2026
Application No. 18/656,520

AUTOMATED THREAT MODELING USING APPLICATION RELATIONSHIPS

Final Rejection §101§112§DOUBLEPATENT
Filed
May 06, 2024
Priority
Jun 01, 2018 — continuation of 12/019,742
Examiner
DAVIS, ZACHARY A
Art Unit
2492
Tech Center
2400 — Computer Networks
Assignee
Amazon Technologies Inc.
OA Round
4 (Final)
53%
Grant Probability
Moderate
5-6
OA Rounds
2y 1m
Est. Remaining
75%
With Interview

Examiner Intelligence

Grants 53% of resolved cases
53%
Career Allowance Rate
274 granted / 513 resolved
-4.6% vs TC avg
Strong +22% interview lift
Without
With
+21.6%
Interview Lift
resolved cases with interview
Typical timeline
4y 5m
Avg Prosecution
36 currently pending
Career history
569
Total Applications
across all art units

Statute-Specific Performance

§101
12.2%
-27.8% vs TC avg
§103
30.9%
-9.1% vs TC avg
§102
15.8%
-24.2% vs TC avg
§112
38.7%
-1.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 513 resolved cases

Office Action

§101 §112 §DOUBLEPATENT
DETAILED ACTION A response was received on 26 May 2026. By this response, Claims 21, 25-27, 30, 31, 35, 39, and 40 have been amended. No claims have been added or canceled. Claims 21-40 are currently pending in the present application. Response to Amendment The amendments to the claims do not clearly comply with the requirement of 37 CFR 1.121(c)(2) that amended claims must include markings indicating the changes made relative to the immediate prior version of the claims. In particular, at least Claim 25 appears to have had text added without being marked with underlining as required, and Claim 25 also appears to include text, marked with strikethrough for deletion, which was not previously present in the claim. As a courtesy and to advance prosecution of the present application, the amendments to the claims have been treated as though they were fully in compliance with the requirements of 37 CFR 1.121(c). However, Applicant is reminded that all subsequent amendments must fully comply with the provisions of 37 CFR 1.121. Response to Arguments Applicant’s summary of the interview appears to be inaccurate. Applicant lists both 06 May 2026 (the correct date of the telephonic interview) and 26 May 2026 as the date of the interview. Applicant also refers to “Examiner Ford” which appears to be a typographical error (see page 9 of the present response). It is further noted that, although the Examiner did indicate that the amendments proposed in the interview appeared likely to overcome the rejections relating to Claims 21 and 25 under 35 U.S.C. 112(b), Applicant has submitted amendments different amendments to Claims 25 and 26 than those proposed. Applicant’s arguments with respect to the rejection of Claims 21-40 under 35 U.S.C. 101 are persuasive to the extent that the amendments to independent Claims 21, 27, and 35 now clearly integrate a practical application, and more specifically that restricting threat modeling to a particular (second) sub-graph provides an improvement that integrates the abstract idea into a practical application, by reducing the use of computational and memory resources by restricting threat modeling analysis to a particular subset of a graph (see advantage 5 of paragraph 0012 of the present specification, as cited at pages 17 and 19 of the present response). It is noted that Applicant’s remaining arguments regarding other purported advantages do not clearly find nexus with the claimed limitations; however, the advantage noted above is sufficient to integrate the recited abstract idea into a practical application, and therefore, the rejection under 35 U.S.C. 101 is withdrawn. See also the notice of allowance mailed 07 February 2024 in the parent application Serial No. 15/996,361. Applicant's arguments filed 26 May 2026 have been fully considered but they are not persuasive. Regarding the nonstatutory double patenting rejection of Claims 21, 27, 34, and 35, Applicant asserts that the explanation provided in the rejection is conclusory (pages 9-10 of the present response; Applicant also makes an unclear reference to claims 9 and 10, but pending claims 9 and 10 are canceled and patented claims 9 and 10 were not cited in the rejection). However, as quoted in Applicant’s remarks, the rejection did explicitly explain the correspondence between the various limitations in the pending and patented claims, as well as how the pending claims are broader than the patented claims (i.e. the patented claims recite additional details compared to the pending claims). As per MPEP 804 II.B.2, a claim under examination is not patentably distinct from the reference claim(s) if the claim under examination is anticipated by the reference claim(s), citing In re Goodman, 11 F.3d 1046, 1052, 29 USPQ2d 2010, 2015-16 (Fed. Cir. 1993). The present analysis falls into this fact pattern, where the entire scope of the reference claims falls within the scope of the examined claims. In this situation, an obviousness analysis is not required and the rejection should explain the fact that the claim in the conflicting patent anticipates the broader claim in the application being examined, which is what was done in the outstanding rejection. For Applicant’s convenience and to provide even further detail, the narrative analysis has been supplemented by a table clearly mapping the corresponding limitations of the patented and pending claims in a side-by-side manner. Regarding the rejection of Claims 21-26, 30, 31, and 35-40 under 35 U.S.C. 112(b) as indefinite, Applicant merely asserts that the claims have been clarified (pages 11-12 of the present response). However, it is noted that not all issues have been clearly addressed by the present amendments, and the amendments have also raised new issues. Regarding the rejections of Claims 21-40 under 35 U.S.C. 102 as anticipated by, or in the alternative, under 35 U.S.C. 103 as obvious over Olson et al, US Patent Application Publication 2015/0244734, and Tonn, US Patent 8650170, and with general reference to independent Claims 21, 27, and 35, Applicant first argues that Olson does not disclose that “at least a portion of the edges represent relationships, determined based at least in part on static code analysis, dynamic analysis, or metadata, between software components” (pages 13-14 of the present response, citing paragraphs 0023-0024 and 0051-0071 of Olson). In response to applicant's argument that the references fail to show certain features of the invention, it is noted that the features upon which applicant relies (i.e., that the relationships are determined based on static code analysis, dynamic analysis, or metadata) are not recited in the rejected claim(s). Although the