Prosecution Insights
Last updated: August 17, 2026
Application No. 18/787,926

TECHNIQUES FOR DISPLAYING WARNINGS ABOUT POTENTIALLY PROBLEMATIC SOFTWARE APPLICATIONS

Non-Final OA §103
Filed
Jul 29, 2024
Priority
Jan 23, 2024 — provisional 63/624,261
Examiner
WHEATON, BRADFORD F
Art Unit
Tech Center
Assignee
Apple Inc.
OA Round
1 (Non-Final)
62%
Grant Probability
Moderate
1-2
OA Rounds
1y 10m
Est. Remaining
73%
With Interview

Examiner Intelligence

Grants 62% of resolved cases
62%
Career Allowance Rate
240 granted / 390 resolved
+1.5% vs TC avg
Moderate +11% lift
Without
With
+11.2%
Interview Lift
resolved cases with interview
Typical timeline
3y 11m
Avg Prosecution
22 currently pending
Career history
416
Total Applications
across all art units

Statute-Specific Performance

§101
18.3%
-21.7% vs TC avg
§103
68.6%
+28.6% vs TC avg
§102
2.1%
-37.9% vs TC avg
§112
8.8%
-31.2% vs TC avg
Black line = Tech Center average estimate • Based on career data from 390 resolved cases

