Prosecution Insights
Last updated: October 02, 2026
Application No. 18/664,660

ROW LEVEL SECURITY ON DATABASE OBJECTS

Non-Final OA §102§103§112
Filed
May 15, 2024
Examiner
ZHU, ZHIMEI
Art Unit
2495
Tech Center
2400 — Computer Networks
Assignee
SAP SE
OA Round
3 (Non-Final)
78%
Grant Probability
Favorable
3-4
OA Rounds
3m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 78% — above average
78%
Career Allowance Rate
230 granted / 296 resolved
+19.7% vs TC avg
Strong +37% interview lift
Without
With
+37.1%
Interview Lift
resolved cases with interview
Typical timeline
2y 8m
Avg Prosecution
9 currently pending
Career history
306
Total Applications
across all art units

Statute-Specific Performance

§101
10.3%
-29.7% vs TC avg
§103
49.5%
+9.5% vs TC avg
§102
10.4%
-29.6% vs TC avg
§112
18.9%
-21.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 296 resolved cases

Office Action

§102 §103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 6/22/2026 has been entered. Response to Arguments Applicant’s arguments with respect to claim(s) 1, 3-11, and 13-20 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. Claim Rejections - 35 USC § 112 The following is a quotation of the first paragraph of 35 U.S.C. 112(a): (a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention. The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112: The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention. Claims 1, 3-11, and 13-20 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. Independent claims 1, 11 and 20 recite “dynamically generating a first filter predicate string based on the first row level security policy by invoking a condition provider procedure that returns an authorization filter for a first user”. The originally filed specification fails to disclose that the authorization filter based on the first row level security policy is for a first user because the originally filed specification discloses in claim 5 that the second query result set based on the first row level security policy is specific to a second user that caused the first query to be generated. Therefore, independent claims 1, 11 and 20 and their dependent claims contain new matters. Claim Rejections - 35 USC § 102 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. Claims 1, 3, 10, 11, 13, 19 and 20 are rejected under 35 U.S.C. 102(a)(2) as being anticipated by Li (US 2025/0278508). Regarding claims 1, 11 and 20, Li teaches A computer-implemented method comprising: detecting a first query targeting a first database object (see [0069] and Fig. 7: “The query processing module 335 receives 720 a database query for processing.”); responsive to determining that a first row level security policy is defined for the first database object (see [0068] and Fig. 7: “The data processing service 102 receives 710 an access control policy specification that specifies the access control policy. The access control policy specification may specify conditions associated with data access for users. According to an embodiment, the conditions are specified as expressions based on attributes describing the data. For example, the attribute may be a column or field of the data or the attribute may be a tag associated with the data.” And see [0022]: “The system supports fine grained data access control, for example, access to a subset of rows, access to a subset of columns, access requiring masking of sensitive information, and so on. Accordingly, the process performing the data processing needs fine grained access control. … An example of fine-grained access control policy is that a user has access to all rows that satisfy a condition based on one or more attributes, for example, all rows having state=“California”.”): dynamically generating a first filter predicate string based on the first row level security policy by invoking a condition provider procedure that returns an authorization filter for a first user, wherein the first row level security policy binds the first database object and the condition provider procedure (see [0072] and Fig. 7: “The query processing module 335 determines 740 filter conditions based on access control policies specified in the access control policy specification. The filter conditions include instructions to determine a subset of data of a dataset, for example, a file. The subset of data represents the data of the dataset that is accessible to the user providing the database query according to the access control policy.” And see [0073]: “For example, the query processing module 335 may determine that the subset of data of dataset D1 stored in file F1 that is accessible to the user is determined using a condition C1.” The Examiner interprets a condition C1 as a first filter predicate string.); converting the first filter predicate string into a first query optimizer predicate that is inserted into a query optimizer tree such that the first filter predicate string is applied to one or more nodes of the query optimizer tree (see [0059] and Fig. 5: “The logical plan generation module 530 generates a logical plan for the database query. The logical plan includes representation of the various steps that need to be executed for processing the database query. … The logical plan generation module 530 further optimizes the resolved logical plan to obtain an optimized logical plan.” And see [0060]: “The physical plan generation module 540 may generate different physical plans for the same logical plan and evaluate each physical plan using a cost model to select the optimal physical plan for execution.” Also see [0070] and Fig. 6: “The query processing module 335 compiles 730 the database query to generate a query plan, for example, a query plan similar to that illustrated in FIG. 6. The query plan includes a set of database operators. According to an embodiment, the query plan is a graph made up of nodes representing database operators and edges connecting the database operators. The graph corresponding to a database query may include an edge E from a database operator O1 to a database operator O2 indicating that the output generated by the database operator O1 is provided as input to the database operator O2.” The Examiner interprets the query plan 610 shown in Fig. 6, which is a graph made up of nodes representing database operators and edges connecting the database operators, as a query optimizer tree. And see [0073] and Fig. 7: “The query processing module 335 includes 750 access control filters in the query plan based on the filter conditions. For example, the query processing module 335 may determine that the subset of data of dataset D1 stored in file F1 that is accessible to the user is determined using a condition C1. The query processing module 335 generates an access control filter F1 based on the conditions C1. The query processing module 335 identifies the data access operator O1 of the query plan that accesses data of the dataset D1. Assume that the data access operator O1 has an edge going from the data access operator O1 to a data processing operator O2. The query processing module 335 modifies the query plan by inserting the access control filter F1 between the data access operator