Prosecution Insights
Last updated: September 17, 2026
Application No. 18/864,448

SECURED ACCESS SYSTEM

Final Rejection §103§112
Filed
Nov 08, 2024
Priority
May 10, 2022 — EU 22172558.3 +1 more
Examiner
HABTEGEORGIS, MATTHIAS
Art Unit
2491
Tech Center
2400 — Computer Networks
Assignee
Barix AG
OA Round
2 (Final)
79%
Grant Probability
Favorable
3-4
OA Rounds
1y 2m
Est. Remaining
96%
With Interview

Examiner Intelligence

Grants 79% — above average
79%
Career Allowance Rate
93 granted / 118 resolved
+20.8% vs TC avg
Strong +17% interview lift
Without
With
+16.7%
Interview Lift
resolved cases with interview
Typical timeline
3y 0m
Avg Prosecution
21 currently pending
Career history
142
Total Applications
across all art units

Statute-Specific Performance

§101
5.1%
-34.9% vs TC avg
§103
63.5%
+23.5% vs TC avg
§102
10.9%
-29.1% vs TC avg
§112
19.3%
-20.7% vs TC avg
Black line = Tech Center average estimate • Based on career data from 118 resolved cases

Office Action

§103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Arguments Applicant’s argument, see Remarks, filed 07/02/2026, with respect to the rejection(s) of independent claim 1 under 35 USC § 102 has been fully considered and the amendments overcome the rejection 1 under 35 USC § 102. However, the argument is moot because of the new ground of rejections under 35 USC § 103 based on newly found prior art, Silva Pinto, US 2016/0086176. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 14 and 25 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claim 14 recites the limitation "A system for carrying out the method of claim 1, wherein the system comprises an authentication server, at least one mobile device and at least one further device, the further device comprising a network adapter configured to provide at least one of a direct internet connection and an indirect internet connection," in lines 1-5. The further recitations of the same devices of claim 1 have antecedent basis issue (lack of clarity). The Examiner recommends to rewrite claim 14 as an independent claim reciting the same limitations as claim 1 including the device claims. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-9, 14-22 and 25-26 are rejected under 35 U.S.C. 103 as being unpatentable over US-PGPUB No. 2014/0273824 A1 to Fenner et al. (hereinafter “Fenner”), and further in view of US-PGPUB No. 2016/0086176 A1 to Silva Pinto et al. (hereinafter “Silva Pinto”) Regarding claim 1: Fenner discloses: (Currently Amended) A method (see the method of Fig. 10) for enabling a communication connection between a mobile device (see Fig. 1, Remote Device 106) and a further device (see Fig. 1, Implantable Device 110), the mobile device and the further device having a common interface for data exchange (¶19: “… method for pairing an implantable device with a remote device using an NFC tag associated with the implantable device …”, see the method of Fig. 10), wherein the further device comprises a network adapter configured to provide at least one of a direct internet connection and an indirect internet connection (see Fig. 1, Implantable device 108 connected to network 104, and ¶51: “networks 104 can include … wide area networks (… e.g., the Internet),”), the method comprising: sending a communication request from the mobile device to the further device via the common interface (¶63: “remote device 210 can move within close proximity of NFC device 204 and send a request induction signal that is received by communication component 206 (e.g., an NFC induction coil antenna).”), […]; transmitting an encrypted challenge from the further device to the mobile device via the common interface (¶63: “The request induction signal can energize the NFC device, causing the NFC device to transmit identification information stored therein back to remote device 210 using NFC protocol.”, see also ¶28: “remote device 106 and implantable device 108 can establish a secure and authorized communication channel, thus becoming "paired." … remote device 106 and implantable device 108 can exchange secure, private, or otherwise protected information between one another only after becoming paired.”); transferring the encrypted challenge from the mobile device via a data connection to a server, the server being an authentication server (¶64: “remote device 210 can communicate the identification information to the server 212 to facilitate authenticating and authorizing …”), at which a user of the mobile device has logged on or at which the user of the mobile device has not logged on (¶35: “This could be accomplished by entering user information associated with an account on the remote device 106”); checking an access authorization in the authentication server on a basis of the encrypted challenge (¶64: “server 212 can determine that a pairing between remote device 210 and implantable device 202 is authorized”), and if the access authorization is absent, outputting a corresponding message and/or terminating the communication connection via the authentication server (implicitly disclosed in ¶64, and claim 12: “wherein the identification information comprises information that facilitates determining whether a device is authentic, unauthorized, or a counterfeit.”, Note: “information” implies message to be displayed); or if the access authorization is