Prosecution Insights
Last updated: August 06, 2026
Application No. 18/680,361

USER ACCOUNT OBJECT MANAGEMENT

Non-Final OA §103§112
Filed
May 31, 2024
Priority
Dec 02, 2021 — GB 2117391.9 +1 more
Examiner
YUAN, PETER LI
Art Unit
Tech Center
Assignee
Immersive Labs Holdings Limited
OA Round
1 (Non-Final)
Grant Probability
Favorable
1-2
OA Rounds

Examiner Intelligence

Grants only 0% of cases
0%
Career Allowance Rate
0 granted / 0 resolved
-60.0% vs TC avg
Minimal +0% lift
Without
With
+0.0%
Interview Lift
resolved cases with interview
Typical timeline
Avg Prosecution
12 currently pending
Career history
17
Total Applications
across all art units

Statute-Specific Performance

§101
27.9%
-12.1% vs TC avg
§103
48.5%
+8.5% vs TC avg
§102
2.9%
-37.1% vs TC avg
§112
11.8%
-28.2% vs TC avg
Black line = Tech Center average estimate • Based on career data from 0 resolved cases

Office Action

§103 §112
DETAILED ACTION The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . The Office Action is in response to claims filed 05/31/2024. Claims 1-20 are pending. Claim Objections Claims 1-20 are objected to because the relationship between activating a user account object and allocating a user account object is unclear. In independent claims 1, 11, and 20, a user account objected is “activated” from the database. Further in the claims, the user account object is “deallocated” despite the claims not reciting that the user account object is “allocated.” Additionally, in claim 3 the user account objects are now “activated” and “allocated.” Claim 13 distinguishes that the intermediary server is configured to “activate” a plurality of user account objects and “allocated” the plurality of user account objects to the user device. However, it is unclear if “activated” and “allocated” are equivalent or not in the scope in each of the claim sets. Appropriate clarification and/or correction is required. Claim 8 and 18 are objected to because claim 8 recites “the allocated user account object” while claim 18 recites “the configured user account object.” The relationship between these differing scopes is unclear. Appropriate clarification and/or correction is required. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. The term “isolated network segment” in claims 1-20 is a relative term which renders the claim indefinite. The term “isolated network segment” is not defined by the claim, the specification does not provide a standard for ascertaining the requisite degree, and one of ordinary skill in the art would not be reasonably apprised of the scope of the invention. It is unclear what the network segment is “isolated” from. The term “remote server” in claims 11-19 is a relative term which renders the claim indefinite. The term “remote server” is not defined by the claim, the specification does not provide a standard for ascertaining the requisite degree, and one of ordinary skill in the art would not be reasonably apprised of the scope of the invention. It is unclear what the server is “remote” from. Claim 8 recites the limitation "the allocated user account object" in lines 1-2 of claim 8. There is insufficient antecedent basis for this limitation in the claim. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-2, 4-9, 11-12, 14-18, and 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Brandwine Pat. No. US 20170366551 A1 (hereafter Brandwine) in view of Poghosyan et al. Pat. No. US 11770382 B1 (hereafter Poghosyan). With regard to claim 1, Brandwine teaches a method for managing user account objects within a digital environment via a framework, the framework comprising (¶ [0057] states “FIG. 3 illustrates an example process 300 for making a security decision using an authorization function and ephemeral compute instance that can be utilized in accordance with various embodiments.” ¶ [0014] states “When a request to provision a resource is received to the interface layer 108, information for the request can be directed to a resource manager 110 or other such system, service, or component configured to manage user accounts and information, resource provisioning and usage, and other such aspects.” ¶ [0046] states “The ability to utilize virtual instances and containers as discussed above further allows these decisions to be based at least in part upon “arbitrary” third party functionality, or functionality that is defined by a third party entity within a framework of the provider environment.” Examiner’s Note: the provider environment is digital environment and makes up the framework): an application programming interface, API, the API enabling a user to send and receive commands to the digital environment (¶ [0017] states “An interface layer 108 in at least one embodiment includes a scalable set of customer-facing servers that can provide the various APIs and return the appropriate responses based on the API specifications.” ¶ [0025] states “The frontend 220 can process all the requests to execute user code on the virtual compute system 210. In one embodiment, the frontend 220 serves as a front door to all the other services provided by the virtual compute system 210.” ¶ [0020] states “The virtual compute system 210 may provide the user computing devices 202 with one or more user interfaces, command-line interfaces (CLI), application programming interfaces (API), and/or other programmatic interfaces for generating and uploading user codes, invoking the user codes (e.g., submitting a request to execute the user codes on the virtual compute system 210).” See FIG. 2A); and at least one isolated network segment configured to perform one or more tasks, the at least one isolated network segment comprising a plurality of dynamically instantiable resources (¶ [0019] states “The virtual compute system 210 in the example situation 200 of FIG. 2A can maintain a pool 240A of virtual machine instances that each have one or more respective software components (e.g., operating systems, language runtimes, libraries, etc.) loaded thereon” and “The virtual machine instance manager can create and configure virtual machine instances according to a predetermined set of configurations”); the method comprising the steps of: receiving a request, via the API, from the user to perform a task of the one or more tasks (¶ [0057] states “In this example, a request to access a resource is received 302. As mentioned, this can include various types of access to various types of resources, such as query access to a database, establishing of a connection to a data store, causing code to be executed on a compute resource, and the like.” Examiner’s Note: a user wants to utilize a portion of the resources to perform a task, such as execute code); receiving at the at least one isolated network segment, at least one command from the user, to enable the requested task to be completed within the at least one isolated network segment, wherein the at least one command is sent by the user using the configured user account object (¶ [0028] states “A user request may specify one or more third-party libraries (including native libraries) to be used along with the user code.” ¶ [0039] states “Alternatively, the worker manager 240 may further configure an existing container on the instance assigned to the user, and assign the container to the request. For example, the worker manager 240 may determine that the existing container may be used to execute the user code if a particular library demanded by the current user request is loaded thereon. In such a case, the worker manager 240 may load the particular library and the user code onto the container and use the container to execute the user code.” Examiner’s Note: the user request includes a command to specify what libraries