Prosecution Insights
Last updated: August 17, 2026
Application No. 18/671,212

DATA PRIVACY INCONSISTENCY DETECTION

Non-Final OA §101§103§112
Filed
May 22, 2024
Priority
May 22, 2023 — provisional 63/468,238
Examiner
SHEHNI, GHAZAL B
Art Unit
2499
Tech Center
2400 — Computer Networks
Assignee
The Regents of the University of Michigan
OA Round
3 (Non-Final)
87%
Grant Probability
Favorable
3-4
OA Rounds
2m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 87% — above average
87%
Career Allowance Rate
943 granted / 1082 resolved
+29.2% vs TC avg
Moderate +13% lift
Without
With
+12.7%
Interview Lift
resolved cases with interview
Typical timeline
2y 5m
Avg Prosecution
20 currently pending
Career history
1103
Total Applications
across all art units

Statute-Specific Performance

§101
13.9%
-26.1% vs TC avg
§103
39.9%
-0.1% vs TC avg
§102
20.1%
-19.9% vs TC avg
§112
11.2%
-28.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 1082 resolved cases

Office Action

§101 §103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . The following is a second non-final office action in response to communications received 06/12/2026. Claims 9, 11, 20 have been cancelled previously. Claim 23 has been added. Claims 1-8, 10, 12-19, 21-23 are pending and addressed below. Response to Amendment Applicant’s amendments and response to the claims are NOT sufficient to overcome the 35 USC 101 rejection. Examiner maintains the 35 USC 101 rejection as set forth in the previous office action in regards to abstract idea. The claim’s reliance on automatically triggering extension behaviors by emulating user interactions and utilizing honeypages to elicit data flows, does not illustrate a practical application of technology that goes beyond a mere abstract idea. Response to Arguments Applicant’s arguments filed 06/12/2026 have been fully considered but they are moot in view of new grounds of rejections. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claim 22-23 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Claim 22 recites in part process steps which, under the broadest reasonable interpretation, are a series of mental processes including an observation, evaluation, judgment or opinion that could be performed in the human mind or with the aid of pencil and paper. If a claim, under its broadest reasonable interpretation, covers a mental process or a mathematical concept but for the recitation of generic computer components, then it falls within the "Mental Process" grouping of abstract ideas. Therefore, claims 22-23 recite an abstract idea. This judicial exception is not integrated into a practical application. In particular, the claim recites automatically triggering extension behaviors by emulating user interactions and utilizing honeypages to elicit data flows, such that it amounts no more than mere instructions to apply the exception using a generic computer component. As described in MPEP 2106.0S(g), limitations that amount to merely adding insignificant extra-solution activity to a judicial exception cannot integrate a judicial exception into a practical application. Accordingly, this additional element does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. Therefore, claims 22-23 are directed to a judicial exception. Claim 22 does not include additional elements that are sufficient to amount to significantly more than the judicial exception. Claims 22-23 are not patent eligible. Allowable Subject Matter Claims 2-7, 13-18 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. Claim Rejections - 35 USC § 112 The following is a quotation of the first paragraph of 35 U.S.C. 112(a): (a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention. The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112: The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention. Claim 23 is rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the enablement requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to enable one skilled in the art to which it pertains, or with which it is most nearly connected, to make and/or use the invention. Claim 23 recites wherein the honeypages are utilized to isolated network traffic initiated by the extension. The specification recites ExtPrivA emulated user interactions on both real-world web pages and a honeypage to elicit the extension’s behavior that generated data traffic (par. 24). It is not cleared how honeypages can utilized to isolated network traffic initiated by the extension. The applicant’s disclosure does not recite such concept and Examiner request further clarification in order to do properly examine claim 23. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1, 8, 10, 12, 19, 21-23 are rejected under 35 U.S.C. 103 as being unpatentable over NPL: Duc et al (“Detection of Inconsistencies in Privacy Practices of Browser Extensions”); Publication date May 01, 2023 in view of NPL: Wentao et al (“ExtensionGuard: Towards runtime browser extension information leakage detection”). As per claim 1, Duc discloses a method of detecting inconsistencies between privacy policy disclosures and practices (we propose ExtPrivA that automatically detects the inconsistencies between browser extensions’ data collection and their privacy disclosures…see abstract), wherein the method is performed by at least one processor executing computer instructions stored on non-transitory, computer-readable memory, and wherein the method comprises the steps of: generating dashboard disclosure privacy statements based on dashboard disclosure data for an extension (see fig.1 and section I, part c); generating privacy policy statements based on privacy policy data for the extension (it extracts privacy statements from the disclosed privacy practices, see section III); determining privacy contradiction data between the dashboard disclosure privacy statements and the privacy policy statements (the system detects contradictory privacy statements and inconsistencies between the data flows and the privacy statements by using a formal model, see section VI); generating extension use data for the extension based on data collected during operation of the extension, wherein generating the extension use data includes extracting data types from one or more extension network requests so as to generate extension use data items (section V, part B; #1a; section VI, part D, #2), and wherein each of the one or more extension network requests includes a receiver and a data object that is sent as a part of the extension network request to the receiver (section VI, part C: Flow-Relevant Privacy Statement…); and determining inconsistencies between extension data practice and an extension privacy policy based on the dashboard disclosure privacy statements, the privacy policy statements, and the extension use data (detection of inconsistencies…section VI…performing in-depth analysis of How to Policy inconsistencies of the extensions…section VII). Duc does not explicitly disclose the method is performed by at least one processor. However Wentao discloses the method is performed by at least one processor (ExtensionGuard is built upon Chromium 42 (64 bit) and test platform is a 2.3 GHz Intel Core i7 machine with 16GB memory running Mac OS v10.10.3…section V, part C). Therefore one ordinary skill in the art would have found it obvious before the effective filling date of the claimed invention to use Wentao in Duc for including the above limitations because one ordinary skill in the art would recognize it is well known in the art to have a system comprising a processor and memory. As per claim 12, Duc discloses an automated data collection-disclosure consistency determination system (ExtPrivA, an end-to-end system that extracts the stated privacy practices and performs a fine-grained analysis of data flows to detect any inconsistencies between the actual data practices and the privacy disclosures of web browser extension, section I), comprising: at least one processor; and memory storing computer instructions; wherein the automated data collection-disclosure consistency determination system is configured so that, when the computer instructions are executed by the at least one processor, the automated data collection-disclosure consistency determination system: generates dashboard disclosure privacy statements based on dashboard disclosure data for an extension (see fig.1 and section I, part c); generates privacy policy statements based on privacy policy data for the extension (it extracts privacy statements from the disclosed privacy practices, see section III); determines privacy contradiction data between the dashboard disclosure privacy statements and the privacy policy statements (the system detects contradictory privacy statements and inconsistencies between the data flows and the privacy statements by using a formal model, see section VI); generates extension use data for the extension based on data collected during operation of the extension, wherein generating the extension use data includes extracting data types from one or more extension network requests so as to generate extension use data items (section V, part B; #1a; section VI, part D, #2), and wherein each of the one or more extension network requests includes a receiver and a data object that is sent as a part of the extension network request to the receiver (section VI, part C: Flow-Relevant Privacy Statement…); and determines inconsistencies between extension data practice and an extension privacy policy based on the dashboard disclosure privacy statements, the privacy policy statements, and the extension use data (detection of inconsistencies…section VI…performing in-depth analysis of How to Policy inconsistencies of the extensions…section VII). Duc does not explicitly disclose determination system comprising: at least one processor and memory. However Wentao discloses determination system comprising: at least one processor and memory (ExtensionGuard is built upon Chromium 42 (64 bit) and test platform is a 2.3 GHz Intel Core i7 machine with 16GB memory running Mac OS v10.10.3…section V, part C). Therefore one ordinary skill in the art would have found it obvious before the effective filling date of the claimed invention to use Wentao in Duc for including the above limitations because one ordinary skill in the art would recognize it is well known in the art to have a system comprising a processor and memory. As per claim 22, Duc discloses a method of detecting inconsistencies between privacy policy disclosures and practices, comprising the steps of: generating dashboard disclosure privacy statements based on dashboard disclosure data for an extension (see fig.1 and section I, part c); generating privacy policy statements based on privacy policy data for the extension (it extracts privacy statements from the disclosed privacy practices, see section III); determining privacy contradiction data between the dashboard disclosure privacy statements and the privacy policy statements the system detects contradictory privacy statements and inconsistencies between the data flows and the privacy statements by using a formal model, see section VI); generating extension use data for the extension based on data collected during operation of the extension, wherein the generation includes automatically triggering extension behaviors by emulating user interactions and utilizing honeypages to elicit data flows (…ExtPrivA triggered an extension’s functionality and inferred data types from its data traffic to extract its actual data-collection practices. ExtPrivA emulated user interactions on both real-world web pages and a honeypage to elicit the extensions’ behavior that generated data traffic from the extensions to external servers, section I, part b) TC2)…section IX cites trigger malicious behaviors, specially honeypages…); and determining inconsistencies between extension data practice and an extension privacy policy based on the dashboard disclosure privacy statements, the privacy policy statements, and the extension use data (detection of inconsistencies…section VI…performing in-depth analysis of How to Policy inconsistencies of the extensions…section VII). Duc does not explicitly disclose generating extension use data for the extension based on data collected during operation of the extension. However Wentao discloses generating extension use data for the extension based on data collected during operation of the extension (detect the leakage of sensitive information in the data flows during the extension execution, section I, II). Therefore one ordinary skill in the art would have found it obvious before the effective filling date of the claimed invention to use Wentao in Duc for including the above limitations because one ordinary skill in the art would recognize it would further accommodate security-savvy users' needs to protect their sensitive data, thus the ease of taking inputs from educated users is a critical component to the success of ExtensionGuard, section IV, part D. As per claims 8, 19, the combination of Duc and Wentao discloses wherein generating the extension use data for the extension based on data collected during operation of the extension includes performing a network request initiator inspection process where an initiator of a network request is inspected to determine whether the network request was initiated from the extension or from a website (Duc: section IV, part B). As per claim 10, the combination of Duc and Wentao discloses wherein the extension is a browser extension for a web browser (Duc: section I). As per claim 21, the combination of Duc and Wentao discloses wherein generating the extension use data includes extracting the data types from the one or more extension network requests so as to separate the one or more extension network requests from network requests of web browsers (Duc: section V, part B, #1a). As per claim 23, the combination of Duc and Wentao discloses wherein the honeypages are utilized to isolated network traffic initiated by the extension (Duc: section I, part b) TC2). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure (see PTO-form 892). The following Patents and Papers are cited to further show the state of the art at the time of Applicant’s invention with respect to detecting inconsistencies in data privacy policies. Prakash et al (Pub. No. US 2021/0105302); “Systems and Methods for Determining User Intent at a Website and Responding to the User Intent”; -Teaches the browser extension, which for example can comprise computer program instructions provided by the counterfeit URL detection system and executable by a processor of the user device, can receive a URL requested by the browser application…before the browser application retrieves and displays content associated with the webpage identified by the URL, the browser extension determines whether the URL is counterfeit…par. 50. Any inquiry concerning this communication or earlier communications from the examiner should be directed to GHAZAL B SHEHNI whose telephone number is (571)270-7479. The examiner can normally be reached Mon-Fri 9am-5pm PCT. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Philip Chea can be reached at 5712723951. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /GHAZAL B SHEHNI/Primary Examiner, Art Unit 2499
Read full office action

