Prosecution Insights
Last updated: October 02, 2026
Application No. 18/744,791

INFORMATION PROCESSING APPARATUS, INFORMATION PROCESSING METHOD, AND COMPUTER-READABLE RECORDING MEDIUM

Non-Final OA §103§112
Filed
Jun 17, 2024
Priority
Jun 30, 2023 — JP 2023-108605
Examiner
RAHIM, MONJUR
Art Unit
2436
Tech Center
2400 — Computer Networks
Assignee
NEC Corporation
OA Round
2 (Non-Final)
85%
Grant Probability
Favorable
2-3
OA Rounds
7m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 85% — above average
85%
Career Allowance Rate
762 granted / 901 resolved
+26.6% vs TC avg
Strong +16% interview lift
Without
With
+16.4%
Interview Lift
resolved cases with interview
Typical timeline
2y 11m
Avg Prosecution
36 currently pending
Career history
924
Total Applications
across all art units

Statute-Specific Performance

§101
15.1%
-24.9% vs TC avg
§103
56.8%
+16.8% vs TC avg
§102
7.2%
-32.8% vs TC avg
§112
4.5%
-35.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 901 resolved cases

Office Action

§103 §112
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION 1. This action is in response to the amendment and argument field on 31 December 2025. 2. Claims 1, 3-4, and 7-8 have been amended. 3 Claims 2, 5, and 6 have been cancelled. 4. Claims 9-18 are newly added. 5. Claims 1, 3-4 and 7-18 remain Pending and Rejected. Claim Rejections - 35 USC § 112 6. Claim rejection of 35 USC § 101 remain rejected because claim amendment did not overcome the rejection. Responses to the Argument 7. The applicant’s arguments filed on 31 December 2025 are moot in view of new ground of rejection rendered. Claim Rejections - 35 USC § 103 8. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1, 7 and 8 are rejected under 35 U.S.C §103 as being unpatentable over Batchelor et al. (US Patent No. 12375494), hereinafter Batchelor and in view of Mardikar et al. (US Publication No. 20150237074), hereinafter Mardikar. Regarding claim 1: one or more memories storing instructions (Batchelor, col 18, lines 29-30). and one or more processors configured to execute the instructions to: estimate a plurality access attributes representing attributes for an access request for an information asset, transmitted to the information asset from a terminal device (Batchelor, FIG.15, col 2, lines 40-63). calculate a likelihood value for each of the plurality of access attribute (Batchelor, FIG.2, col 5, lines 9-13). derive an attribute risk for each combination of the plurality of access attribute and calculate an access risk for the access request, using the attribute risk and the likelihood values (Batchelor, FIG.12A, col 6, lines 1-8, col 5, lines 57-65). derive an attribute need for each combination of the plurality of access attribute and calculate a access request using the attribute needs and likelihood the value (Batchelor, col 11, lines 16-29, col 8, lines 18-26). and determine whether to permit the access request for the information asset, based on the access risk and access needs (Batchelor, col 16, lines 39-44, FIG.9). Batchelor does not explicitly suggest, wherein the plurality of access attributes includes at least information representation a user of the terminal device, information representing a role of the user and information representation a label of the information asset; however, in a same field endeavor Mardikar discloses this limitation (Mardikar ¶11, ¶16). It would have been obvious to one of ordinary skill in the art at the time the invention was filed to include the method of access control of Batchelor with the role based access method disclosed in Mardikar security may be managed at a level that corresponds closely to the organization's structure. Each user is assigned one or more roles, and each role is assigned one or more privileges that are permitted to users in that role, stated by Mardikar at para.7. Regarding claim 7: estimating a plurality access attributes representing attributes for an access request for an information asset, transmitted to the information asset from a terminal device (Batchelor, FIG.15, col 2, lines 40-63). calculating a likelihood value for each of the plurality of access attribute (Batchelor, FIG.2, col 5, lines 9-13). deriving an attribute risk for each combination of the plurality of access attribute and calculate an access risk for the access request, using the attribute risk and the likelihood values (Batchelor, FIG.12A, col 6, lines 1-8, col 5, lines 57-65). deriving an attribute need for each combination of the plurality of access attribute and calculate a access request using the attribute needs and likelihood the value (Batchelor, col 11, lines 16-29, col 8, lines 18-26). and determining whether to permit the access request for the information asset, based on the access risk (Batchelor, col 16, lines 39-44, FIG.9). Batchelor does not explicitly suggest, wherein the plurality of access attributes includes at least information representation a user of the terminal device, information representing a role of the user and information representation a label of the information asset; however, in a same field endeavor Mardikar discloses this limitation (Mardikar ¶11, ¶16). It would have been obvious to one of ordinary skill in the art at the time the invention was filed to include the method of access control of Batchelor with the role based access method disclosed in Mardikar security may be managed at a level that corresponds closely to the organization's structure. Each user is assigned one or more roles, and each role is assigned one or more privileges that are permitted to users in that role, stated by Mardikar at para.7. Regarding claim 8: estimating a plurality access attributes