are used with the user code. The container (in the VM) receives the library which enables the requested task to completed within the isolated network segment); Brandwine does not explicitly teach a database of user account objects and activating a user account object with the user. However, in an analogous art, Poghosyan teaches a method for managing user account objects within a digital environment via a framework, the framework comprising (Col. 6 Lines 27-29 states “Once identified, the user then selects the particular access profile for check out, invoking the particular access profile to start a task in the particular cloud application.” Examiner’s Note: the access profile is the user account object): a database comprising a plurality of user account objects, each user account object being associated with a pool of user account objects (Col. 5 Lines 12-14 states “After creation and configuration, the access profiles are stored in a profile repository for just-in-time access by the users.” Col. 7 Lines 4-6 states “The profile service 130, in turn, accesses the profile repository 160 to get the access profiles available for the user (at 215).” Examiner’s Note: the available access profiles are the pool of user account objects). activating a user account object from the database, by associating the user account object with the user and the at least one isolated network segment (Col. 7 Lines 16-20 states “The just-in-time privileged access profile check out and check in process for a user to obtain privileged access to a cloud environment 200 then continues to a step at which the user checks out a particular access profile to perform the tasks via the particular cloud application (at 230).” Examiner’s Note: checking out the access profile is associating the user account object with the user. The cloud environment is analogous to the isolated network segment. The access profile, user, and cloud environment that the user has access to using the access profile are associated with each other); configuring the user account object for performing the requested task (Col. 1 Lines 48-53 states “an admin user connects to the just-in-time access system to configure one or more privileged access profiles. In some embodiments, the admin user configures each privileged access profile based on one of access requirements and recommendations made by the access intelligence system.”); receiving at the at least one isolated network segment, at least one command from the user, to enable the requested task to be completed within the at least one isolated network segment, wherein the at least one command is sent by the user using the configured user account object (Col. 7 Lines 28-31 states “The profile service 130, in turn, transmits the temporary credentials back to the user (at 245) for the user to access the particular cloud application.” Col. 7 Lines 32-41 states “After the user has obtained access permissions for the particular cloud application, the just-in-time privileged access profile check out and check in process for a user to obtain privileged access to a cloud environment 200 continues to the next step at which the user interacts with the particular cloud application (at 250) to perform the tasks as needed in connection with the heterogeneous cloud environment 170. For examples, the tasks may include creating resources or managing permissions for user and/or resources, among other tasks.” Examiner’s Note: the user uses the temporary credentials to send commands to the cloud environment); and deallocating the user account object upon detection of a completion indication from the at least one isolated network segment indicating the completion of the requested task, wherein deallocation comprises dissociating the user account object with the user and associating the user account object with the pool of user account objects (Col. 7 Lines 43-50 states “When the user has completed the tasks via the particular cloud application, the user may then perform check in of the particular access profile (260). Check in of the particular access profile is received by the profile service 130 which revokes access to the user account and removes any temporary user account (at 265) for using the particular cloud application at the heterogeneous cloud environment 170.” Examiner’s Note: when the user checks in the access profile, the user is no longer associated with the access profile, or user account object. Checking in the access profile makes it available, which is associating the user account object with the pool of user account objects). It would have been obvious to a person having ordinary skill in the art prior to the effective filing date to combine the check-out and check-in of access profiles of Poghosyan with the API for sending requests to be executed in a cloud environment of Brandwine. As a result, the user must check out an access profile before they can access the cloud environment (virtual machines and containers) of Brandwine. A person having ordinary skill in the art would have been motivated to make this combination for the purpose of improving security of the cloud system (Col. 4 Lines 42-45 states “Embodiments of the dynamic privileged access governance system and processes described in this specification differ from and improve upon currently existing security solutions and other existing security options”). Additionally, Poghosyan teaches “the dynamic privileged access governance system and processes are cloud-native and adapts to the dynamic nature of the cloud systems. By contrast, the existing security solutions and other existing security options are too rigid and do not scale for public cloud needs” (Col. 4 Lines 49-53). With regard to claim 2, Brandwine and Poghosyan teach the method according to claim 1. Poghosyan additionally teaches wherein the step of configuring the user account object comprises provisioning one or more attributes of the user account object for performing the requested task (Col. 1 Lines 48-53 states “an admin user connects to the just-in-time access system to configure one or more privileged access profiles. In some embodiments, the admin user configures each privileged access profile based on one of access requirements and recommendations made by the access intelligence system.” Col. 5 Lines 8-12 states “Access profiles are created based on a combination of the type of access, the characteristics or attributes of users (e.g., job function or job role) for whom the access profiles are intended for use, and the frequency that a user uses the access granted within the access profile.” Col. 8 Lines 20-21 states “The admin user creates a new profile with users and permissions.” Examiner’s Note: access profiles are user account objects that have attributes such as access requirements. Access requirements are used for performing the requested task). With regard to claim 4, Brandwine and Poghosyan teach the method according to claim 1. Poghosyan additionally teaches further comprising selecting one or more pre-provisioned user account objects from the database, the one or more pre-provisioned user account objects comprising at least one required attribute for performing the requested task (Col. 5 Lines 8-14 states “Access profiles are created based on a combination of the type of access, the characteristics or attributes of users (e.g., job function or job role) for whom the access profiles are intended for use, and the frequency that a user uses the access granted within the access profile. After creation and configuration, the access profiles are stored in a profile repository for just-in-time access by the users.” Examiner’s Note: the access profiles are configured and stored in the