Prosecution Insights
Last updated: October 04, 2026
Application No. 18/816,932

SECURE, ANONYMOUS BROWSING WITH A REMOTE BROWSING SERVER

Final Rejection §103
Filed
Aug 27, 2024
Priority
Sep 14, 2015 — provisional 62/218,273 +3 more
Examiner
NGUYEN, QUANG N
Art Unit
2441
Tech Center
2400 — Computer Networks
Assignee
Penguin Computing Inc.
OA Round
3 (Final)
88%
Grant Probability
Favorable
4-5
OA Rounds
5m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 88% — above average
88%
Career Allowance Rate
456 granted / 520 resolved
+29.7% vs TC avg
Strong +17% interview lift
Without
With
+16.6%
Interview Lift
resolved cases with interview
Typical timeline
2y 6m
Avg Prosecution
30 currently pending
Career history
553
Total Applications
across all art units

Statute-Specific Performance

§101
12.0%
-28.0% vs TC avg
§103
40.4%
+0.4% vs TC avg
§102
19.7%
-20.3% vs TC avg
§112
7.9%
-32.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 520 resolved cases

Office Action

§103
Detailed Action 1. This Office Action is responsive to the Amendment filed 07/17/2026. Claims 1, 9, 10, 17, 18, 25, 33, 38, 43, 48 and 52 have been amended. Claims 1-58 are presented for examination. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Information Disclosure Statement 2. The information disclosure statement (IDS) submitted on 07/07/2026 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Claim Objections 3. Claim 1 is objected to because of the following informalities: On lines 9-10 of claim 1, line 12 of claim 9, line 8 of claim 33 and line 11 of claim 38: “the instantiation of the application” should be “the remote instantiation of the application”. On line 5 of claim 53 and line 7 of claim 56: “forwarding a remote browsing administrator device,” should be “forwarding to a remote browsing administrator device”. Appropriate correction is required. Claim Rejections - 35 USC § 103 4. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 5. Claims 1, 2, 4-42 and 53-58 are rejected under 35 U.S.C. 103 as being unpatentable over Soman et al. (US 2018/0159896 A1), hereinafter “Soman”, in view of Chauhan (US 2020/0153719 A1). 6. As to claim 1, Soman teaches a method by a remote browsing administrator device comprising at least one processor, the method comprising: receiving, from a client device, a request to open an application ([0021]: secure browsing device 120 receives (201) a request for an internet browser from end user device 110); allocating a remote browsing server, the remote browsing server comprising a remote instantiation of the application and a remote browsing connector ([0023]: after receiving the request from end user device 110, operation 200 further directs secure browsing service 120 to allocate (202) a virtual machine with an instance of the internet browser executing thereon to the end user device); redirecting the request to open the application to the remote browsing connector, wherein the remote browsing connector generates a video stream of renderings from the remote instantiation of the application and transmits user inputs received from the client device to the remote instantiation of the application ([0025]: After allocating the virtual machine to end user device 110, secure browsing 120 further provides (203) a remote connection to the internet browser to end user device 110 to permit the end user device to receive the visual representation of the browser executing in the virtual machine as well as provide user input to the browser to the virtual machine); and causing the client device to connect to the remote instantiation of the application through the remote browsing connector such that the client device displays the video stream and captures the user inputs, and the remote browsing connector transmits the user inputs to the remote instantiation of the application ([0027]: When the end user device is accessing the browser on the virtual machine using a remote desktop protocol, the graphical user interface (GUI) of the desktop is generated on the server hosting the virtual machine and the GUI image data is then encoded and transmitted over the network to the client device, where it is decoded and displayed to the user … Any user input information, such as keyboard and mouse events detected over the secure browser window on the end user device, are transmitted from the device to the virtual machine over the network connection). Soman does not explicitly teach “the requested application is a non-browser application”. In an analogous art, Chauhan teaches “the requested application is a non-browser application” ([0143]: a client application 1102 comprising an embedded browser 1104 may connect to an application server 1112 of an enterprise and request/access a network application, such as a media player application). It would have been obvious to one of ordinary skill in the art before the effective filing data of the claimed invention to combine the teachings of Soman and Chauhan to achieve the claimed invention to enable a user to request/access a variety of media content other than a web page such as video games, media players, via a non-browser application. 7. As to claim 2, Soman-Chauhan teaches the method of claim 1, wherein the request to open the application further comprises an indication of a uniform resource indicator associated with the application (Soman, [0022]: Once a request by the end user corresponds to an untrusted web destination (URL or IP address) that requires the use of secure browsing service 120, a request may be transferred to the secure browsing service 120 to accommodate the secure browsing requirement). 8. As to claim 4, Soman-Chauhan teaches the method of claim 2, wherein the uniform resource indicator is not a Hypertext Transfer Protocol link (Soman, [0022]: the user may select an icon or some other initiation mechanism (e.g., button, image, etc.) to provide a secure remote browser). 