Office Action

§103
DETAILED ACTION Claims 1-20 are pending in the current application. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-2, 7-9 and 14-16 are rejected under 35 U.S.C. 103 as being unpatentable Takatsuna (Patent No. US 11,755,308), in view of Lin (Pub. No. US 2021/0319127 A1)and further in view of Patil et al. (Pub. No. US 2021/0006462 A1). As to claims 1 and 8 Takatsuna discloses a method for displaying warnings when potentially problematic software applications are launched on computing devices, the method comprising, by a computing device: receiving a first request to install a software application that is comprised of at least one SAA (Takatsuna Col. 4 lines 25-50, Col. 5 lines 13-20 and Col. 6 lines 1-3; which shows a plurality of phases associated with running and install software, include program/code/asset and update associated with it include received a request to install software); installing the software application (Takatsuna Col. 5 lines 13-20; which shows the installation of the software updateable application); receiving, from the management entity, an informational package that pertains to the at least one SAA (Takatsuna Col. 7 lines 2-7 and Col. 8 lines 16-28; which shows being able to receive/download from a controller/management entity and distribution package/information package related to software and viewed as associated asset/code/program that is to be updated, viewed as pertaining to at least one SAA); assigning the informational package to the software application (Takatsuna Col. 7 lines 2-7 and Col. 8 lines 16-56; which shows that the distributed package is an update for a software application that is downloaded/installed and activated viewed as being assigned/attached/associated with the software application that is to be updated); receiving a second request to launch the software application (Takatsuna Col. 5 lines 13-20 and Col. 6 lines 8-10; which shows specific phases associated with software application that can include a phase/request with the activation/launch of the updated software, viewed as software with assigned informational package); and displaying, in association with launching the software application, a user interface that is derived, at least in part, from the informational package (Takatsuna Col. 5 lines 13-20 and Col. 8 lines 29-39; which shows as part of activation/launch process of the software application associated with the update include output/display of notification that user can interact with/user interface where the information presented is associated/derived/determined based on the software update received and attached/connected/associated with the software). Takatsuna does not specifically disclose maintaining a probabilistic data structure that is based on a plurality of software application assets (SAAs) that have been flagged as problematic; and identifying, using the probabilistic data structure, that the at least one SAA has potentially been flagged as problematic. However, Lin discloses maintaining a probabilistic data structure that is based on a plurality of software application assets (SAAs) that have been flagged as problematic (Lin [0002] lines3-5, [0014] lines 11-24 and [0044] lines 10-23; which shows deploying and updating/maintain bloom filter black list, viewed as a type of probabilistic data structure of asset that have be flagged as bad/problematic, of assets involved in the computer operations, thus viewed as including software application assets with the computer operation); identifying, using the probabilistic data structure, that the at least one SAA has potentially been flagged as problematic (Lin [0002] lines3-5, [0014] lines 11-24 and [0044] lines 10-23; which shows being able to use the bloom filter blacklist/probabilistic data structure to determine with an asset associated with the program/software is flagged as bad/potentially problematic). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date to incorporate the teachings of Lin showing the use of probabilistic data structure for tracking potential software asset risk into the download and installation of new software assets of Takatsuna to increase software security by being able to quickly identify information if an asset is potentially bad, as taught by Lin [0014] lines 11-32. Takatsuna as modified by Lin does not specifically disclose identifying, by interfacing with a management entity, that the at least one SAA has in fact been flagged as problematic. However, Patil discloses identifying, by interfacing with a management entity, that the at least one SAA has in fact been flagged as problematic (Patil [0041] lines 1-8, [0043] lines 1-10, [0044] lines 1-5 and [0051] lines 1-5; which shows being able to interface with a management entity to use probability data structure to determine/identify a potential issue after determining that option was flagged/filtered as a potential issue, that in light of the teachings of Lin for the specifics of bloom filter to identify potential issues with assets associated with software can be viewed together as showing identifying, by interfacing with a management entity, that the at least one SAA has in fact been flagged as problematic). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date to incorporate the teachings of Patil showing the specifics of having a manager check after a potential issues has been flagged with probabilistic data structure to verify if it has been actually flagged into the use of probabilistic data structure to track good and bad software assets of Takatsuna as modified by Lin for the purpose of increasing accuracy of asset risk determination by providing an additional check after filtered through probabilistic data structure to confirm asset indicated risk, as taught by Patil [0051] lines 1-5. As to claims 2 and 9 Takatsuna does not specifically disclose, however, Lin discloses wherein the probabilistic data structure is generated by: for each SAA of the plurality of SAAs: generating, using a plurality of hash functions, respective hash values for the SAA; and configuring the probabilistic data structure in accordance with the respective hash values (Lin [0014] lines 14-32; which shows in the generation of the bloom filter/probabilistic data structure for each of the plurality of assets includes using a hashing operation/function for each asset and configuring/setting the bloom filter/data structure in accordance with respective hash values for the assets). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date to incorporate the teachings of Lin showing the use of probabilistic data structure for tracking potential software asset risk into the download and installation of new software assets of Takatsuna to increase software security by being able to quickly identify information if an asset is potentially bad, as taught by Lin [0014] lines 11-32. As to claims 7 and 14, Takatsuna does not specifically disclose, however, Lin discloses wherein the probabilistic data structure comprises a Bloom Filter, a Count-Min Sketch, a HyperLogLog, a Skip Bloom Filter, a Quotient Filter, a Cuckoo Filter, a Randomized Binary Search Tree, a MinHash, a Random Hyperplane Tree, or some combination thereof (Lin [0002] lines3-5, [0014] lines 11-24 and [0044] lines 10-23; which shows being able to use the bloom filter blacklist/probabilistic data structure to determine with an asset associated with the program/software is flagged as bad/potentially problematic thus showing that the probabilistic data structure comprises a Bloom Filter from the list of possible options and combinations). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date to incorporate the teachings of Lin showing the use of probabilistic data structure for tracking potential software asset risk into the download and installation of new software assets of Takatsuna to increase software security by being able to quickly identify information if an asset is potentially bad, as taught by Lin [0014] lines 11-32. As to claim 15, Takatsuna discloses a computing device configured to display warnings when potentially problematic software applications are launched, the computing device comprising: at least one processor (Takatsuna Col. 15 lines 58-64); and at least one memory storing instructions that, when executed by the at least one processor, cause the computing device to carry out steps that include (Takatsuna Takatsuna Col. 15 lines 58-64): The remaining limitation of the claim are comparable to claim 1 above and rejected under the same reasoning. As to claim 16 it is comparable to claim 2 above and rejected under the same reasoning. Claims 3, 5, 10, 12, 17 and 19 are rejected under 35 U.S.C. 103 as being unpatentable Takatsuna, Lin and Patil as applied to claims 1, 8 and 15 above, and further in view of Manuel-Devadoss (Pub. No. US 2024/0193277 A1). As to claims 3, 10 and 17 Takatsuna does not specifically disclose, however, Lin discloses wherein the management entity is communicatively coupled to a data structure that includes, for the at least one SAA, a respective entry that includes: (1) a respective hash value for the at least one SAA (Lin [0014] lines 14-32; which shows the ability to determine a respective hash value for asset). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date to incorporate the teachings of Lin showing the use of probabilistic data structure for tracking potential software asset risk into the download and installation of new software assets of Takatsuna to increase software security by being able to quickly identify information if an asset is potentially bad, as taught by Lin [0014] lines 11-32. Takatsuna as modified by Lin and Patil do not specifically disclose the specifics of a data structure that includes (2) a respective informational package that includes: first information about why the at least one SAA is problematic, and second information about remedial options, if any, available for mitigating the problematic nature of the at least one SAA. However, Manuel-Devadoss discloses the specifics of a data structure that includes (2) a respective informational package that includes: first information about why the at least one SAA is problematic, and second information about remedial options, if any, available for mitigating the problematic nature of the at least one SAA (Manuel-Devadoss [0033] lines 1-8, [0035] lines 1-7, [0036] lines 1-4; which shows the determination/management unit connected with a vulnerability database that identifies and catalogs all known hardware, software and firmware vulnerable, viewed as including SAA that are vulnerable/problematic, and also maintains a severity score for each vulnerability, viewed as type of first information of why problematic as it indicates/describes the degree in which the asset in vulnerable/problematic, as well as for each vulnerability there is maintained in the database remediation actions available to address the issue of the vulnerable asset, viewed the second information in the information package for remediation options if available where there is also a unique ID assigned to each vulnerability, where in light of the teachings of Lin above showing the specifics of assigning/associated with specific bad assets an hash value/unique id would together be viewed as showing the management entity is communicatively coupled to a data structure that includes, for the at least one SAA, a respective entry that includes: (1) a respective hash value for the at least one SAA; and (2) a respective informational package that includes: first information about why the at least one SAA is problematic, and second information about remedial options, if any, available for mitigating the problematic nature of the at least one SAA ). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date to incorporate the teachings of Manuel-Devadoss of maintain dataset of software vulnerability data and associated remediation actions that can be taken to address the issues into the determining potentially risky software assets of Takatsuna as modified by Lin and Patil improve software security by determining, tracking and provided possible remediation actions to determined vulnerabilities, as taught by Manuel-Devadoss [0035] lines 1-7. As to claims 5, 12 and 19 Takatsuna as modified by Lin and Patil do not specifically disclose, however, Manuel-Devadoss discloses wherein the plurality of SAAs comprises: code directories, source code files, executable files, configuration files, library files, database files, resource files, markup and stylesheet files, script files, configuration files, documentation files, log files, temporary files, binary data files, license files, version control files, or some combination thereof (Manuel-Devadoss [0013] lines 1-7 and [0032] lines 1-8; which shows that the assets being analyzed to determine vulnerability/problems includes but not limited to any component connected to or installed in the computing environment or framework that can include software assets and specific executable code in the asset, viewed as type of executable file and thus show that the SAAs comprise at least an executable files and thus teach wherein the plurality of SAAs comprises: code directories, source code files, executable files, configuration files, library files, database files, resource files, markup and stylesheet files, script files, configuration files, documentation files, log files, temporary files, binary data files, license files, version control files, or some combination thereof ). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date to incorporate the teachings of Manuel-Devadoss of maintain dataset of software vulnerability data and associated remediation actions that can be taken to address the issues into the determining potentially risky software assets of Takatsuna as modified by Lin and Patil improve software security by determining, tracking and provided possible remediation actions to determined vulnerabilities, as taught by Manuel-Devadoss [0035] lines 1-7. Claims 4, 11 and 18 are rejected under 35 U.S.C. 103 as being unpatentable Takatsuna, Lin, Patil and Manuel-Devadoss as applied to claims 3, 10 and 17 above, and further in view of Vora et al. (Patent No. US 10,649,630 B1) As to claims 4, 11 and 18 Takatsuna as modified by Lin and Patil do not specifically disclose, however, Manuel-Devadoss discloses wherein the user interface includes: the first information; a first affordance, based on the second information, that, when selected, causes the computing device to update the software application to mitigate the problematic nature of the at least one SAA (Manuel-Devadoss [0033] lines 1-8, [0035] lines 1-5, [0036] lines 1-4, [0050] lines 4-9, [0056] lines 1-7 and [0058] lines 1-4; which show the display/presenting information obtained from the CVE database of vulnerabilities for display including descriptions of vulnerabilities, viewed as first information and remedial actions to address the problem/issue/risk that can include a first affordance option to update the software application with other remedial options available that can be used). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date to incorporate the teachings of Manuel-Devadoss of maintain dataset of software vulnerability data and associated remediation actions that can be taken to address the issues into the determining potentially risky software assets of Takatsuna as modified by Lin and Patil improve software security by determining, tracking and provided possible remediation actions to determined vulnerabilities, as taught by Manuel-Devadoss [0035] lines 1-7. Takatsuna as modified by Lin, Patil and Manuel-Devadoss do not specifically disclose a second affordance, based on the second information, that, when selected, causes the computing device to delete the software application to mitigate the problematic nature of the at least one SAA. However, Vora discloses a second affordance, based on the second information, that, when selected, causes the computing device to delete the software application to mitigate the problematic nature of the at least one SAA (Vora Col. 1 lines 55-61 and Col. 17 lines 36-44; which shows the specific of remediation actions that can be taken to address software asset problems including removing/deleting the software associated with the problem, that in light of the plurality of remediation actions disclosed in Manuel-Devadoss above that are non-limited together are viewed as showing the specifics of a second affordance, based on the second information, that, when selected, causes the computing device to delete the software application to mitigate the problematic nature of the at least one SAA ) Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date to incorporate the teachings of Vora showing the specifics of remediation actions include deletion of the software associated with the determined issue into the providing remediation actions to address determined software issues of Takatsuna as modified by Lin, Patil and Manuel-Devadoss to increase the adaptability by having additional types of remediation options available to address issues, as taught by Vora Col. 1 lines 55-61 Claims 6, 13 and 20 are rejected under 35 U.S.C. 103 as being unpatentable Takatsuna, Lin and Patil as applied to claims 1, 8 and 15 above, and further in view of Joyti et al. (Patent No. US 8,306,988 B1) As to claims 6, 13 and 20 Takatsuna as modified by Lin and Patil do not specifically disclose receiving an update package that, when processed by the computing device, establishes an updated probabilistic data structure that is based on an updated plurality of SAAs that have been flagged as problematic identifying, using the updated probabilistic data structure, that at least one installed SAA on the computing device has potentially been flagged as problematic; identifying, by interfacing with the management entity, that the at least one installed SAA has in fact been flagged as problematic; receiving, from the management entity, a second informational package that pertains to the at least one installed SAA; and assigning the informational package to a second software application associated with the at least one installed SAA. However, Joyti discloses receiving an update package that, when processed by the computing device, establishes an updated probabilistic data structure that is based on an updated plurality of SAAs that have been flagged as problematic identifying, using the updated probabilistic data structure, that at least one installed SAA on the computing device has potentially been flagged as problematic; identifying, by interfacing with the management entity, that the at least one installed SAA has in fact been flagged as problematic; receiving, from the management entity, a second informational package that pertains to the at least one installed SAA; and assigning the informational package to a second software application associated with the at least one installed SAA (Joyti Col. 3 lines 7-11 and Col. 4 lines 14-19; which shows being able to send/push along with a software update hash values for updating bloom filter, viewed as establishing an updated probabilistic data structure that is based on software update, where the bloom filter is associated with/represent then blacklist that identifies unsafe/problematic object and thus viewed when that is updated that an associated software object has been identified/flagged as problematic, where identifying, using the updated probabilistic data structure, that at least one installed SAA on the computing device has potentially been flagged as problematic; identifying, by interfacing with the management entity, that the at least one installed SAA has in fact been flagged as problematic; receiving, from the management entity, a second informational package that pertains to the at least one installed SAA; and assigning the informational package to a second software application associated with the at least one installed SAA are viewed as repeating of the limitations of claim 1 above but for using the updated probabilistic data structure to determine that a SAA is problematic and providing/assigning/using the specific package/update associated with determined asset thus together in light of the cited prior art teachings of claim 1 above viewed as discloses receiving an update package that, when processed by the computing device, establishes an updated probabilistic data structure that is based on an updated plurality of SAAs that have been flagged as problematic identifying, using the updated probabilistic data structure, that at least one installed SAA on the computing device has potentially been flagged as problematic; identifying, by interfacing with the management entity, that the at least one installed SAA has in fact been flagged as problematic; receiving, from the management entity, a second informational package that pertains to the at least one installed SAA; and assigning the informational package to a second software application associated with the at least one installed SAA). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date to incorporate the teachings of Joyti showing the ability to receive and update probabilistic data structure based on updated software information for use, into the use of probabilistic data structure in risk analysis of software of Takatsuna as modified by Lin and Patil for the purpose of increasing confidence in security by keeping data update to detect problematic issues, as taught by Joyti Col. 4 lines 14-32. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to BRADFORD F WHEATON whose telephone number is (571)270-1779. The examiner can normally be reached Monday-Friday 8:00-5:00 EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Chat Do can be reached at 571-272-3721. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /BRADFORD F WHEATON/Examiner, Art Unit 2193
Read full office action