profile repository before the user checks them out, so they are pre-provisioned). With regard to claim 5, Brandwine and Poghosyan teach the method according to claim 2. Poghosyan additionally teaches wherein the attributes comprise at least a security level configured to limit access of the user to at least one of the dynamically instantiable resources of the at least one isolated network segment based on the requested task (Col. 1 Lines 48-53 states “an admin user connects to the just-in-time access system to configure one or more privileged access profiles. In some embodiments, the admin user configures each privileged access profile based on one of access requirements and recommendations made by the access intelligence system.” Examiner’s Note: the access requirements are a security level that limits access of the user). With regard to claim 6, Brandwine and Poghosyan teach the method according to claim 1. Brandwine additionally teaches further comprising the step of instantiating the at least one isolated network segment by configuring the plurality of dynamically instantiable resources for performing the requested task (¶ [0029] states “the virtual compute system 210 may modify the behavior (e.g., logging facilities) of the container in which the user code is executed, and cause the output data to be provided back to the user.” ¶ [0037] states “the worker manager 240 may, based on information specified in the request to execute user code, create a new container.” ¶ [0039] states “Alternatively, the worker manager 240 may further configure an existing container on the instance assigned to the user, and assign the container to the request. For example, the worker manager 240 may determine that the existing container may be used to execute the user code if a particular library demanded by the current user request is loaded thereon. In such a case, the worker manager 240 may load the particular library and the user code onto the container and use the container to execute the user code”). With regard to claim 7, Brandwine and Poghosyan teach the method according to claim 1. Brandwine additionally teaches wherein the plurality of dynamically instantiable resources of the at least one isolated network segment are pre-configured for performing the one or more tasks (¶ [0034] states “The warming pool manager 230 may pre-configure the virtual machine instances in the warming pool 230A, such that each virtual machine instance is configured to satisfy at least one of the operating conditions that may be requested or specified by the user request to execute program code on the virtual compute system 210. In one embodiment, the operating conditions may include program languages in which the potential user codes may be written”). With regard to claim 8, Brandwine and Poghosyan teach the method according to claim 1. Brandwine additionally teaches wherein the user, and the allocated user account object, are associated with a given organization (¶ [0002] states “Organizations operate computer networks that interconnect a number of computing devices to support operations or to provide services to third parties.” ¶ [0012] states “In this example a user is able to utilize a client device 102 to submit requests across at least one network 104 to a resource provider environment 106.”). Poghosyan additionally teaches wherein the user, and the allocated user account object, are associated with a given organization (Col. 1 Lines 40-44 state “the just-in-time access system comprises an authentication module for user and admin user authentication and a profile module comprising a profile access manager, a profile configuration module, and a profile repository.” Col. 1 Lines 44-47 states “a user connects to the just-in-time access system to check out a profile providing privileged access to a cloud environment and check in the profile once the user is finished accessing the cloud environment.” Examiner’s Note: it is understood that the user and the access profiles are related to an organization that protects access to a cloud environment). It would have been obvious to a person having ordinary skill in the art prior to the effective filing date to combine the user and access profiles of Poghosyan with the user and organization of Brandwine. As a result, the user of the check in and check out system and the access profiles are associated with an organization that uses the cloud environment. A person having ordinary skill in the art would have been motivated to make this combination for the purpose of improving operational security of an organization (Col. 4 Lines 42-45 states “Embodiments of the dynamic privileged access governance system and processes described in this specification differ from and improve upon currently existing security solutions and other existing security options”). With regard to claim 9, Brandwine and Poghosyan teach the method according to claim 1. Brandwine additionally teaches wherein the at least one command received by the at least one isolated network segment is received via an intermediary component (¶ [0038] states “Once a request has been successfully processed by the frontend 220, the worker manager 240 can locate capacity to service the request to execute user code on the virtual compute system 210” and “the worker manager 240 may assign the container to the request and cause the user code to be executed in the container.” Examiner’s Note: the code, or command, is received at the container by the worker manager. The worker manager is the intermediary component). With regard to claim 11, Brandwine teaches a system for managing user account objects within a digital environment, the system comprising (¶ [0014] states “When a request to provision a resource is received to the interface layer 108, information for the request can be directed to a resource manager 110 or other such system, service, or component configured to manage user accounts and information, resource provisioning and usage, and other such aspects”): a user device for accessing the digital environment (¶ [0020] states “various user computing devices 202 are shown in communication with the virtual compute system 210.”); an intermediary server comprising an application programming interface, API, the API enabling a user to send and receive commands via the user device (¶ [0017] states “An interface layer 108 in at least one embodiment includes a scalable set of customer-facing servers that can provide the various APIs and return the appropriate responses based on the API specifications.” ¶ [0025] states “The frontend 220 can process all the requests to execute user code on the virtual compute system 210. In one embodiment, the frontend 220 serves as a front door to all the other services provided by the virtual compute system 210.” ¶ [0020] states “The virtual compute system 210 may provide the user computing devices 202 with one or more user interfaces, command-line interfaces (CLI), application programming interfaces (API), and/or other programmatic interfaces for generating and uploading user codes, invoking the user codes (e.g., submitting a request to execute the user codes on the virtual compute system 210).” ¶ [0022] states “Similarly, each of the frontend 220, the warming pool manager 230, and the worker manager 240 can be implemented across multiple physical computing devices or on a single physical computing device, among other such options.”); and a remote server for providing at least one isolated network segment configured to perform one or more tasks, the at least one isolated network segment comprising a plurality of dynamically instantiable resources (¶ [0022] states “Virtual machine instances (hereinafter “instances”)” and “The illustration of the various components within the virtual compute system 210 is logical in nature and one or more of the components can be implemented by a single computing device or multiple computing devices. For example, the instances 252, 254, 256, 258 can be implemented on one or more physical computing devices in different various geographic regions.” Examiner’s Note: the virtual machines can be implemented on computing devices that are different, or remote, to other servers); wherein the intermediary server is configured to: receive a request through the API from the user device to perform a task of the one or more tasks (¶ [0020] states “The virtual compute system 210 may provide the user computing devices 202 with one or more user interfaces, command-line interfaces (CLI), application programming interfaces (API), and/or other programmatic interfaces for generating and uploading user codes, invoking the user codes (e.g., submitting a request to execute the user codes on the virtual compute system 210), scheduling event-based jobs or timed jobs, tracking the user codes, and/or viewing other logging or monitoring information related to their requests and/or user codes.” ¶ [0025] states “The frontend 220 can process all the requests to execute user code on the virtual compute system 210.” ¶ [0057] states “In this example, a request to access a resource is received 302. As mentioned, this can include various types of access to various types of resources, such as query access to a database, establishing of a connection to a data store, causing code to be executed on a compute resource, and the like.” Examiner’s Note: a user wants to utilize a portion of the resources to perform a task, such as execute code. A computer representing the front end and the worker manager is considered the “intermediary server”); receive at the at least one isolated network segment, at least one command from the user device, to enable the requested task to be completed within the at least one isolated network segment, wherein the at least one command is sent using the configured user account object (¶ [0028] states “A user request may specify one or more third-party libraries (including native libraries) to be used along with the user code.” ¶ [0039] states “Alternatively, the worker manager 240 may further configure an existing container on the instance assigned to the user, and assign the container to the request. For example, the worker manager 240 may determine that the existing container may be used to execute the user code if a particular library demanded by the current user request is loaded thereon. In such a case, the worker manager 240 may load the particular library and the user code onto the container and use the container to execute the user code.” Examiner’s Note: the user request includes a command to specify what libraries are used with the user code. The container (in the VM) receives the library which enables the requested task to completed within the isolated network segment); Brandwine does not explicitly teach a database of user account objects and activating a user account object with the user. However, in an analogous art, Poghosyan teaches a system for managing user account objects within a digital environment, the system comprising (Col. 6 Lines 27-29 states “Once identified, the user then selects the particular access profile for check out, invoking the particular access profile to start a task in the particular cloud application.” Examiner’s Note: the access profile is the user account object): storage for storing a database comprising a plurality of user account objects, each user account object being associated with a pool of user account objects (Col. 5 Lines 12-14 states “After creation and configuration, the access profiles are stored in a profile repository for just-in-time access by the users.” Col. 7 Lines 4-6 states “The profile service 130, in turn, accesses the profile repository 160 to get the access profiles available for the user (at 215).” Examiner’s Note: the available access profiles are the pool of user account objects); activate a user account object from the database, by associating the user account object with the user and the at least one isolated network segment (Col. 7 Lines 16-20 states “The just-in-time privileged access profile check out and check in process for a user to obtain privileged access to a cloud environment 200 then continues to a step at which the user checks out a particular access profile to perform the tasks via the particular cloud application (at 230).” Examiner’s Note: checking out the access profile is associating the user account object with the user. The cloud environment is analogous to the isolated network segment. The access profile, user, and cloud environment that the user has access to using the access profile are associated with each other); configure the user account object for performing the requested task (Col. 1 Lines 48-53 states “an admin user connects to the just-in-time access system to configure one or more privileged access profiles. In some embodiments, the admin user configures each privileged access profile based on one of access requirements and recommendations made by the access intelligence system.”); receive at the at least one isolated network segment, at least one command from the user device, to enable the requested task to be completed within the at least one isolated network segment, wherein the at least one command is sent using the configured user account object (Col. 7 Lines 28-31 states “The profile service 130, in turn, transmits the temporary credentials back to the user (at 245) for the user to access the particular cloud application.” Col. 7 Lines 32-41 states “After the user has obtained access permissions for the particular cloud application, the just-in-time privileged access profile check out and check in process for a user to obtain privileged access to a cloud environment 200 continues to the next step at which the user interacts with the particular cloud application (at 250) to perform the tasks as needed in connection with the heterogeneous cloud environment 170. For examples, the tasks may include creating resources or managing permissions for user and/or resources, among other tasks.” Examiner’s Note: the user uses the temporary credentials to send commands to the cloud environment); and deallocate the user account object upon detection of a completion indication from the at least one isolated network segment indicating the completion of the requested task, wherein deallocation comprises dissociating the user account object from the user device and associating the user account object with the pool of user account objects (Col. 7 Lines 43-50 states “When the user has completed the tasks via the particular cloud application, the user may then perform check in of the particular access profile (260). Check in of the particular access profile is received by the profile service 130 which revokes access to the user account and removes any temporary user account (at 265) for using the particular cloud application at the heterogeneous cloud environment 170.” Examiner’s Note: when the user checks in the access profile, the user is no longer associated with the access profile, or user account object. Checking in the access profile makes it available, which is associating the user account object with the pool of user account objects). It would have been obvious to a person having ordinary skill in the art prior to the effective filing date to combine the check-out and check-in of access profiles of Poghosyan with the API for sending requests to be executed in a cloud environment of Brandwine. As a result, the user