Prosecution Insights
Last updated: October 02, 2026
Application No. 18/763,627

RELATIONSHIP-BASED ACCESS CONTROL AUTHORIZATION MODEL QUERY GENERATION

Final Rejection §103
Filed
Jul 03, 2024
Examiner
PLECHA, THADDEUS J
Art Unit
2438
Tech Center
2400 — Computer Networks
Assignee
Okta Inc.
OA Round
2 (Final)
87%
Grant Probability
Favorable
3-4
OA Rounds
2m
Est. Remaining
97%
With Interview

Examiner Intelligence

Grants 87% — above average
87%
Career Allowance Rate
562 granted / 645 resolved
+29.1% vs TC avg
Moderate +10% lift
Without
With
+10.2%
Interview Lift
resolved cases with interview
Typical timeline
2y 5m
Avg Prosecution
14 currently pending
Career history
664
Total Applications
across all art units

Statute-Specific Performance

§101
14.9%
-25.1% vs TC avg
§103
35.1%
-4.9% vs TC avg
§102
6.6%
-33.4% vs TC avg
§112
31.6%
-8.4% vs TC avg
Black line = Tech Center average estimate • Based on career data from 645 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . The following is a Final Office action in response to communications received on June 15, 2026. Claims 1-20 are pending and addressed below. Response to Arguments Applicant’s amendments are sufficient to overcome the claim objections set forth in the previous Office Action. Applicant’s amendments are sufficient to overcome the 35 U.S.C. 112(b) rejections set forth in the previous Office Action. Applicant’s arguments regarding the 35 U.S.C. 103 rejections set forth in the previous Office Action have been fully considered but are not persuasive. Applicant argues (pp. 10-11 of Remarks): Ramamurthy's disclosed process begins with an authorization policy already expressed as a SQL predicate and creates or uses an authorization index within the SQL/database environment. Ramamurthy does not teach or suggest receiving an authorization model that indicates a set of users, objects, relations, and relationship tuples; identifying relations in that authorization model; and generating data messages based on both the set of relations and the set of relationship tuples indicated within that authorization model. Examiner respectfully disagrees. Initially, in response to applicant's arguments against the references individually, one cannot show nonobviousness by attacking references individually where the rejections are based on combinations of references. See In re Keller, 642 F.2d 413, 208 USPQ 871 (CCPA 1981); In re Merck & Co., 800 F.2d 1091, 231 USPQ 375 (Fed. Cir. 1986). Applicant concentrates the argument on Ramamurthy when a combination of Pang and Ramamurthy is relied on. The previous Office Action clearly shows that Pang discloses not only the tuples and relationships (sections 1, 2.1, 2.2 and 2.3.1) but also the use of indices (section 3). The deficiency of Pang is the specific type of data message generation to obtain the indices, not the indices themselves. The previous Office Action cited Ramamurthy for this exact teaching (paragraphs [0018], [0026], [0047] and [0049]). In summary, Pang discloses not only the tuples and relationships for authorization but also the use of indices. Pang does not disclose the specifically claimed generation of data messages, which Ramamurthy cures. Applicant’s arguments do not specifically address the combination of teachings between Pang and Ramamurthy. Applicant’s arguments are not persuasive. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1, 4-11, 13-16 and 18-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Pang et al. (“Zanzibar: Google’s Consistent, Global Authorization System” and hereinafter referred to as Pang) in view of Ramamurthy et al. (U.S. Pub. No. 2012/0330925 cited in the IDS filed on 9/8/2025 and hereinafter referred to as Ramamurthy). As to claim 1, Pang discloses a method for indexing permission relationships in a relationship-based authorization system, comprising: receiving, from a developer of the relationship-based authorization system, an authorization model for a data management system, the authorization model indicating a set of users and a set of objects (sections 1, 2.1, 2.2 and 2.3.1, Pang teaches providing namespace configurations and tuples (i.e. models) that define objects and relationships to users for authorization); identifying, via an identification system, a set of relations indicating relationships within the authorization model between the set of users and the set of objects, the set of relations corresponding to a set of relationship tuples, wherein a respective relationship tuple indicates an authorization level of a respective user for a respective object (sections 1, 2.1, 2.2 and 2.3.1, Pang teaches identifying relations from the namespace configurations/tuples indicating authorization levels for users to objects.). While Pang does generally disclose indices (see section 3 of Pang), Pang does not specifically disclose generating, via a message generation system, a set of data messages based on the set of relations and the set of relationship tuples indicated within the authorization model, the set of data messages being generated to obtain a set of indices that indicate results of the set of data messages, wherein the set of indices are for authorizing access to data within the data management system as claimed. However, Ramamurthy does disclose generating, via a message generation system, a set of data messages based on the set of relations and the set of relationship tuples indicated within the authorization model, the set of data messages being generated to obtain a set of indices that indicate results of the set of data messages, wherein the set of indices are for authorizing access to data within the data management system (paragraphs [0018], [0026], [0047] and [0049], Ramamurthy teaches generating queries from authorization definitions to obtain a set of indices to authorize access.). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention of Pang with the teachings of Ramamurthy for generating a set of data messages because this would improve efficiency. Claims 11 and 16 recite substantially similar subject matter to claim 1 and are therefore, rejected for similar reasons to claim 1 above. (Note: Claims 1 and 11 recite the additional limitations of processors and memories which are taught by Ramamurthy at, for example, paragraph [0093]). As to claim 4, the combination of teachings between Pang and Ramamurthy disclose the method of claim 1, further comprising: receiving an update to the data management system, the update comprising adding one or more objects, removing one or more objects, or both (paragraphs [0050]-[0054] and [0077], Ramamurthy teaches receiving updated for adding/removing objects); and updating, via the message generation system, the set of indices based at least in part on receiving the update to the data management system (paragraphs [0050]-[0054] and [0077], Ramamurthy teaches updating the indices.). Examiner supplies the same rationale for the combination of the references as in claim 1 above. Claims 13 and 18 recite substantially similar subject matter to claim 4 and are therefore, rejected for similar reasons to claim 4 above. As to claim 5, the combination of teachings between Pang and Ramamurthy disclose the method of claim 1, further comprising: receiving an update to the authorization model, the update comprising an addition of one or more users, one or more objects, one or more relations relating users and objects, or any combination thereof, a removal of one or more users, one or more objects, one or more relations relating users and objects, or any combination thereof, or both (paragraphs [0050]-[0054] and [0077], Ramamurthy teaches changing the authorization policy); and updating, via the message generation system, the set of data messages and the set of indices based at least in part on receiving the update to the authorization model (paragraphs [0050]-[0054] and [0077], Ramamurthy teaches updating the indices.). Examiner supplies the same rationale for the combination of the references as in claim 1 above. Claims 14 and 19 recite substantially similar subject matter to claim 5 and are therefore, rejected for similar reasons to claim 5 above. As to claim 6, the combination of teachings between Pang and Ramamurthy disclose the method of claim 1, wherein receiving the authorization model comprises: receiving, from a first tenant of a multi-tenant system, a first authorization model for the data management system, the first authorization model indicating information for authorizing users associated with the first tenant to access one or more objects within the data management system that are associated with the first tenant, wherein the data management system is accessible by one or more tenants of the multi-tenant system, and wherein the first authorization model comprises the authorization model (sections 1, 2.1 and 3.1.1, Pang teaches cloud services and storing information in separation.). Claims 15 and 20 recite substantially similar subject matter to claim 6 and are therefore, rejected for similar reasons to claim 6 above. As to claim 7, the combination of teachings between Pang and Ramamurthy disclose the method of claim 1, wherein the set of data messages comprise a set of data queries and the method further comprises: obtaining the set of indices used for authorizing access to the data within the data management system based at least in part on one or more data query operations on the set of data queries, the one or more data query operations combining the set of data queries (paragraphs [0018], [0026], [0047], [0049] and [0075], Ramamurthy teaches generating queries from authorization definitions to obtain a set of indices to authorize access where queries are joined.). Examiner supplies the same rationale for the combination of the references as in claim 1 above. As to claim 8, the combination of teachings between Pang and Ramamurthy disclose the method of claim 1, wherein a respective index of the set of indices indicates a direct relationship between the respective user and the respective object, a computed relationship between the respective user and the respective object, a nested relationship between the respective user and the respective object, a hierarchical relationship between the respective user and the respective object, or any combination thereof (sections 2.1, 2.3.1 and 3, Pang teaches indices for user-object relations, nested and hierarchical relationships.). As to claim 9, the combination of teachings between Pang and Ramamurthy disclose the method of claim 1, wherein the set of data messages are structured query language (SQL) queries (paragraph [0030], Ramamurthy teaches SQL.). Examiner supplies the same rationale for the combination of the references as in claim 1 above. As to claim 10, the combination of teachings between Pang and Ramamurthy disclose the method of claim 1, wherein the authorization model is a fine-grained authorization model that is defined via a domain-specific language (sections 2.1, 2.3.1 and 3, Pang teaches fined-grain authorization.). Claim(s) 2-3, 12 and 17 is/are rejected under 35 U.S.C. 103 as being unpatentable over Pang and Ramamurthy as applied to claims 1, 11 and 16 above, and further in view of Jain et al. (U.S. Pub. No. 2024/0256582 and hereinafter referred to as Jain). As to claim 2, the combination of