representing attributes for an access request for an information asset, transmitted to the information asset from a terminal device (Batchelor, FIG.15, col 2, lines 40-63). calculating a likelihood value for each of the plurality of access attribute (Batchelor, FIG.2, col 5, lines 9-13). deriving an attribute risk for each combination of the plurality of access attribute and calculate an access risk for the access request, using the attribute risk and the likelihood values (Batchelor, FIG.12A, col 6, lines 1-8, col 5, lines 57-65). deriving an attribute need for each combination of the plurality of access attribute and calculate a access request using the attribute needs and likelihood the value (Batchelor, col 11, lines 16-29, col 8, lines 18-26). and determining whether to permit the access request for the information asset, based on the access risk (Batchelor, col 16, lines 39-44, FIG.9). Batchelor does not explicitly suggest, wherein the plurality of access attributes includes at least information representation a user of the terminal device, information representing a role of the user and information representation a label of the information asset; however, in a same field endeavor Mardikar discloses this limitation (Mardikar ¶11, ¶16). It would have been obvious to one of ordinary skill in the art at the time the invention was filed to include the method of access control of Batchelor with the role based access method disclosed in Mardikar security may be managed at a level that corresponds closely to the organization's structure. Each user is assigned one or more roles, and each role is assigned one or more privileges that are permitted to users in that role, stated by Mardikar at para.7. Claim Rejections - 35 USC § 103 9. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 3-4 are rejected under 35 U.S.C §103 as being unpatentable over Batchelor and in view of Chari et al. (US Publication No. 20140196104), hereinafter Chari. Regarding claim 3: Batchelor in view of Mardikar does not explicitly suggest, wherein the one or more processors further: input each combination of the access attributes into an attribute risk derivation model and outputs the attribute risk; however, in a same field of endeavor Chari discloses this limitation (Chari, ¶70). It would have been obvious to one of ordinary skill in the art at the time the invention was filed to include the method of access control of Batchelor in view of Mardikar with the risk model generation disclosed in Chari to secure sensitive and valuable resources of an enterprise or organization., stated by Chari at para.5. Regarding claim 4: Batchelor in view of Mardikar does not explicitly suggest, wherein the one or more processors further: input each combination of the access attributes and the likelihoods for each combination of the access attributes into an access risk derivation model, and output the access risk for the access request, however, in a same field of endeavor Chari discloses this limitation (Chari, ¶60-61). Same motivation for combining the respective features of Batchelor in view of Mardikar and Chari applies herein, as discussed in the rejection of claim 3. 10. Claims 9-18 are rejected under 35 U.S.C §103 as being unpatentable over Batchelor with Mardikar and in view of Shingh et al. (US patent No. 12537836), hereinafter Shingh. Regarding claim 9: Batchelor in view of Mardikar does not explicitly teach wherein the information representing the user of the terminal device and the information representing the role of the user are estimated based on past access logs; however, in a same field of endeavor Shingh discloses this limitation (Shingh, abstract). It would have been obvious to one of ordinary skill in the art at the time the invention was filed to include the method of access control of Batchelor in view of Mardikar with the use of historical data and role based access control disclosed in Shingh to have advanced analysis of user and entity behaviors, querying and long-range analytics for historical analysis, other support for incident investigation and management, reporting (for compliance requirements, for example), and other functionality. 15 as services and made available through APis. In such an example, rather than using their own data to build and train models for common activities, organizations may access pre-trained models that accomplish specific tasks. Whether an organization needs natural language processing ('NLP'), stated by Shingh at col 54, lines 10-15). Regarding claim 10: Batchelor in view of Mardikar does not explicitly teach wherein the information representing the label of the information asset is estimated by executing natural language processing; however, in a same field of endeavor Shingh discloses this limitation (Shingh, col 66, lines 15-19). Same motivation for combining the respective features of Batchelor in view of Mardikar and Shingh applies herein, as discussed in the rejection of claim 3. Regarding claim 11: Batchelor in view of Mardikar does not explicitly teach wherein the plurality of access attributes includes a security status of a host, and wherein the security status of the host is estimated based on determining whether the host has vulnerabilities and a number or severity of the vulnerabilities; however, in a same field of endeavor Shingh discloses this limitation (Shingh, col 61, lines 45-49). Same motivation for combining the respective features of Batchelor in view of Mardikar and Shingh applies herein, as discussed in the rejection of claim 3. Regarding claim 12: Batchelor in view of Mardikar does not explicitly teach wherein the plurality of access attributes includes a security status