must check out an access profile before they can access the cloud environment (virtual machines and containers) of Brandwine. A person having ordinary skill in the art would have been motivated to make this combination for the purpose of improving security of the cloud system (Col. 4 Lines 42-45 states “Embodiments of the dynamic privileged access governance system and processes described in this specification differ from and improve upon currently existing security solutions and other existing security options”). Additionally, Poghosyan teaches “the dynamic privileged access governance system and processes are cloud-native and adapts to the dynamic nature of the cloud systems. By contrast, the existing security solutions and other existing security options are too rigid and do not scale for public cloud needs” (Col. 4 Lines 49-53). With regard to claim 12, Brandwine and Poghosyan teach the system according to claim 11. Poghosyan additionally teaches wherein the intermediary server is configured to configure the user account object by provisioning one or more attributes of the user account object for performing the requested task (Col. 1 Lines 48-53 states “an admin user connects to the just-in-time access system to configure one or more privileged access profiles. In some embodiments, the admin user configures each privileged access profile based on one of access requirements and recommendations made by the access intelligence system.” Col. 5 Lines 8-12 states “Access profiles are created based on a combination of the type of access, the characteristics or attributes of users (e.g., job function or job role) for whom the access profiles are intended for use, and the frequency that a user uses the access granted within the access profile.” Col. 8 Lines 20-21 states “The admin user creates a new profile with users and permissions.” Examiner’s Note: access profiles are user account objects that have attributes such as access requirements. Access requirements are used for performing the requested task). With regard to claim 14, Brandwine and Poghosyan teach the system according to claim 11. Poghosyan additionally teaches wherein the intermediary server is configured to select one or more pre-provisioned user account objects from the database, the one or more pre-provisioned user account objects comprising at least one required attribute for performing the requested task (Col. 5 Lines 8-14 states “Access profiles are created based on a combination of the type of access, the characteristics or attributes of users (e.g., job function or job role) for whom the access profiles are intended for use, and the frequency that a user uses the access granted within the access profile. After creation and configuration, the access profiles are stored in a profile repository for just-in-time access by the users.” Examiner’s Note: the access profiles are configured and stored in the profile repository before the user checks them out, so they are pre-provisioned). With regard to claim 15, Brandwine and Poghosyan teach the system according to claim 12. Poghosyan additionally teaches wherein the attributes comprise at least a security level configured to limit access of the user to at least one of the dynamically instantiable resources of the at least one isolated network segment based on the requested task (Col. 1 Lines 48-53 states “an admin user connects to the just-in-time access system to configure one or more privileged access profiles. In some embodiments, the admin user configures each privileged access profile based on one of access requirements and recommendations made by the access intelligence system.” Examiner’s Note: the access requirements are a security level that limits access of the user). With regard to claim 16, Brandwine and Poghosyan teach the system according to claim 11. Brandwine additionally teaches wherein the intermediary server is configured to instruct the instantiation of the at least one isolated network segment by configuring the plurality of dynamically instantiable resources for performing the requested task (¶ [0029] states “the virtual compute system 210 may modify the behavior (e.g., logging facilities) of the container in which the user code is executed, and cause the output data to be provided back to the user.” ¶ [0037] states “the worker manager 240 may, based on information specified in the request to execute user code, create a new container.” ¶ [0039] states “Alternatively, the worker manager 240 may further configure an existing container on the instance assigned to the user, and assign the container to the request. For example, the worker manager 240 may determine that the existing container may be used to execute the user code if a particular library demanded by the current user request is loaded thereon. In such a case, the worker manager 240 may load the particular library and the user code onto the container and use the container to execute the user code”). With regard to claim 17, Brandwine and Poghosyan teach the system according to claim 11. Brandwine additionally teaches wherein the plurality of dynamically instantiable resources of the at least one isolated network segment are pre-configured for performing the one or more tasks (¶ [0034] states “The warming pool manager 230 may pre-configure the virtual machine instances in the warming pool 230A, such that each virtual machine instance is configured to satisfy at least one of the operating conditions that may be requested or specified by the user request to execute program code on the virtual compute system 210. In one embodiment, the operating conditions may include program languages in which the potential user codes may be written”). With regard to claim 18, Brandwine and Poghosyan teach the system according to claim 11. Brandwine additionally teaches wherein the user, and the configured user account object, are associated with a given organization (¶ [0002] states “Organizations operate computer networks that interconnect a number of computing devices to support operations or to provide services to third parties.” ¶ [0012] states “In this example a user is able to utilize a client device 102 to submit requests across at least one network 104 to a resource provider environment 106.”). Poghosyan additionally teaches wherein the user, and the configured user account object, are associated with a given organization (Col. 1 Lines 40-44 state “the just-in-time access system comprises an authentication module for user and admin user authentication and a profile module comprising a profile access manager, a profile configuration module, and a profile repository.” Col. 1 Lines 44-47 states “a user connects to the just-in-time access system to check out a profile providing privileged access to a cloud environment and check in the profile once the user is finished accessing the cloud environment.” Examiner’s Note: it is understood that the user and the access profiles are related to an organization that protects access to a cloud environment). It would have been obvious to a person having ordinary skill in the art prior to the effective filing date to combine the user and access profiles of Poghosyan with the user and organization of Brandwine. As a result, the user of the check in and check out system and the access profiles are associated with an organization that uses the cloud environment. A person having ordinary skill in the art would have been motivated to make this combination for the purpose of improving operational security of an organization (Col. 4 Lines 42-45 states “Embodiments of the dynamic privileged access governance system and processes described in this specification differ from and improve upon currently existing