claims are interpreted in light of the specification, limitations from the specification are not read into the claims. See In re Van Geuns, 988 F.2d 1181, 26 USPQ2d 1057 (Fed. Cir. 1993). At least Olson does disclose that edges describe relationships between nodes (Olson, paragraph 0069, where a node represents fundamental data and a fundamental includes a software component as per paragraph 0006). Applicant’s further arguments that the combination of Olson and Tonn does not disclose performing additional threat modeling on a second sub-graph in response to receipt of a new rule or new policy (pages 14-16 of the present response, citing paragraphs 0080-0109, 0023-0024, and 0051-0071 of Olson, as well as column 2, lines 6-47 of Tonn) also do not clearly reflect the claims as currently amended. However, as noted below, the amendments to the claims more narrowly reciting that the additional threat modeling is “restricted to” the second sub-graph are sufficient to overcome the outstanding rejections under 35 U.S.C. 102 or 103. Therefore, for the reasons detailed below, the Examiner maintains the rejections as set forth below. Claim Objections Claims 25, 27, 30, 33, and 35 are objected to because of the following informalities: In Claim 25, line 5, either the comma or the colon after “modeling” should be deleted. In Claim 27, line 15, it appears that “determine” should read “determining” for clear grammar and parallel structure. In Claim 30, line 2, it appears that “ce” should be deleted before “to protect”. In Claim 33, line 2, it appears that “of the” should be inserted between “one or more” and “software components found”. Claim 35 recites “to perform threat modeling the one or more processors are configured to determine…” in lines 10-11. For consistency in the claims, it appears that this may be intended to read that, to perform the threat modeling, the program instructions further cause the processors to determine. Appropriate correction is required. Double Patenting The nonstatutory double patenting rejection of Claims 21, 27, 34, and 35 is NOT withdrawn for the reasons detailed above. The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer. Claims 21, 27, 34, and 35 are rejected on the ground of nonstatutory double patenting as being unpatentable over Claims 1, 5, 11, 12, 14, and 15 of U.S. Patent No. 12,019,742. Although the claims at issue are not identical, they are not patentably distinct from each other because the pending claims are generally broader than and obvious variations of the patented claims. More specifically, pending Claim 21 recites a system corresponding to portions of the system of patented Claim 1 in combination with limitations of Claim 14. Determining the graph in Claim 21 corresponds to generating the graph in Claim 1; determining the sub-graph in Claim 21 corresponds to identifying the sub-graph in Claim 1; the steps of performing threat modeling in Claims 21 and 1 correspond, where patented Claim 1 recites additional details compared to pending Claim 21; and performing additional threat modeling relating to a new policy in Claim 21 corresponds to similar limitations in patented Claim 14. Similarly, pending Claim 27 recites a method corresponding to portions of the method of patented Claim 5 in combination with limitations of Claim 14, and pending Claim 35 recites a software implementation of a method corresponding to portions of the software of patented Claim 15 in combination with limitations of Claim 14. Further, pending Claim 34 recites features corresponding to patented Claims 11 and 12. See the following table for further detail: Present Application 18/656,520 US Patent 12,019,742 21. A system, comprising: one or more computing devices configured to implement a threat modeler, wherein the threat modeler is configured to: determine a graph comprising a plurality of nodes and a plurality of edges, wherein at least a portion of the nodes represent software components and at least a portion of the edges represent relationships between software components; determine, in the graph, a first sub-graph associated with an event indicative of a change to one or more of the nodes or edges in the graph; perform threat modeling on the first sub-graph using one or more analyzers, wherein to perform threat modeling on the first sub-graph the threat modeler is configured to determine, based at least in part on application of one or more rules by one or more rules engines, whether the first sub-graph complies with one or more policies; and responsive to receipt of a new rule to be applied by the one or more rules engines or a new policy, determine, based at least in part on the new rule or the new policy, a second sub-graph of the graph, and perform additional threat modeling restricted to the second sub-graph of the graph using the one or more analyzers to determine compliance of the second sub-graph of the graph according to the new rule or the new policy. 1. A system, comprising: one or more computing devices configured to implement a threat modeler, wherein the threat modeler is configured to: generate a graph of intra-application and inter-application relationships among a plurality of distinct applications, the graph comprising a plurality of nodes and a plurality of edges, wherein at least a portion of the nodes represent application components for respective applications of the plurality of distinct applications and at least a portion of the edges represent relationships between applications or between application components; receive an event indicative of a change to one or more of the application components represented by the nodes, or to the relationships between the applications or between the application components represented by the edges in the graph; modify the graph based at least in part on the change; identify, in the modified graph, a sub-graph associated with the change; perform threat modeling, restricted to the sub-graph associated with the change, using a rules engine, wherein the rules engine applies one or more rules to metadata associated with a plurality of nodes and one or more edges of the sub-graph, and wherein the threat modeling restricted to the sub-graph determines that one or more security threats are present in the sub-graph based at least in part on application of the one or more rules; and transmit, over a network, a notification associated with the one or more security threats determined by the threat modeling restricted to the sub-graph, wherein the notification is transmitted based at least in part on the change made to one or more of the application components represented by the nodes, or to the relationships between the applications or between the application components represented by the edges in the graph. 