Prosecution Insights
Last updated: August 14, 2026
Application No. 18/787,080

AUTOMATED AUTHENTICATION AND AUTHORIZATION IN A COMMUNICATION SYSTEM

Non-Final OA §101§102§112
Filed
Jul 29, 2024
Priority
Jan 22, 2020 — provisional 62/964,624 +3 more
Examiner
WYSZYNSKI, AUBREY H
Art Unit
2434
Tech Center
2400 — Computer Networks
Assignee
Valimail Inc.
OA Round
1 (Non-Final)
90%
Grant Probability
Favorable
1-2
OA Rounds
7m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 90% — above average
90%
Career Allowance Rate
640 granted / 715 resolved
+31.5% vs TC avg
Moderate +12% lift
Without
With
+12.5%
Interview Lift
resolved cases with interview
Typical timeline
2y 8m
Avg Prosecution
17 currently pending
Career history
745
Total Applications
across all art units

Statute-Specific Performance

§101
13.6%
-26.4% vs TC avg
§103
37.2%
-2.8% vs TC avg
§102
23.2%
-16.8% vs TC avg
§112
8.2%
-31.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 715 resolved cases

Office Action

§101 §102 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . The preliminary amendment of 11/12/24 was received and considered. Claims 1-20 are presented for examination. Double Patenting Claims 1-20 of this application are patentably distinct from the claims of Application No. 17/328,759 and 17/155,091. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-8, 10-17 and 19-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter. As per claims 1, 10, and 19: Step 1: Statutory Categories: Claim 1 is a system (machine). Claim 10 is a computer-implemented method (process). Claim 19 is a non-transitory computer-readable medium (manufacture). Step 2A, Prong 1: Judicial Exception? The claims are directed towards receiving rules governing authentication from an organization, receiving an authentication query regarding a message, determining a response based on the identifier and the rules, and transmitting the response. These limitations are directed towards a mental process (evaluating an identifier against a set of rules to determine an outcome) and/or a method of organizing human activity (managing organizational rules and verifying identity/authorization). The claims effectively describe the concept of a gatekeeper checking credentials against a policy before allowing access or verifying origin. Step 2A, Prong 2: The independent claims merely use generic computer components, i.e. “one or more processors”, “a third party-server”, “a message recipient device” as a tool to execute the rule-based authentication. There is no recitation of how the network’s efficiency is improved or how a novel hardware architecture is utilized. The claims simply automate the abstract idea of rule-checking using standard network communication. Therefore, the abstract idea is not integrated in a practical application. Step 2B: Significantly More: The recited hardware elements (servers, processors and recipient devices) are invoked at a high level of generality to perform their basic, routine, and conventional functions, i.e. receiving data, processing data and transmitting data. Standard network communication and data routing do not prove the requisite “inventive concept” to transform the abstract idea into a patent-eligible invention. As per claims 2-5, 11-14 and 20: These claims add steps for determining a “likely role”, transmitting “recommendations” for “policy modification”, generating a “guided workflow” and searching “open-source intelligence”. This limitations introduce further abstract concepts, specifically methods of organizing human activity (managing policies, guiding user workflows) and metal processes (evaluating open-source intelligence to determine a role). The do not offer a technical solution to a technical problem. As per claims 6-7 and 15-16: These claims add that authentication is done through a “DNS record” or by using a “public key” to authenticated a “digital signature”. While these are technical network elements, they are highly conventional. Merely applying well-known cryptographic techniques (public keys/digital signatures) or using standard network directories (DNS) for their intended purposes does not amount to “significantly more”. As per claims 8 and 17: These claims recite that the query includes “contextual metadata” and the rules specific “contextual conditions”. This merely broadens the scope of the data being analyzed by the abstract rule engine. Gathering an analyzing additional data points is does not amount to “significantly more”. Claim Objections Claims 9 and 18 objected to because of the following informalities: “metada” is misspelled and assumed to be “metadata”. Appropriate correction is required. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 2, 11, 20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Regarding claims 2, 11, 20, the phrase "likely role" renders the claims indefinite because the claims include elements not actually disclosed (those encompassed by "or the like"), thereby rendering the scope of the claims unascertainable. See MPEP § 2173.05(d). Claim Rejections - 35 USC § 102 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. Claims 1-20 are rejected under 35 U.S.C. 102(a)(2) as being anticipated by US 10,897,485 to Goldstein. The applied reference has a common Assignee with the instant application. Based upon the earlier effectively filed date of the reference, it constitutes prior art under 35 U.S.C. 102(a)(2). This rejection under 35 U.S.C. 102(a)(2) might be overcome by: (1) a showing under 37 CFR 1.130(a) that the subject matter disclosed in the reference was obtained directly or indirectly from the inventor or a joint inventor of this application and is thus not prior art in accordance with 35 U.S.C. 102(b)(2)(A); (2) a showing under 37 CFR 1.130(b) of a prior public disclosure under 35 U.S.C. 102(b)(2)(B) if the same invention is not being claimed; or (3) a statement pursuant to 35 U.S.C. 102(b)(2)(C) establishing that, not later than the effective filing date of the claimed invention, the subject matter disclosed in the reference and the claimed invention were either owned by the same person or subject to an obligation of assignment to the same person or subject to a joint research agreement. Regarding claim 1, Goldstein teaches a system comprising: one or more processors (processor 402); and one or more computer-readable media configured to store code comprising instructions (main memory 404 and instructions 424), wherein the instructions, when executed by the one or more processors, cause the one or more processors to: receive, by a third-party server from an organization (Fig. 1, receiving email system/third party system 120), one or more rules governing authentication of messages transmitted