Prosecution Timeline

Jul 29, 2024
Application Filed
Jul 28, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12705160
MANAGING COMPUTING RESOURCE CONSUMPTION OF SOFTWARE APPLICATIONS USING CONTROL GROUPS TO FACILITATE SAFETY COMPLIANCE
2y 8m to grant Granted Aug 11, 2026
Patent 12699769
DYNAMIC RUNTIME MICRO-SEGMENTATION OF INTERPRETED LANGUAGES
3y 2m to grant Granted Aug 04, 2026
Patent 12688021
PROCESSOR CONTROLLED PROGRAMMABLE LOGIC DEVICE MODIFICATION
6y 7m to grant Granted Jul 21, 2026
Patent 12688014
GENERATING APPLICATIONS FOR VARIOUS PLATFORMS BY USE OF A NO CODE ENVIRONMENT
3y 5m to grant Granted Jul 21, 2026
Patent 12688029
COMMUNICATION APPARATUS FOR WIRELESSLY COMMUNICATING WITH ANOTHER APPARATUS, INFORMATION PROCESSING METHOD, AND PROGRAM
3y 2m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
62%
Grant Probability
73%
With Interview (+11.2%)
3y 11m (~1y 10m remaining)
Median Time to Grant
Low
PTA Risk
Based on 390 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month