security solutions and other existing security options”). With regard to claim 20, Brandwine teaches a non-transitory computer-readable storage medium comprising a set of computer-readable instructions stored thereon, which when executed by at least one processor are arranged to manage user account objects within a digital environment via a framework, the framework comprising (¶ [0075] states “Storage media and other non-transitory computer readable media for containing code, or portions of code, can include any appropriate media known or used in the art.” ¶ [0064] states “the device includes at least one processor 402 for executing instructions that can be stored in a memory device or element 404.” ¶ [0014] states “When a request to provision a resource is received to the interface layer 108, information for the request can be directed to a resource manager 110 or other such system, service, or component configured to manage user accounts and information, resource provisioning and usage, and other such aspects.” ¶ [0046] states “The ability to utilize virtual instances and containers as discussed above further allows these decisions to be based at least in part upon “arbitrary” third party functionality, or functionality that is defined by a third party entity within a framework of the provider environment.” Examiner’s Note: the provider environment is digital environment and makes up the framework): an application programming interface, API, the API enabling a user to send and receive commands to the digital environment (¶ [0017] states “An interface layer 108 in at least one embodiment includes a scalable set of customer-facing servers that can provide the various APIs and return the appropriate responses based on the API specifications.” ¶ [0025] states “The frontend 220 can process all the requests to execute user code on the virtual compute system 210. In one embodiment, the frontend 220 serves as a front door to all the other services provided by the virtual compute system 210.” ¶ [0020] states “The virtual compute system 210 may provide the user computing devices 202 with one or more user interfaces, command-line interfaces (CLI), application programming interfaces (API), and/or other programmatic interfaces for generating and uploading user codes, invoking the user codes (e.g., submitting a request to execute the user codes on the virtual compute system 210).” See FIG. 2A); and at least one isolated network segment configured to perform one or more tasks, the at least one isolated network segment comprising a plurality of dynamically instantiable resources (¶ [0019] states “The virtual compute system 210 in the example situation 200 of FIG. 2A can maintain a pool 240A of virtual machine instances that each have one or more respective software components (e.g., operating systems, language runtimes, libraries, etc.) loaded thereon” and “The virtual machine instance manager can create and configure virtual machine instances according to a predetermined set of configurations”); wherein managing the user account objects in the digital environment comprises the steps of: receiving a request, via the API, from the user to perform a task of the one or more tasks (¶ [0057] states “In this example, a request to access a resource is received 302. As mentioned, this can include various types of access to various types of resources, such as query access to a database, establishing of a connection to a data store, causing code to be executed on a compute resource, and the like.” Examiner’s Note: a user wants to utilize a portion of the resources to perform a task, such as execute code); receiving at the at least one isolated network segment, at least one command from the user, to enable the requested task to be completed within the at least one isolated network segment, wherein the at least one command is sent by the user using the configured user account object (¶ [0028] states “A user request may specify one or more third-party libraries (including native libraries) to be used along with the user code.” ¶ [0039] states “Alternatively, the worker manager 240 may further configure an existing container on the instance assigned to the user, and assign the container to the request. For example, the worker manager 240 may determine that the existing container may be used to execute the user code if a particular library demanded by the current user request is loaded thereon. In such a case, the worker manager 240 may load the particular library and the user code onto the container and use the container to execute the user code.” Examiner’s Note: the user request includes a command to specify what libraries are used with the user code. The container (in the VM) receives the library which enables the requested task to completed within the isolated network segment); Brandwine does not explicitly teach a database of user account objects and activating a user account object with the user. However, in an analogous art, Poghosyan teaches a non-transitory computer-readable storage medium comprising a set of computer-readable instructions stored thereon, which when executed by at least one processor are arranged to manage user account objects within a digital environment via a framework, the framework comprising (Col. 6 Lines 27-29 states “Once identified, the user then selects the particular access profile for check out, invoking the particular access profile to start a task in the particular cloud application.” Examiner’s Note: the access profile is the user account object): a database comprising a plurality of user account objects, each user account object being associated with a pool of user account objects (Col. 5 Lines 12-14 states “After creation and configuration, the access profiles are stored in a profile repository for just-in-time access by the users.” Col. 7 Lines 4-6 states “The profile service 130, in turn, accesses the profile repository 160 to get the access profiles available for the user (at 215).” Examiner’s Note: the available access profiles are the pool of user account objects). activating a user account object from the database, by associating the user account object with the user and the at least one isolated network segment (Col. 7 Lines 16-20 states “The just-in-time privileged access profile check out and check in process for a user to obtain privileged access to a cloud environment 200 then continues to a step at which the user checks out a particular access profile to perform the tasks via the particular cloud application (at 230).” Examiner’s Note: checking out the access profile is associating the user account object with the user. The cloud environment is analogous to the isolated network segment. The access profile, user, and cloud environment that the user has access to using the access profile are associated with each other); configuring the user account object for performing the requested task (Col. 1 Lines 48-53 states “an admin user connects to the just-in-time access system to configure one or more privileged access profiles. In some embodiments, the admin user configures each privileged access profile based on one of access requirements and recommendations made by the access intelligence system.”); receiving at the at least one isolated network segment, at least one command from the user, to enable the requested task to be completed within the at least one isolated network segment, wherein the at least one command is sent by the user using the configured user account object (Col. 7 Lines 28-31 states “The profile service 130, in turn, transmits the temporary credentials back to the user (at 245) for the user to access the particular cloud application.” Col. 7 Lines 32-41 states “After