from a named entity that is associated with the organization (col. 4, line 59: the domain owner system 110 includes a rule creator 111 that generates validation rules to allow receiving email systems, such as receiving email system 120, to verify the authenticity of emails that indicate the domain of the domain owner system 110 as the sender of the email.), the third-party server designated by the organization for managing part a namespace of the organization, the named entity identifiable by an identifier under the namespace (col. 9, line 22: the DNS record containing the targeted SPF domain specification may be hidden behind one or more DNS CNAME or NS records referring to other domains, and not managed by the targeted DNS SPF resolver); receive, by the third-party server, an authentication query from a message recipient device that attempts to authenticate a message transmitted from a transmitter device purportedly associated with the identifier of the named entity (Fig. 3, 315: query DNS for email domain validation record); determine, by the third-party server and based on the identifier and the one or more rules specified by the organization, a response to the authentication query (340: extract identifying information from query); and transmit the response to the message recipient device (360: transmit target validation record), the response including information that allows the message recipient device to authenticate the message (330: authenticate email). Regarding claim 2, Goldstein teaches the system of claim 1, wherein the instructions, when executed, further cause the one or more processors to: determine a likely role of the named entity (col. 7, line 44: . The authorization evaluator 135 accesses the deliverer/IP store 131 to determine the identity of the delivering email system 115 associated with the identifying information.); transmit a recommendation to the organization for a potential policy modification based on the likely role of the named entity; and implement the potential policy modification (col. 7, line 48: the authorization evaluator accesses the authorized deliverers list 132 to determine whether that delivering email system is an authorized delivery agent for the domain indicated in the identifying information of the DNS query.). Regarding claim 3, Goldstein teaches the system of claim 2, wherein the instructions, when executed, further cause the one or more processors to generate a guided workflow that comprises one or more questions or suggested actions for the organization to characterize the named entity (Figs. 2 and 3: interaction diagrams. Step 345: identify delivering organization based on identifying information). Regarding claim 4, Goldstein teaches the system of claim 2, wherein the likely role of the named entity is determined based on a recursive process (Figs. 2 and 3: interaction diagrams.). Regarding claim 5, Goldstein teaches the system of claim 2, wherein the likely role of the named entity is determined based on one or more searches of open-source intelligence sources (col. 12, line 9: the inbound stream of DNS queries received by the authorizing DNS server 130 can be used as a source of EHLO names and IP addresses that require investigation. For a complete database all (EHLO Name, IP Address) combinations originating from legitimate email should map to a known delivering organization. Any inbound data that cannot be mapped to a known delivering organization may generally indicate a) missing legitimate values in the database). Regarding claim 6, Goldstein teaches the system of claim 1, wherein the named entity is authenticated by the message recipient device through a DNS record associated with the named entity (Fig. 3, 325: query DNS). Regarding claim 7, Goldstein teaches the system of claim 1, wherein the information that allows the message recipient to authenticate the message includes a public key of the named entity, the public key capable of authenticating a digital signature signed by the named entity (Example Key Delegation System. Fig. 3: 345: identifying information). Regarding claim 8, Goldstein teaches the system of claim 1, wherein the authentication query from the message recipient includes contextual metadata of the transmitter device and the one or more rules specified by the organization specify contextual conditions for authenticating the message (fig. 3, 320: generate target domain based on email connection attributes). Regarding claim 9, Goldstein teaches the system of claim 1, wherein the instruction to determine the response to the authentication query comprises instructions to: retrieve an authentication credential of the named entity from a domain name system (DNS) address specified in the identifier of the named entity (Step 325: query DNS); use the authentication credential to verify attested metadata of the named entity that is included in the message (340: extract identifying information); and determine, responsive to a successful verification, that the message is authenticated (350: determine if authorized), wherein the response comprises an indication that the third-party server has determined that the message is authenticated (330: validate email). As per claims 10-18 and 19-20, this is a method and medium version of the claimed system discussed above in claims 1-9 wherein all claimed limitations have also been addressed and/or cited as set forth above. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to AUBREY H WYSZYNSKI whose telephone number is (571)272-8155. The examiner can normally be reached M-F 9-5. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, ALI SHAYANFAR can be reached at 571-270-1050. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /AUBREY H WYSZYNSKI/Primary Examiner, Art Unit 2434
Read full office action

Prosecution Timeline

Jul 29, 2024
Application Filed
May 13, 2026
Non-Final Rejection mailed — §101, §102, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12705352
SCANNING FOR MALWARE BASED ON PROCESS IDENTIFICATION
3y 9m to grant Granted Aug 11, 2026
Patent 12705336
VALIDATING A USER SESSION
1y 8m to grant Granted Aug 11, 2026
Patent 12676891
ENDPOINT SECURITY GROUPS IN PRIVATE MULTI-ACCESS EDGE COMPUTE NETWORKS
2y 6m to grant Granted Jul 07, 2026
Patent 12659351
SECURE NETWORK COMMUNICATION SYSTEM AND METHOD
2y 4m to grant Granted Jun 16, 2026
Patent 12652310
SELECTING ACTIONS RESPONSIVE TO COMPUTING ENVIRONMENT INCIDENTS BASED ON SEVERITY RATING
2y 10m to grant Granted Jun 09, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
90%
Grant Probability
99%
With Interview (+12.5%)
2y 8m (~7m remaining)
Median Time to Grant
Low
PTA Risk
Based on 715 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month