9. As to claim 5, Soman-Chauhan teaches the method of claim 1, wherein the request to open the application is received from a browser associated with the client device (Soman, [0022]: browser request module 115 may monitor the operations of the user on a local browser installed at the end user device 110 to identify URIs/URLs associated with requests). 10. As to claim 6, Soman-Chauhan teaches the method of claim 5, wherein the browser associated with the client device displays the video stream and captures the user inputs from the client device (Soman, [0027]: When the end user device is accessing the browser on the virtual machine using a remote desktop protocol, the graphical user interface (GUI) of the desktop is generated on the server hosting the virtual machine and the GUI image data is then encoded and transmitted over the network to the client device, where it is decoded and displayed to the user … Any user input information, such as keyboard and mouse events detected over the secure browser window on the end user device, are transmitted from the device to the virtual machine over the network connection). 11. As to claim 7, Soman-Chauhan teaches the method of claim 1, wherein the request to open the application is received from an operating system associated with the client device (Soman, [0022]: receive a request for a secure remote browser from an icon being selected by the user or browser request module 115 (i.e., operating system) may monitor the operations of the user on a local browser installed at the end user device 110 to identify URIs/URLs associated with requests). 12. As to claim 8, Soman-Chauhan teaches the method of claim 7, wherein a local application instance executing on the client device displays the video stream and captures the user inputs from the client device (Soman, [0027]: When the end user device is accessing the browser on the virtual machine using a remote desktop protocol, the graphical user interface (GUI) of the desktop is generated on the server hosting the virtual machine and the GUI image data is then encoded and transmitted over the network to the client device, where it is decoded and displayed to the user … Any user input information, such as keyboard and mouse events detected over the secure browser window on the end user device, are transmitted from the device to the virtual machine over the network connection). 13. As to claims 9-10 and 12-16, claims 910 and 12-16 are corresponding remote browsing administrator device claims that recite similar limitations as of method claims 1-2 and 4-8; therefore, they are rejected under the same rationale. 14. As to claims 17-18, 20-26 and 28-32, claims 17-18, 20-26 and 28-32 are corresponding method and client device claims that recite similar limitations as of method claims 1, 2 and 4-8; therefore, they are rejected under the same rationale. 15. As to claims 33-34, 36-39 and 41-42, claims 33-34, 36-39 and 41-42 are corresponding method and remote browsing administrator device claims that recite similar limitations as of method claims 1-4 and 6; therefore, they are rejected under the same rationale. 16. Claim 3, 11, 19, 27, 35 and1 40 are rejected under 35 U.S.C. 103 as being unpatentable over Soman-Chauhan, and further in view of Shah et al. (US 2020/0252803 A1), hereinafter “Shah”. 17. As to claim 3, Soman-Chauhan teaches the method of claim 2, but does not explicitly teach “the uniform resource indicator identifies a type of application associated with the application”. In an analogous art, Shah teaches “the uniform resource indicator identifies a type of application associated with the application” ([0073]: Safe browsing engine 430 may manage secure browsing for UE 110 by determining whether a URL corresponds to an malicious URL based on the URL’s features; [0079]: wherein the features may include whether the URL is associated with an application, a particular application associated with the URL, a particular type of application associated with the URL, a particular operating system associated with the URL). It would have been obvious to one of ordinary skill in the art before the effective filing data of the claimed invention to combine the teachings of Soman-Chauhan and Shah to achieve the claimed invention to enable the system to identify a particular type of application associated with the requested URL and determine whether the requested URL corresponds to a malicious URL (Shah, [0073]). 18. As to claim 11, claim 11 is a corresponding remote browsing administrator device claim that recites similar limitations as of method claim 3; therefore, it is rejected under the same rationale. 19. As to claims 19 and 27, claims 19 and 27 are corresponding method and client device claims that recite similar limitations as of method claim 3; therefore, they are rejected under the same rationale. 20. As to claims 35 and 40, claims 35 and 40 are corresponding method and remote browsing administrator device claims that recite similar limitations as of method claim 3; therefore, they are rejected under the same rationale. 21. Claims 43-52 are rejected under 35 U.S.C. 103 as being unpatentable over Soman, in view of Gyorffy et al. (US 2010/0287382 A1), hereinafter “Gyorffy”, and further in view of Chauhan (US2020/0153719 A1). 