14. The method as recited in claim 5, further comprising: adding a new policy to the one or more analyzers; determining, in the graph, a plurality of additional sub-graphs associated with a plurality of software products; and performing additional threat modeling on the additional sub-graphs using the one or more analyzers, comprising determining whether the sub-graph complies with the new policy. 27. A computer-implemented method performed by one or more computing devices, comprising: determining a graph comprising a plurality of nodes and a plurality of edges, wherein at least a portion of the nodes represent software components and at least a portion of the edges represent relationships between software components; determining, in the graph, a first sub-graph associated with an event indicative of a change to one or more of the nodes or edges in the graph; performing threat modeling on the first sub-graph using one or more analyzers, wherein performing threat modeling comprises determining, based at least in part on application of one or more rules by one or more rules engines, whether the first sub-graph complies with one or more policies; and responsive to receipt of a new rule to be applied by the one or more rules engines or a new policy, determine, based at least in part on the new rule or the new policy, a second sub-graph of the graph, and performing additional threat modeling restricted to the second sub-graph of the graph using the one or more analyzers to determine compliance of the second sub-graph of the graph according to the new rule or the new policy. 5. A computer-implemented method performed by one or more computing devices, comprising: determining a graph of intra-application and inter-application relationships among a plurality of distinct applications, the graph comprising a plurality of nodes and a plurality of edges, wherein at least a portion of the nodes represent software components for respective applications of the plurality of distinct applications and at least a portion of the edges represent relationships between applications or between software components; determining, in the graph, a sub-graph associated with a change, indicated by an event, that has been made to one or more of: the software components represented by the nodes, or the relationships between the applications or between the software components represented by the edges in the graph; performing, responsive to the event indicative of the change to one or more of the software components or the relationships between the applications or between the software components represented by the edges, threat modeling restricted to the sub-graph associated with the change, using one or more analyzers, comprising determining whether the sub-graph associated with the change complies with one or more policies; and transmitting, over a network, a notification associated with the determining compliance with the one or more policies, wherein the notification is transmitted based at least in part on the change made to one or more of the software components represented by the nodes, or the relationships between the applications or between the software components represented by the edges in the graph. 14. The method as recited in claim 5, further comprising: adding a new policy to the one or more analyzers; determining, in the graph, a plurality of additional sub-graphs associated with a plurality of software products; and performing additional threat modeling on the additional sub-graphs using the one or more analyzers, comprising determining whether the sub-graph complies with the new policy. 34. (Previously presented) The computer-implemented method of claim 27, wherein said determining the graph is based at least in part on: statically analyzing program code or configurations associated with the software components; or analyzing, at runtime, the software components. 11. The method as recited in claim 5, wherein the graph is determined based at least in part on static analysis of program code or configurations associated with the software components. 12. The method as recited in claim 5, wherein the graph is determined based at least in part on runtime analysis of the software components. 35. One or more non-transitory computer-readable media, storing program instructions that when executed on or across one or more processors cause the one or more processors to: determine a graph comprising a plurality of nodes and a plurality of edges, wherein at least a portion of the nodes represent software components and at least a portion of the edges represent relationships between software components; determine, in the graph, a first sub-graph associated with an event indicative of a change to one or more of the nodes or edges in the graph; perform threat modeling on the first sub-graph using one or more analyzers, wherein to perform threat modeling the one or more processors are configured to determine, based at least in part on application of one or more rules by one or more rules engines, whether the first sub-graph complies with one or more policies; and responsive to receipt of a new rule to be applied by the one or more rules engines or a new policy, determine, based at least in part on the new rule or the new policy, a second sub-graph of the graph, and perform additional threat modeling restricted to the second sub-graph of the graph using the one or more analyzers to determine compliance of the second sub-graph of the graph according to the new rule or the new policy. 15. One or more non-transitory computer-readable storage media storing program instructions computer-executable on or across one or more processors to perform: determining a graph of intra-application and inter-application relationships among a plurality of distinct applications, the graph comprising a plurality of nodes and a plurality of edges, wherein at least a portion of the nodes represent software products for respective applications of the plurality of distinct applications and at least a portion of the edges represent relationships between the applications or between the software products; receiving an event indicative of a change to one or more of the software products represented by the nodes, or to the relationships between the applications or between the software products represented by the edges in the graph; determining, in the graph, a sub-graph associated with the change; performing threat modeling, restricted to the sub-graph associated with the change, using a rules engine, wherein performing threat modeling comprises applying one or more rules to the sub-graph, and wherein application of the one or more rules determines whether one or more security vulnerabilities are present in the sub-graph; and transmitting, over a network, a notification associated with the threat modeling restricted to the sub-graph, wherein the notification is transmitted based at least in part on the change made to one or more of the software products represented by the nodes, or the relationships between the applications or between the software products represented by the edges in the graph. 