of communication channels, and wherein the security status of communication channels is estimated based on protocols and cipher suites that are used for access; however, in a same field of endeavor Shingh discloses this limitation (Shingh, col 61, lines 1-11). Same motivation for combining the respective features of Batchelor in view of Mardikar and Shingh applies herein, as discussed in the rejection of claim 3. Regarding claim 13: Batchelor in view of Mardikar does not explicitly teach wherein the plurality of access attributes includes a type of device that transmitted the access request, and wherein an estimation of the type of device that transmitted the access request is based on determining whether a communication content of other communication whose source IP address matches the access request includes information matching a signature defined in advance; however, in a same field of endeavor Shingh discloses this limitation (Shingh, col 82, lines 49-63). Same motivation for combining the respective features of Batchelor in view of Mardikar and Shingh applies herein, as discussed in the rejection of claim 3. Regarding claim 14: Batchelor in view of Mardikar does not explicitly teach wherein the information representing the user of the terminal device and the information representing the role of the user are estimated based on past access logs; however, in a same field of endeavor Shingh discloses this limitation (Shingh, col 94, lines 40-49). Same motivation for combining the respective features of Batchelor in view of Mardikar and Shingh applies herein, as discussed in the rejection of claim 3. Regarding claim 15: Batchelor in view of Mardikar does not explicitly teach wherein the information representing the label of the information asset is estimated by executing natural language processing; however, in a same field of endeavor Shingh discloses this limitation (Shingh, col 66, lines 10-19). Same motivation for combining the respective features of Batchelor in view of Mardikar and Shingh applies herein, as discussed in the rejection of claim 3. Regarding claim 16: Batchelor in view of Mardikar does not explicitly teach wherein the plurality of access attributes includes a security status of a host, and wherein the security status of the host is estimated based on determining whether the host has vulnerabilities and a number or severity of the vulnerabilities; however, in a same field of endeavor Shingh discloses this limitation (Shingh, col 52, lines 47-59). Same motivation for combining the respective features of Batchelor in view of Mardikar and Shingh applies herein, as discussed in the rejection of claim 3. Regarding claim 17: Batchelor in view of Mardikar does not explicitly teach wherein the plurality of access attributes includes a security status of communication channels, and wherein the security status of communication channels is estimated based on protocols and cipher suites that are used for access; however, in a same field of endeavor Shingh discloses this limitation (Shingh, col 83, lines 50-58). Same motivation for combining the respective features of Batchelor in view of Mardikar and Shingh applies herein, as discussed in the rejection of claim 3. Regarding claim 18: [Batchelor in view of Mardikar does not explicitly teach wherein the plurality of access attributes includes a type of device that transmitted the access request, and wherein an estimation of the type of device that transmitted the access request is based on determining whether a communication content of other communication whose source IP address matches the access request includes information matching a signature defined in advance; however, in a same field of endeavor Shingh discloses this limitation (Shingh, col 82, lines 49-65, col 47, lines 37-50). Same motivation for combining the respective features of Batchelor in view of Mardikar and Shingh applies herein, as discussed in the rejection of claim 3. Conclusion 11. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action. The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure (See form “PTO-892 Notice of reference cited). Any inquiry concerning this communication or earlier communications from the examiner should be directed to MONJUR RAHIM whose telephone number is (571)270-3890. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Shewye Gelagay can be reached on 571-272-4219. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /Monjur Rahim/ Patent Examiner United States Patent and Trademark Office Art Unit: 2436; Phone: 571.270.3890 E-mail: monjur.rahim@uspto.gov Fax: 571.270.4890
Read full office action

Prosecution Timeline

Jun 17, 2024
Application Filed
Oct 01, 2025
Non-Final Rejection mailed — §103, §112
Dec 31, 2025
Response Filed
May 04, 2026
Final Rejection mailed — §103, §112
Jul 29, 2026
Response after Non-Final Action

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750662
DIFFERENTIATING OWN ACCESSORIES FROM THOSE OF OTHERS
2y 5m to grant Granted Sep 29, 2026
Patent 12744682
QUANTUM TIMESTAMPING
1y 12m to grant Granted Sep 22, 2026
Patent 12743517
STEGANOGRAPHIC MODIFICATION DETECTION AND MITIGATION FOR ENHANCED ENTERPRISE SECURITY
1y 12m to grant Granted Sep 22, 2026
Patent 12739628
METHOD FOR SLICE-SPECIFIC AUTHENTICATION AND AUTHORIZATION STATUS TRANSMISSION
3y 7m to grant Granted Sep 15, 2026
Patent 12712889
DETECTING EXECUTION OF A WEB SHELL
3y 2m to grant Granted Aug 18, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

2-3
Expected OA Rounds
85%
Grant Probability
99%
With Interview (+16.4%)
2y 11m (~7m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 901 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month