the user has obtained access permissions for the particular cloud application, the just-in-time privileged access profile check out and check in process for a user to obtain privileged access to a cloud environment 200 continues to the next step at which the user interacts with the particular cloud application (at 250) to perform the tasks as needed in connection with the heterogeneous cloud environment 170. For examples, the tasks may include creating resources or managing permissions for user and/or resources, among other tasks.” Examiner’s Note: the user uses the temporary credentials to send commands to the cloud environment); and deallocating the user account object upon detection of a completion indication from the at least one isolated network segment indicating the completion of the requested task, wherein deallocation comprises dissociating the user account object with the user and associating the user account object with the pool of user account objects (Col. 7 Lines 43-50 states “When the user has completed the tasks via the particular cloud application, the user may then perform check in of the particular access profile (260). Check in of the particular access profile is received by the profile service 130 which revokes access to the user account and removes any temporary user account (at 265) for using the particular cloud application at the heterogeneous cloud environment 170.” Examiner’s Note: when the user checks in the access profile, the user is no longer associated with the access profile, or user account object. Checking in the access profile makes it available, which is associating the user account object with the pool of user account objects). It would have been obvious to a person having ordinary skill in the art prior to the effective filing date to combine the check-out and check-in of access profiles of Poghosyan with the API for sending requests to be executed in a cloud environment of Brandwine. As a result, the user must check out an access profile before they can access the cloud environment (virtual machines and containers) of Brandwine. A person having ordinary skill in the art would have been motivated to make this combination for the purpose of improving security of the cloud system (Col. 4 Lines 42-45 states “Embodiments of the dynamic privileged access governance system and processes described in this specification differ from and improve upon currently existing security solutions and other existing security options”). Additionally, Poghosyan teaches “the dynamic privileged access governance system and processes are cloud-native and adapts to the dynamic nature of the cloud systems. By contrast, the existing security solutions and other existing security options are too rigid and do not scale for public cloud needs” (Col. 4 Lines 49-53). Claim(s) 3 and 13 is/are rejected under 35 U.S.C. 103 as being unpatentable over Brandwine in view of Poghosyan and further in view of Bijon et al. Pat. No. US 20220021746 A1 (hereafter Bijon). With regard to claim 3, Brandwine and Poghosyan teach the method according to claim 1. Poghosyan additionally teaches wherein a plurality of user account objects are activated and allocated to the user and, wherein the step of configuring the plurality of user account objects comprises provisioning each of the plurality of user account objects with differing attributes for performing the requested task (Col. 7 Lines 18-20 states “the user checks out a particular access profile to perform the tasks via the particular cloud application (at 230).” Col. 7 Lines 25-31 states “The heterogeneous cloud environment 170 then returns, to the profile service 130, temporary credentials for the user to access the particular cloud application (at 240). The profile service 130, in turn, transmits the temporary credentials back to the user (at 245) for the user to access the particular cloud application.” Col. 5 Lines 8-12 states “Access profiles are created based on a combination of the type of access, the characteristics or attributes of users (e.g., job function or job role) for whom the access profiles are intended for use, and the frequency that a user uses the access granted within the access profile.” Examiner’s Note: when a user checks out an access profile, the access profile has been allocated to the user. The plurality of access profiles is configured with differing attributes). Brandwine and Poghosyan do not explicitly teach a plurality of user account objects are activated and allocated to the user. However, in an analogous art, Bijon teaches wherein a plurality of user account objects are activated and allocated to the user and, wherein the step of configuring the plurality of user account objects comprises provisioning each of the plurality of user account objects with differing attributes for performing the requested task (¶ [0057] states “The global identity (GI 1) 502 may be associated with multiple selected accounts and is able to access those accounts without further authentication. Once a global identity is authenticated, it may access different accounts associated with that global identity and perform tasks in the context of those accounts without providing further authentication for those different accounts.”). It would have been obvious to a person having ordinary skill in the art prior to the effective filing date to combine the global identity associated with multiple accounts of Bijon with the check in of access profiles of Poghosyan and the cloud environment of Brandwine. As a result, after the user of Poghosyan authenticates, the user may check out multiple access profiles similar to how the user of Bijon has multiple accounts to access multiple cloud resources (Bijon ¶ [0058] states “GI 1 502 may be mapped to different accounts across different deployments, cloud providers, and/or regions”). Multiple access profiles are now activated and allocated to the user. A person having ordinary skill in the art would have been motivated to make this combination for the purpose of improving the user experience and efficiency of using multiple accounts simultaneously for managing multiple cloud environments (¶ [0004] states “an operation may include performing a first task using a first account and then performing a second task using a second account and so on. Thus, a user would have to log into the first account to perform the first task, log off, and then log into the second account to perform the second task and so on, leading to an inefficient process”). With regard to claim 13, Brandwine and Poghosyan teach the system according to claim 11. Poghosyan additionally teaches wherein the intermediary server is configured to activate a plurality of user account objects and allocate the plurality of user account objects to the user device and, wherein the intermediary server is configured to configure the user account objects by provisioning each of the plurality of user account objects with differing attributes for performing the requested task (Col. 7 Lines 18-20 states “the user checks out a particular access profile to perform the tasks via the particular cloud application (at 230).” Col. 7 Lines 25-31 states “The heterogeneous cloud environment 170 then returns, to the profile service 130, temporary credentials for the user to access the particular cloud application (at 240). The profile service 130, in turn, transmits the temporary credentials back to the user (at 245) for the user to access the particular cloud application.” Col. 5 Lines 8-12 states “Access profiles are created based on a combination of the type of access, the characteristics or attributes of users (e.g., job function or job role) for whom the access profiles are intended for