14. The method as recited in claim 5, further comprising: adding a new policy to the one or more analyzers; determining, in the graph, a plurality of additional sub-graphs associated with a plurality of software products; and performing additional threat modeling on the additional sub-graphs using the one or more analyzers, comprising determining whether the sub-graph complies with the new policy. Claim Rejections - 35 USC § 101 The rejection of Claims 21-40 under 35 U.S.C. 101 as directed to abstract ideas without significantly more is withdrawn in light of the amendments to the claims, noting that Applicant’s arguments indicating that restricting threat modeling to a particular (second) sub-graph provides an improvement that integrates the abstract idea into a practical application (see pages 17-19 of the present response) are generally persuasive. Claim Rejections - 35 USC § 112 The rejection of Claims 21-24, 31, 35-38, and 40 under 35 U.S.C. 112(b) is withdrawn in light of the amendments to the claims. The rejection of Claims 25, 26, 30, and 39 under 35 U.S.C. 112(b) as indefinite is NOT withdrawn, because not all issues have been addressed and/or because the amendments have raised new issues, as detailed below. The following is a quotation of 35 U.S.C. 112(a): (a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention. The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112: The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention. Claims 21-40 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claims contain subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. Independent Claims 21, 27, and 35 have been amended to recite “determine, based at least in part on the new rule or the new policy, a second sub-graph of the graph”. Although the specification discloses plural sub-graphs for different applications or services (see paragraph 0040) or that a sub-graph is identified for new program code (see paragraph 0044), and further the entire graph is reviewed with respect to a new rule or new policy (see paragraph 0039), there does not appear to be any description of determining a sub-graph based on a new rule or new policy. Further, Applicant has not pointed out where in the specification where the amended claims are supported. See also MPEP § 2163.04. Therefore, there is not clear written description of the claimed subject matter in the specification. Claims not explicitly referred to above are rejected due to their dependence on a rejected base claim. The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 25, 26, 30, and 39 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claim 25 recites “a policy” in line 3. It is not clear whether this is intended to refer to one of the one or more policies of Claim 21 or the new policy, or to a distinct policy. Claim 25 further recites “security best practice” in lines 3, 8-9, and 17. This term appears to be a relative term which is not clearly defined in the specification or claims and for which a standard of comparison to determine a best practice has not been set forth. See MPEP § 2173.05(b). The claim more specifically recites “a security best practice” in lines 8-9; it is not clear whether this is intended to refer to the same practice as in line 3. The claim additionally recites “the corresponding software component” in lines 14-15. It is not clear to which of the “one or more corresponding software components” in lines 11-12 this is intended to refer. The above ambiguities render the claim indefinite. Claim 26 recites “generate one or more notifications for the corresponding software component found to match the new rule or to violate the new policy comprises generate a notification” in lines 10-12. It is not clear what the subjects of the verbs “comprises” or “generate a notification” are intended to be. The claim further recites “a vulnerability” in lines 12-13. It is not clear whether this is intended to refer to the same vulnerability as in line 3 or a distinct vulnerability. Claim 30 recites “security best practice” in lines 6 and 9. This appears to be a relative term which is not clearly defined in the specification or claims and for which a standard of comparison to determine a best practice has not been set forth. See MPEP § 2173.05(b). Claim 39 recites “the program instruction cause” in line 5. The plural verb “cause” does not agree with the singular subject “instruction”. The claim further recites “security best practices” in line 7. This appears to be a relative term which is not clearly defined in the specification or claims and for which a standard of comparison to determine a best practice has not been set forth. See MPEP § 2173.05(b). Allowable Subject Matter Claims 21-40 would be allowable if rewritten or amended to overcome the rejections under 35 U.S.C. 112(a) and (b), set forth in this Office action, and if the double patenting rejection were overcome by amendment or the filing of a terminal disclaimer. The following is a statement of reasons for the indication of allowable subject matter: Although the closest prior art, Olson and Tonn, generally disclose methods (and corresponding systems and software implementations thereof) that include determining a graph and first sub-graph, performing threat modeling on a first sub-graph, determining a second sub-graph, and performing additional threat modeling on the second sub-graph, none of the cited art, alone or in combination, clearly recites performing the additional threat modeling restricted to the second sub-graph in combination with the other claimed limitations. Therefore, the claims recite allowable subject matter. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to Zachary A Davis whose telephone number is (571)272-3870. The examiner can normally be reached Monday-Friday, 9:00am-5:30pm, Eastern Time. Examiner interviews are available via telephone and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Rupal D Dharia can be reached at (571) 272-3880. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /Zachary A. Davis/Primary Examiner, Art Unit 2492
Read full office action