Prosecution Timeline

May 22, 2024
Application Filed
Aug 26, 2025
Non-Final Rejection mailed — §101, §103, §112
Feb 24, 2026
Response Filed
Mar 17, 2026
Final Rejection mailed — §101, §103, §112
Jun 12, 2026
Response after Non-Final Action
Jun 30, 2026
Non-Final Rejection mailed — §101, §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12705405
Read-Only Memory (ROM) Security
2y 10m to grant Granted Aug 11, 2026
Patent 12706737
METHOD FOR ROLE-BASED DATA TRANSMISSION USING PHYSICALLY UNCLONABLE FUNCTION (PUF)-BASED KEYS
2y 0m to grant Granted Aug 11, 2026
Patent 12699773
METHOD AND APPARATUS FOR CLONE SEARCH
2y 10m to grant Granted Aug 04, 2026
Patent 12694157
TERMINAL CHIP AND MEASUREMENT METHOD THEREOF
3y 0m to grant Granted Jul 28, 2026
Patent 12694093
FLEXIBLE AND REUSABLE RULE EVALUATION FOR SECURE EXECUTION OF EXTERNAL COMMANDS
2y 4m to grant Granted Jul 28, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
87%
Grant Probability
99%
With Interview (+12.7%)
2y 5m (~2m remaining)
Median Time to Grant
High
PTA Risk
Based on 1082 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month