O1 and the data processing operator O2. Accordingly, the output of the data access operator O1 is filtered by the access control filter F1 to generate a subset S1 of data of the dataset D1. The subset S1 represents a subset of data of the dataset D1 that is accessible to the user according to the access control policy. The subset S1 is fed as input to the data processing operator O2.” The Examiner interprets generating an access control filter F1 based on the conditions C1 and modifying the query plan by inserting the access control filter F1 between the data access operator O1 and the data processing operator O2 taught by [0073] as converting the first filter predicate string into a first query optimizer predicate that is inserted into a query optimizer tree.); injecting the first query optimizer predicate into a first query plan (see [0065]: “A node may represent an access control filter, for example, access control filter that is inserted by the query processing module 335 in the query plan to implement the access control policy.”); generating a first query result set during execution of the first query plan (see [0065] and Fig. 6: “A node may represent an access control filter, for example, access control filter that is inserted by the query processing module 335 in the query plan to implement the access control policy. The data of the dataset 640a is accessed by the data access operator 650d and provided to the access control filter 650c via the edge 625d. A subset of the data of the dataset 640a that was accessed by the data access operator 650d is provided as input to the data processing operator 650b via edge 625b after being filtered by the access control filter 650c.” The Examiner interprets the data of the dataset 640a that is accessed by the data access operator 650d as a first query result set.); and applying the first query optimizer predicate to the first query result set (see [0065] and Fig. 6: “The data of the dataset 640a is accessed by the data access operator 650d and provided to the access control filter 650c via the edge 625d. A subset of the data of the dataset 640a that was accessed by the data access operator 650d is provided as input to the data processing operator 650b via edge 625b after being filtered by the access control filter 650c.” The Examiner interprets the access control filter 650c filtering the data of the dataset 640a that was accessed by the data access operator 650d as applying the first query optimizer predicate to the first query result set.). Regarding claims 3 and 13, Li further teaches wherein applying the first query optimizer predicate to the first query result set comprises creating a second query result set which is a truncated version of the first query result set (see [0065] and Fig. 6: “The data of the dataset 640a is accessed by the data access operator 650d and provided to the access control filter 650c via the edge 625d. A subset of the data of the dataset 640a that was accessed by the data access operator 650d is provided as input to the data processing operator 650b via edge 625b after being filtered by the access control filter 650c.”). Regarding claims 10 and 19, Li further teaches detecting a second query (see [0073]: “the query processing module 335 may insert an access control filter for an output of every data access operator that processes a dataset identified in the access control policy specification such that the user has access to only a subset of the data of the dataset”); generating the query optimizer tree based on the second query (see [0073]: “the query processing module 335 may insert an access control filter for an output of every data access operator that processes a dataset identified in the access control policy specification such that the user has access to only a subset of the data of the dataset”. And see [0070] and Fig. 6: “The query processing module 335 compiles 730 the database query to generate a query plan, for example, a query plan similar to that illustrated in FIG. 6. The query plan includes a set of database operators. According to an embodiment, the query plan is a graph made up of nodes representing database operators and edges connecting the database operators.); traversing the query optimizer tree to collect any view nodes that are protected by row level security policies query (see [0073]: “the query processing module 335 may insert an access control filter for an output of every data access operator that processes a dataset identified in the access control policy specification such that the user has access to only a subset of the data of the dataset”); for each collected view node: retrieving metadata of a corresponding row level security policy for the collected view node (see [0068] and Fig. 7: “The data processing service 102 receives 710 an access control policy specification that specifies the access control policy. The access control policy specification may specify conditions associated with data access for users.” And see [0022]: “The system supports fine grained data access control, for example, access to a subset of rows, access to a subset of columns, access requiring masking of sensitive information, and so on. Accordingly, the process performing the data processing needs fine grained access control. … An example of fine-grained access control policy is that a user has access to all rows that satisfy a condition based on one or more attributes, for example, all rows having state=“California”.”); invoking a condition provider procedure to dynamically generate a filter predicate string from a permission table for a current user (see [0072] and Fig. 7: “The query processing module 335 determines 740 filter conditions based on access control policies specified in the access control policy specification. The filter conditions include instructions to determine a subset of data of a dataset, for example, a file. The subset of data represents the data of the dataset that is accessible to the user providing the database query according to the access control policy.” And see [0073]: “For example, the query processing module 335 may determine that the subset of data of dataset D1 stored in file F1 that is accessible to the user is determined using a condition C1.”); converting the filter predicate string to a query optimizer predicate (see [0073] and Fig. 7: “The query processing module 335 generates an access control filter F1 based on the conditions C1. The query processing module 335 identifies the data access operator O1 of the query plan that accesses data of the dataset D1. Assume that the data access operator O1 has an edge going from the data access operator O1 to a data processing operator O2. The query processing module 335 modifies the query plan by inserting the access control filter F1 between the data access operator O1 and the data processing operator O2. Accordingly, the output of the data access operator O1 is filtered by the access control filter F1 to generate a subset S1 of data of the dataset D1. The subset S1 represents a subset of data of the dataset D1 that is accessible to the user according to the access control policy. The subset S1 is fed as input to the data processing operator O2.”); and injecting the query optimizer predicate into the collected view node in the query optimizer tree (see [0073]: “the query processing module 335 may insert an access control filter for an output of every data access operator that processes a dataset identified in the access control policy specification such that the user has access to only a subset of the data of the dataset”). Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 4, 5, 14 and 15 are rejected under 35 U.S.C. 103 as being unpatentable over Li (US 2025/0278508) as applied to claim 3 above, and further in view of Avanes (US 2023/0022027). Regarding claims 4 and 14, Li fails to teach wherein the first row level security policy is defined by the first user. In the same field of endeavor, Avanes discloses that the first row level security policy is defined by the first user (see Abstract: “Row-level security (RLS) may provide fine-grained access control based on flexible, user-defined access policies to databases, tables, objects, and other data structures.” And see [0052]: “one user (e.g., a policy administrator) may define an RLS policy and that same user may attach that RLS policy to one or more tables.”). Both Avanes and Li teach row-level security. Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art to let the first row level security policy of Li be defined by the first user as taught by Avanes. It would have been obvious because doing so predictably achieves the commonly understood benefit of making access policies to databases and tables flexible and configurable by a user. Regarding claims 5 and 15, Li further teaches wherein the second query result set is specific to a second user that caused the first query to be generated (see [0003]: “the helper process accesses the data and by executing the data access operator, filters the data using the access control filter to determine a subset of data that the user is allowed to access according to the access control policy.”). Claims 6-8 and 16-18 are rejected under 35 U.S.C. 103 as being unpatentable over Li (US 2025/0278508) as applied to claim 1 above, and further in view of Thomson (US 5,751,949). Regarding claims 6 and 16, Li fails to teach detecting creation of a second database object to be protected by a second row level security policy different from the first row level security policy. In the same field of endeavor, Thomson discloses detecting creation of a second database object to be protected by a second row level security policy different from the first row level security policy (see col. 2, lines 52-58: “FIG. 5 is an exemplary view of software syntax for joining the security table of FIG. 4 to the first server table illustrated in FIGS. 2 and 3 to effect row security thereof.” “FIG. 6 is an exemplary second view of software syntax for joining the security table of FIG. 4 with the second server table of FIG. 3 to effect row security based on another row label.” PNG media_image1.png 621 813 media_image1.png Greyscale ). Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art to improve the method of Li by adding the step of detecting creation of a second database object to be protected by a second row level security policy different from the first row level security policy taught by Thomson. It would have been obvious because doing so predictably achieves the commonly understood benefit of ensuring the security of the second database object using a fine grained row level security policy. Regarding claims 7 and 17, Thomson further teaches wherein the second row level security policy binds the second database object and a condition provider procedure (see col. 5, lines 56-64 and Fig. 6: “A corresponding VIEW2 is required for joining the security TABLE-S with the corresponding server TABLE2 and is illustrated in FIG. 6 with an exemplary syntax. The second VIEW2 illustrates in FIG. 6 is substantially identical to the first VIEW1 illustrated in FIG. 1 except that the row label in VIEW2 is the "state" as identified by the two letter abbreviation, whereas the row label utilized in the first VIEW1 is the "Dept" indicated by its corresponding reference number.”). Regarding claims 8 and 18, Li teaches dynamically generating a first filter predicate string by invoking the condition provider procedure in response to detecting a first query targeting the first database object (emphasis added to show the difference between the reference and the claim) (see [0072] and Fig. 7: “The query processing module 335 determines 740 filter conditions based on access control policies specified in the access control policy specification. The filter conditions include instructions to determine a subset of data of a dataset, for example, a file. The subset of data represents the data of the dataset that is accessible to the user providing the database query according to the access control policy.” And see [0073]: “For example, the query processing module 335 may determine that the subset of data of dataset D1 stored in file F1 that is accessible to the user is determined using a condition C1.” The Examiner interprets a condition C1 as a first filter predicate string.). Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art to substitute the first filter predicate string, the first query and the first database object of Li with the second filter predicate string, the second query and the second database object of Thomson, respectively. It would have been obvious because doing so predictably achieves the result of ensuring the security of the second database object using a fine grained row level security policy. Claim 9 is rejected under 35 U.S.C. 103 as being unpatentable over Li (US 2025/0278508) as applied to claim 1 above, and further in view of Dutta (US 7,661,141). Regarding claim 9, Li fails to teach wherein a first row level security protection flag is saved in object metadata associated with the first database object. In the same field of endeavor, Dutta discloses wherein a first row level security protection flag is saved in object metadata associated with the first database object (see col. 16, lines 17-20: “In order to allow for row level security, the table has to first be marked as such. This can be done using the ROW_SECURITY flag in the CREATE/ALTER TABLE syntax (e.g., ALTER TABLE SET ROW_SECURITY=ON).”). Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art to improve Li by letting a first row level security protection flag be saved in object metadata associated with the first database object, as taught by Dutta. It would have been obvious because Dutta states the following: “In order to allow for row level security, the table has to first be marked as such. This can be done using the ROW_SECURITY flag” (see col. 16, lines 17-20). Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to ZHIMEI ZHU whose telephone number is (571)270-7990. The examiner can normally be reached 10am-6pm Monday-Friday. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Farid Homayounmehr can be reached at 571-272-3739. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /ZHIMEI ZHU/Examiner, Art Unit 2495
Read full office action