22. As to claim 43, Soman teaches a method by a client device comprising at least one processor, the method comprising: forwarding, to a remote browsing administrator device, a request to open the file or application wherein the request also comprises the file or application ([0023]: after receiving the request from end user device 110, operation 200 further directs secure browsing service 120 to allocate (202) a virtual machine with an instance of the internet browser executing thereon to the end user device); receiving instructions, from the remote browsing administrator device to connect to a remote browsing server via a remote browsing connector ([0025]: After allocating the virtual machine to end user device 110, secure browsing 120 further provides (203) a remote connection to the internet browser to end user device 110 to permit the end user device to receive the visual representation of the browser executing in the virtual machine as well as provide user input to the browser to the virtual machine); receiving, from the remote browsing server, a video stream of renderings from a remote execution of the file or application at the remote browsing server; displaying the video stream of renderings from the remote execution of the file or application via the client device; and providing, to the remote browsing server, user inputs received from the client device ([0027]: When the end user device is accessing the browser on the virtual machine using a remote desktop protocol, the graphical user interface (GUI) of the desktop is generated on the server hosting the virtual machine and the GUI image data is then encoded and transmitted over the network to the client device, where it is decoded and displayed to the user … Any user input information, such as keyboard and mouse events detected over the secure browser window on the end user device, are transmitted from the device to the virtual machine over the network connection). Soman does not explicitly disclose “determining that at least one of a file or application from a removable drive is about to be executed on the client device”. In an analogous art, Gyorffy discloses “determining that at least one of a file or application from a removable drive is about to be executed on the client device” ([0059]: The user will access the USB device like a normal file system and run a Web browser by double clicking on the executable program stored in the device’s flash memory). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Soman and Gyorffy to achieve the claimed invention to ensure that the user application, downloaded from the USB device and executed on the user machine, is free from infection or corruption. Soman-Gyorffy does not explicitly teach “the requested application is a non-browser application”. In an analogous art, Chauhan teaches “the requested application is a non-browser application” ([0143]: a client application 1102 comprising an embedded browser 1104 may connect to an application server 1112 of an enterprise and request/access a network application, such as a media player application). It would have been obvious to one of ordinary skill in the art before the effective filing data of the claimed invention to combine the teachings of Soman-Gyorffy and Chauhan to achieve the claimed invention to enable a user to request/access media content other than a web page such as video games, media players, via a non-browser application. 23. As to claim 44, Soman-Gyorffy-Chauhan teaches the method of claim 43, wherein the removable drive is a Universal Serial Bus drive (Gyorffy, [0059]). 24. As to claim 45, Soman-Gyorffy-Chauhan teaches the method of claim 43, wherein the forwarding the request to open the file or application is via an operating system on the client device (Gyorffy, [0059] and Soman, [0022] and [0034]). 25. As to claim 46, Soman-Gyorffy-Chauhan teaches the method of claim 45, wherein the displaying the video stream of renderings from the remote execution of the file or application comprises displaying the video stream of renderings via a browser on the client device (Soman, [0027]: When the end user device is accessing the browser on the virtual machine using a remote desktop protocol, the graphical user interface (GUI) of the desktop is generated on the server hosting the virtual machine and the GUI image data is then encoded and transmitted over the network to the client device, where it is decoded and displayed to the user). 26. As to claim 47, Soman-Gyorffy-Chauhan teaches the method of claim 43, wherein the displaying the video stream of renderings from the remote execution of the file or application comprises displaying the video stream of renderings via a local application instance executing on the client device (Soman, [0027]: When the end user device is accessing the browser on the virtual machine using a remote desktop protocol, the graphical user interface (GUI) of the desktop is generated on the server hosting the virtual machine and the GUI image data is then encoded and transmitted over the network to the client device, where it is decoded and displayed to the user). 27. As to claims 48-52, claims 48-52 are corresponding client device claims that recite similar limitations as of method claims 43-47; therefore, they are rejected under the same rationale. 28. Claims 53-58 are rejected under 35 U.S.C. 103 as being unpatentable over Soman, in view of Shah et al. (US 2020/0252803 A1), hereinafter “Shah”. 