DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
The response of 07/07/26 was received and considered. Claims 2-3, 13 and 18 are canceled. Claims 1, 4-12, 14-17 and 19-24 are presented for examination.
Response to Arguments
In view of Applicant’s arguments and amendments, filed 07/07/26, with respect to 35 U.S.C. 103 have been fully considered and are persuasive. The 35 U.S.C. 103 rejection of claims 1-20 has been withdrawn.
In view of the amendments and newly added claim limitations, the rejections under 35 U.S.C. 101 and 112 have been revised. The claims are directed to the abstract idea of managing access to resources. Specifically, the claims recite steps for obtaining authentication requests, extracting API metadata, converting metadata into natural language, determining commonalities between user and application data, generating queries, and provisioning access. Under the USPTO's July 2024 Subject Matter Eligibility Guidance on Artificial Intelligence, analyzing data to determine commonalities and generate queries constitutes a mental process (evaluating data and forming judgments), while authenticating users and provisioning access constitutes a method of organizing human activity (managing access to commercial/enterprise resources). The claims do not integrate the abstract idea into a practical application. While the claims recite the use of a "transformer-based model," the model is invoked broadly as a tool to automate the abstract mental process of comparing user profiles to application profiles. The post-solution activity of "dynamically provisioning a designated amount of access" is a conventional administrative outcome of authentication. Unlike eligible AI claims that recite specific, technical remedial measures (e.g., altering a device's physical operation or stopping malicious network traffic), the claimed provisioning of access merely uses a computer as a tool to execute a standard business practice, failing to improve the functioning of the computer itself. The claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception. The claims recite generic computer components (e.g., "processing device," "memory," "URL," "data structures") operating in their well-understood, routine, and conventional capacities to gather data, execute an algorithm, and output a result. The recitation of a "transformer-based model" at a high level of functional generality does not provide an inventive concept, as it merely applies a conventional machine learning architecture to the abstract idea of access control. Therefore, the claims lack an inventive concept and are patent ineligible.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1, 4-12, 14-17 and 19-24 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Independent Claims: 1 (Method), 12 (Storage Medium), and 17 (Apparatus)
Claims 1, 12, and 17: (recite identical core functional limitations adapted for their respective statutory categories).
Step 1 (Statutory Category): Claim 1 is directed to a process (method), Claim 12 to an article of manufacture (non-transitory medium), and Claim 17 to a machine (apparatus comprising a processor and memory).
Step 2A, Prong 1 (Abstract Idea): The limitations recite collecting data (extracting API metadata, storing natural language data), analyzing data (converting to natural language descriptions and determining commonalities using a transformer-based model), and using the results to output queries and provision access. Under MPEP § 2106.04(a), this falls into two categories of abstract ideas:
Mental Processes: Evaluating commonalities between two sets of natural language data to make an authentication decision is a concept that can theoretically be performed in the human mind.
Certain Methods of Organizing Human Activity: Managing access control and authenticating users are fundamental practices in managing human behavior and security.
Step 2A, Prong 2 (Integration into a Practical Application):
The claims merely implement the abstract idea of access control using generic computer components (processor, memory) and a generic AI tool ("a transformer-based model"). Simply applying AI to an abstract idea does not integrate it into a practical application.
Step 2B (Significantly More): The additional elements (accessing a URL, using an API, generating queries) represent well-understood, routine, and conventional computer activities. The use of a "transformer-based model," without reciting how the model is uniquely structured or trained for this specific task, is generally treated as generic computer functionality.
Claims 4, 14, 19: Automatically granting a portion of the request.
Claims 7, 22: Automatically granting additional privileges or revoking privileges based on activity processing.
These claims merely recite automating the abstract idea of access control, mere automation of an abstract idea using a computer does not provide an inventive concept.
Claims 5, 15, 20: Automatically processing activity data using an API subsequent to granting access.
Claims 6, 21: Modifying the data structures based on the activity data.
These claims describe conventional data gathering and record updating (updating a database based on observed activity). These claims are directed to insignificant extra-solution activity that fails to elevate the claim to patent eligibility.
Claims 8, 16: Automatically training at least a portion of the transformer-based model based on user responses to the queries.
Merely "training" a model based on feedback is considered an abstract mathematical or mental process. To be eligible, the training step usually needs to recite a specific technical implementation of how the weights or nodes are updated to improve a specific technical system, which these claims lack.
Claims 9, 23: Specifies that user data structures contain descriptions of activities, temporal info, privileges, roles, and skills.
Claims 10, 24: Specifies that application data structures contain purposes, usage patterns, privileges needed, temporal info, and role/skill requirements.
These claims define the informational content of the data structures. The mere content of information does not carry patentable weight in a § 101 analysis unless there is a functional relationship between the data and the substrate/computer, which is not clearly present here.
Claim 11: Receiving an indication of the request from the application with user identifying information.
Routine network communication. Adds no inventive concept.
Claim Rejections - 35 USC § 112
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112:
The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention.
Claims 1, 4-12, 14-17 and 19-24 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the enablement requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to enable one skilled in the art to which it pertains, or with which it is most nearly connected, to make and/or use the invention.
Claims 1, 12 and 17 requires the “transformer-based model” to perform three highly specialized, distinct tasks: 1. Convert API metadata into a natural language description. 2. Determine commonalities between user data and application data. 3. Generate user queries related to activity. The claims recite broad AI components performing complex tasks. The specification fails to teach how the AI is trained or configured to do so. Based on specification, paragraphs 0036 and 0040, the disclosure appears to merely suggest passing data into an LLM (like BERT or GPT) to “compress” or “distill” it. The specification fails to enable how the model is constrained or fine-tuned when generating security queries. Taking a generic transformer model and getting it to reliably perform security authentication, metadata translation, and dynamic query generation requires significant, undisclosed technical work (e.g. specialized training datasets, fine-tuning processes, or architectural modifications). Because the specification treats the AI as a magic “block box” the claims are rejected for requiring undue experimentation. The dependent claims are rejected based on their dependency.
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1, 4-12, 14-17 and 19-24 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Regarding claims 1, 12 and 17, the phrase "designated amount of time" is unclear for lacking distinct boundaries. Is the access amount pre-set or is it calculated on the fly? What constitutes an “amount” of access. Furthermore, the claim lacks antecedent basis or context for who or what is doing the designating.
Conclusion
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to AUBREY H WYSZYNSKI whose telephone number is (571)272-8155. The examiner can normally be reached M-F 9-5.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, ALI SHAYANFAR can be reached at 571-270-1050. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/AUBREY H WYSZYNSKI/Primary Examiner, Art Unit 2434