Prosecution Timeline

Show 9 earlier events
Jan 15, 2026
Response after Non-Final Action
Feb 03, 2026
Request for Continued Examination
Feb 13, 2026
Response after Non-Final Action
Feb 24, 2026
Non-Final Rejection mailed — §101, §112, §DOUBLEPATENT
May 06, 2026
Applicant Interview (Telephonic)
May 06, 2026
Examiner Interview Summary
May 26, 2026
Response Filed
Aug 17, 2026
Final Rejection mailed — §101, §112, §DOUBLEPATENT (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12676750
Methods, Systems, and Devices for Server Control of Client Authorization Proof of Possession
4y 5m to grant Granted Jul 07, 2026
Patent 12676751
Methods, Systems, and Devices for Server Control of Client Authorization Proof of Possession
4y 5m to grant Granted Jul 07, 2026
Patent 12659750
ULTRA-WIDEBAND UNLOCK DEVICE
3y 8m to grant Granted Jun 16, 2026
Patent 12592929
TECHNIQUE FOR COMPUTING A BLOCK IN A BLOCKCHAIN NETWORK
4y 9m to grant Granted Mar 31, 2026
Patent 12566840
Systems And Methods For Creating Trustworthy Orchestration Instructions Within A Containerized Computing Environment For Validation Within An Alternate Computing Environment
3y 7m to grant Granted Mar 03, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
53%
Grant Probability
75%
With Interview (+21.6%)
4y 5m (~2y 1m remaining)
Median Time to Grant
High
PTA Risk
Based on 513 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month