teachings between Pang and Ramamurthy disclose the method of claim 1. The combination of teachings between Pang and Ramamurthy does not specifically disclose further comprising: receiving, from a client, a natural language query, the natural language query indicating a request for a user associated with the client to access one or more objects of the set of objects that are stored within the data management system based at least in part on the set of relations indicated within the authorization model; authorizing the client to obtain a subset of objects of the set of objects associated with the request that the user is authorized to access based at least in part on the set of indices generated via the message generation system, the user being authorized to access the respective object of the set of objects that is associated with the request based at least in part on at least one index of the set of indices indicating that the user has a relationship with the respective object; and transmitting, to the client, the subset of objects associated with the request of the natural language query that the user is authorized to access based at least in part on one or more relationships between the user and the subset of objects that the user are authorized to access as claimed. However, Jain does disclose further comprising: receiving, from a client, a natural language query, the natural language query indicating a request for a user associated with the client to access one or more objects of the set of objects that are stored within the data management system based at least in part on the set of relations indicated within the authorization model (paragraphs [0003], [0024] and [0055], Jain teaches receiving natural language queries from users for accessing data where access permissions are in place); authorizing the client to obtain a subset of objects of the set of objects associated with the request that the user is authorized to access based at least in part on the set of indices generated via the message generation system, the user being authorized to access the respective object of the set of objects that is associated with the request based at least in part on at least one index of the set of indices indicating that the user has a relationship with the respective object (paragraphs [0003], [0024], [0037] and [0055], Jain teaches providing access only to documents which the user has access to after receiving the query and based on permissions and an index); and transmitting, to the client, the subset of objects associated with the request of the natural language query that the user is authorized to access based at least in part on one or more relationships between the user and the subset of objects that the user are authorized to access (paragraphs [0003], [0024], [0037] and [0055], Jain teaches providing the documents the user is allowed to access to the user.). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the modified invention of Pang with the teachings of Jain for having a natural language query because this would improve user experience. Claims 12 and 17 recite substantially similar subject matter to claim 2 and are therefore, rejected for similar reasons to claim 2 above. As to claim 3, the combination of teachings between Pang, Ramamurthy and Jain disclose the method of claim 2, further comprising: transmitting, via an application programming interface associated with the set of indices used for authorizing access within the data management system, a message requesting for an indication of the subset of objects associated with the request of the natural language query (paragraphs [0037] and [0044], Jain teaches transmitting requests via API); and receiving, via the application programming interface, the subset of objects associated with the request based at least in part on the user having a relationship with each object of the subset of objects, wherein the subset of objects transmitted to the client based at least in part on receiving the subset of objects via the application programming interface (paragraphs [0037], [0044] and [0055], Jain teaches receiving the documents from the API.). Examiner supplies the same rationale for the combination of the references as in claim 2 above. Conclusion THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to THADDEUS J PLECHA whose telephone number is (571)270-7506. The examiner can normally be reached M-F 8-4:30. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Taghi Arani can be reached at 571-272-3787. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /THADDEUS J PLECHA/Examiner, Art Unit 2438
Read full office action

Prosecution Timeline

Jul 03, 2024
Application Filed
Mar 16, 2026
Non-Final Rejection mailed — §103
Jun 15, 2026
Response Filed
Aug 19, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12749079
ACCOUNT SECURITY SYSTEM
1y 10m to grant Granted Sep 29, 2026
Patent 12744811
ANOMALY DETECTION-BASED ATTENTION PURIFICATION GRAPH DEFENSE METHOD
1y 10m to grant Granted Sep 22, 2026
Patent 12737335
METHODS AND SYSTEMS FOR SECURING DATA CLONING AND SHARING OPTIONS ON DATA WAREHOUSES
3y 7m to grant Granted Sep 15, 2026
Patent 12717940
USING MACHINE-LEARNING MODELS TO DETERMINE GRADUATED LEVELS OF ACCESS TO SECURED DATA FOR REMOTE DEVICES
1y 10m to grant Granted Aug 25, 2026
Patent 12689663
CROSS-PLANE MONITORING INTENT AND POLICY INSTANTIATION FOR NETWORK ANALYTICS AND ASSURANCE
1y 10m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
87%
Grant Probability
97%
With Interview (+10.2%)
2y 5m (~2m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 645 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month