Prosecution Timeline

May 15, 2024
Application Filed
Nov 05, 2025
Non-Final Rejection mailed — §102, §103, §112
Feb 03, 2026
Response Filed
Mar 20, 2026
Final Rejection mailed — §102, §103, §112
Jun 22, 2026
Request for Continued Examination
Jun 28, 2026
Response after Non-Final Action
Sep 01, 2026
Non-Final Rejection mailed — §102, §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12726825
AUTOMATED SUSPECT DEVICE FILTERING ON EQUIPMENT IDENTITY REGISTERS
2y 5m to grant Granted Sep 01, 2026
Patent 12726821
SECURE RANGING SYSTEM
2y 3m to grant Granted Sep 01, 2026
Patent 12693994
METHOD FOR REDUCING FALSE-POSITIVES FOR IDENTIFICATION OF DIGITAL CONTENT
2y 10m to grant Granted Jul 28, 2026
Patent 12677150
STATEFUL MULTI-PRIVILEGED SD-WAN CONTROL CONNECTIONS
2y 8m to grant Granted Jul 07, 2026
Patent 12671674
DYNAMIC BYPASS
1y 10m to grant Granted Jun 30, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
78%
Grant Probability
99%
With Interview (+37.1%)
2y 8m (~3m remaining)
Median Time to Grant
High
PTA Risk
Based on 296 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month