29. As to claim 53, Soman teaches a method by a client device comprising at least one processor, the method comprising: determining that an application is about to be executed on the client device ([0022]: the end user device may receive an explicit request from a user on end user device 110); determining forwarding, to a remote browsing administrator device, a request to open the application ([0023]: after receiving the request from end user device 110, operation 200 further directs secure browsing service 120 to allocate (202) a virtual machine with an instance of the internet browser executing thereon to the end user device); receiving instructions, from the remote browsing administrator device to connect to a remote browsing server via a remote browsing connector ([0025]: After allocating the virtual machine to end user device 110, secure browsing 120 further provides (203) a remote connection to the internet browser to end user device 110 to permit the end user device to receive the visual representation of the browser executing in the virtual machine as well as provide user input to the browser to the virtual machine); receiving, from the remote browsing server, a video stream of renderings from a remote instantiation of the application at the remote browsing server; displaying the video stream of renderings from the remote instantiation of the application via the client device; and providing, to the remote browsing server, user inputs received from the client device ([0027]: When the end user device is accessing the browser on the virtual machine using a remote desktop protocol, the graphical user interface (GUI) of the desktop is generated on the server hosting the virtual machine and the GUI image data is then encoded and transmitted over the network to the client device, where it is decoded and displayed to the user … Any user input information, such as keyboard and mouse events detected over the secure browser window on the end user device, are transmitted from the device to the virtual machine over the network connection). Soman does not explicitly disclose “the determining step is based on a behavioral analysis associated with a user profile of the client device satisfying a predefined criterion”. In an analogous art, Shah teaches that Risk score manager 310 may generate a security risk score for a user of UE device 110. Risk score manager 310 may obtain, with the user’s permission, demographic information associated with the user, such as, for example, the geographic area associated with the user, the number of subscriber lines associated with the user, the number of children associated with the user, and/or other types of demographic information that may have relevance to determine a security risk. Furthermore, risk score manager 310 may obtain, the user’s permission, information relating to the browsing history for the user and/or information relating to application use associated with the user, such as which applications are installed on UE device 110 and/or how often the user uses particular applications ([0061-0062]). It would have been obvious to one of ordinary skill in the art before the effective filing data of the claimed invention to combine the teachings of Soman and Shah to achieve the claimed invention to enable the system to determine a security risk for a user’s account/subscription (Shah, [0062]). 30. As to claim 54, Soman-Shah teaches the method of claim 53, wherein the behavioral analysis is based on an action log associated with the user profile (Shah, [0061]: information relating to the browsing history for the user and/or information relating to application use associated with the user, such as which applications are installed on UE device and/or how often the user uses particular applications). 31. As to claim 55, Soman-Shah teaches the method of claim 53, the behavioral analysis is based on an application type of the application (Shah, [0062]: the security risk score may be computed using a machine learning model trained to generate a security risk score based on a set of demographic parameters and/or behavior parameters including the particular websites visited by the UE devices associated with the account/subscription, the particular applications used by the UE devices associated with the account/subscription). 32. As to claims 56-58, claims 56-58 are corresponding client device claims that recite similar limitations as of method claims 53-55; therefore, they are rejected under the same rationale. Response to Arguments 33. Applicant’s arguments filed 07/17/2026 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. 34. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. 35. Further references of interest are cited on Form PTO-892, which is an attachment to this Office Action. 36. Any inquiry concerning this communication or earlier communications from the examiner should be directed to QUANG N NGUYEN whose telephone number is (571) 272-3886. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, KAMAL B. DIVECHA, can be reached at (571) 272-5863. The fax phone number for the organization is (571) 273-8300. Information regarding the status of published or unpublished applications may be obtained from the Patent Center. Status information for unpublished applications is available to registered users. To file and manage patent submissions in Patent Center, visit https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /QUANG N NGUYEN/ Primary Examiner, Art Unit 2453
Read full office action

Prosecution Timeline

Aug 27, 2024
Application Filed
Dec 08, 2025
Non-Final Rejection mailed — §103
Mar 02, 2026
Response Filed
Apr 22, 2026
Non-Final Rejection mailed — §103
Jul 17, 2026
Response Filed
Sep 10, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12744834
ADAPTIVE COMPRESSION OF STORED DATA
1y 10m to grant Granted Sep 22, 2026
Patent 12712932
A COMMUNICATIONS SYSTEM AND METHOD FOR DELIVERING A LIVE MESSAGE TO RECIPIENTS
1y 8m to grant Granted Aug 18, 2026
Patent 12706809
MANAGING CLOUD-NATIVE VIRTUAL NETWORK FUNCTIONS
2y 1m to grant Granted Aug 11, 2026
Patent 12693921
Simplified Configuration of Network Policy
2y 3m to grant Granted Jul 28, 2026
Patent 12598240
USER INTERACTION AND TASK MANAGEMENT USING MULTIPLE DEVICES
2y 3m to grant Granted Apr 07, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

4-5
Expected OA Rounds
88%
Grant Probability
99%
With Interview (+16.6%)
2y 6m (~5m remaining)
Median Time to Grant
High
PTA Risk
Based on 520 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month