use, and the frequency that a user uses the access granted within the access profile.” Examiner’s Note: when a user checks out an access profile, the access profile has been allocated to the user. It is understood the user is using a device to interact with just-in-time privileged access profile check out and check in process. Therefore, the access profile has been allocated to the user device. The plurality of access profiles is configured with differing attributes). Brandwine and Poghosyan do not explicitly teach a plurality of user account objects are activated and allocated to the user. However, in an analogous art, Bijon teaches wherein the intermediary server is configured to activate a plurality of user account objects and allocate the plurality of user account objects to the user device and, wherein the intermediary server is configured to configure the user account objects by provisioning each of the plurality of user account objects with differing attributes for performing the requested task (¶ [0057] states “The global identity (GI 1) 502 may be associated with multiple selected accounts and is able to access those accounts without further authentication. Once a global identity is authenticated, it may access different accounts associated with that global identity and perform tasks in the context of those accounts without providing further authentication for those different accounts.”) It would have been obvious to a person having ordinary skill in the art prior to the effective filing date to combine the global identity associated with multiple accounts of Bijon with the check in of access profiles of Poghosyan and the cloud environment of Brandwine. As a result, after the user of Poghosyan authenticates, the user may check out multiple access profiles similar to how the user of Bijon has multiple accounts to access multiple cloud resources (Bijon ¶ [0058] states “GI 1 502 may be mapped to different accounts across different deployments, cloud providers, and/or regions”). Multiple access profiles are now activated and allocated to the user. A person having ordinary skill in the art would have been motivated to make this combination for the purpose of improving the user experience and efficiency of using multiple accounts simultaneously for managing multiple cloud environments (¶ [0004] states “an operation may include performing a first task using a first account and then performing a second task using a second account and so on. Thus, a user would have to log into the first account to perform the first task, log off, and then log into the second account to perform the second task and so on, leading to an inefficient process”). Claim(s) 10 and 19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Brandwine in view of Poghosyan and further in view of Arllen et al. Pat. No. US 9876703 B1 (hereafter Arllen). With regard to claim 10, Brandwine and Poghosyan teach the method according to claim 1. Brandwine and Poghosyan do not explicitly teach resetting the user account object. However, in an analogous art, Arllen teaches wherein the step of deallocating the user account object further comprises resetting the user account object (Col. 5 Lines 55-59 states “After using an account for testing purposes, the account may be returned to an original condition by the testing module 130 (if any changes were made to the account during testing) and placed back in the account pool in the accounts data store 135.”). It would have been obvious to a person having ordinary skill in the art prior to the effective filing date to combine the resetting of an account of Arllen with the cloud environment of Brandwine and the access profiles of Poghosyan. As a result, if the access profile of Poghosyan is modified while the user has it checked out, then the access profile is reset according to the teachings of Arllen when it is checked in. A person having ordinary skill in the art would have been motivated to make this combination for the purpose of ensuring that the state of user profiles when checked out is the same as when it is checked in. This ensures consistency between tests using the same account or consistency between checking out the same access profiles multiple times. Additionally, by testing accounts, problems in the cloud computing environment can be detected and rectified which improves customer experience (Col. 15 Lines 56-59 states “the performance levels expected by customers may be met because problems may be identified in advance and may be rectified. Also, any expanded or reduced features or services, such as beta programs, early access and the like can be verified to work as intended”). With regard to claim 19, Brandwine and Poghosyan teach the system according to claim 11. Brandwine and Poghosyan do not explicitly teach resetting the user account object. However, in an analogous art, Arllen teaches wherein the intermediary server is configured to deallocate the user account object by resetting the user account object (Col. 5 Lines 55-59 states “After using an account for testing purposes, the account may be returned to an original condition by the testing module 130 (if any changes were made to the account during testing) and placed back in the account pool in the accounts data store 135.”). It would have been obvious to a person having ordinary skill in the art prior to the effective filing date to combine the resetting of an account of Arllen with the cloud environment of Brandwine and the access profiles of Poghosyan. As a result, if the access profile of Poghosyan is modified while the user has it checked out, then the access profile is reset according to the teachings of Arllen when it is checked in. A person having ordinary skill in the art would have been motivated to make this combination for the purpose of ensuring that the state of user profiles when checked out is the same as when it is checked in. This ensures consistency between tests using the same account or consistency between checking out the same access profiles multiple times. Additionally, by testing accounts, problems in the cloud computing environment can be detected and rectified which improves customer experience (Col. 15 Lines 56-59 states “the performance levels expected by customers may be met because problems may be identified in advance and may be rectified. Also, any expanded or reduced features or services, such as beta programs, early access and the like can be verified to work as intended”). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. US 20110265147 A1 teaches CLOUD-BASED BILLING, CREDENTIAL, AND DATA SHARING MANAGEMENT SYSTEM US 20210168133 A1 teaches IDENTITY PROVIDER THAT SUPPORTS MULTIPLE PERSONAS FOR A SINGLE USER US 20180034823 A1 teaches MANAGEMENT OF SERVICE ACCOUNTS US 20150135272 A1 teaches IDENTITY POOL BRIDGING FOR MANAGED DIRECTORY SERVICES US 10911564 B1 teaches Cloud Service Account Management Method US 10715458 B1 teaches Organization Level Identity Management Any inquiry concerning this communication or earlier communications from the examiner should be directed to PETER L YUAN whose telephone number is (571)272-5737. The examiner can normally be reached Mon-Fri 7:30am-5pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Bradley Teets can be reached at 571-272-3338. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /PETER LI YUAN/Examiner, Art Unit 2197 /JOANNE G MACASIANO/Examiner, Art Unit 2197
Read full office action

Prosecution Timeline

May 31, 2024
Application Filed
Jul 27, 2026
Non-Final Rejection mailed — §103, §112 (current)

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
Grant Probability
Low
PTA Risk
Based on 0 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month