absent, generating an encrypted authentication, a content of which is an absent authentication, and if the access authorization is provided, generating an encrypted authentication, and performing: transferring the encrypted authentication from the authentication server to the mobile device via the data connection (¶64: “send a message or signal (e.g., a key or password) back to the remote device indicating this authorization.”); transmitting the encrypted authentication from the mobile device to the further device via the common interface (¶65: “remote device 210 can send the authorization message or signal to implantable device 202 …”); checking the access authorization in the further device on the basis of the encrypted authentication (¶65: “The implantable device can then authenticate the authorization message or signal (e.g., perform a key matching procedure)”), and if the access authorization is absent, outputting or transmitting a corresponding message to the mobile device (implicitly disclosed in ¶84: “If authorized based on the key matching procedure, the authorization component 816 can allow the communication component 814 to communicate with the remote device”), if the access authorization is provided, enabling the data exchange between the mobile device and the further device and/or the data exchange between the further device and the authentication server via the mobile device within a scope of the encrypted authentication (¶65: “and open up communication with remote device 210 (e.g., communication of sensitive information over a secure data channel)”). However, Fenner does not explicitly teach the following limitation taught by Silva Pinot: the further device being disconnected from an internet at a time of the sending (Silva Pinto, ¶13: “The user device sends the OTP password to a wearable device using an offline method for transferring data, preferably using Bluetooth technology, but not limited to it, and may be the reading of a QRCode (Quick Response Code).”, see also Fig. 4, device 200 connected to wearable device 204 using Bluetooth 203). It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the teachings of Fenner to incorporate the functionality of the method to send an OTP password to a wearable device using an offline method using Bluetooth technology, as disclosed by Silva Pinto, such modification would enable the system to reduce the risk of wearable device (further device) being compromised and controlled over the Internet by an attacker. Regarding claim 2: The combination of Fenner and Silva Pinto discloses: The method of claim 1, wherein the data exchange between the further device and the authentication server is effected via the mobile device (¶33: “Upon receipt of the message by implantable device 108, implantable device 108 and server 102 can begin secure communication using remote device 106 as a proxy.”), and parameters which supervise the further device and are stored on the authentication server (¶34: “in order to pair remote device 106 and implantable device 108, server 102 can pass a message to the remote device 106 (e.g., a key or password) … for the purpose of setting up a secure data communications channel between the implantable device 108 and the server 102.”) , or are applied to the authentication server by the user of the mobile device , are written to the further device from the authentication server via the mobile device. Regarding claim 3: The combination of Fenner and Silva Pinto discloses: (Currently Amended) The method of claim 1, wherein the common interface is a wireless interface, preferably a Bluetooth, BLE, WLAN, NFC (¶63: “… the remote device 210 interacts with NFC device 204 to receive identification information stored by the NFC device 204.”), RFID, and/or sound interface, and/or the common interface is a wired interface. Regarding claim 4: The combination of Fenner and Silva Pinto discloses: The method of claim 1, wherein the encrypted authentication includes information about a scope of the access authorization (¶34: “… the message can indicate and thus authorize secure data transfer from implantable device 108 to remote device 106 yet deny data transfer from remote device 106 to implantable device 108.”). Regarding claim 5: The combination of Fenner and Silva Pinto discloses: The method of claim 1, wherein checking the access authorization in the authentication server takes into account information about the mobile device, and/or information about the user logged on at the mobile device and/or at the authentication server (¶35: “… the only way the remote device 106 would then be authorized to view and/or program information on implantable device 108 would be if it were authorized by server 102. This could be accomplished by entering user information associated with an account on the remote device 106 in response to a request by the remote device to communicate with the implantable device 108.”), and/or information from a token of the user. Regarding claim 6: The combination of Fenner and Silva Pinto discloses: The method of claim 1, wherein the mobile device is a laptop or a cellular phone (¶60: “remote device 106 can include but is not limited to, a handheld computing device, a desktop computer, a laptop computer, a smart-phone, a tablet personal computer (PC), a personal digital assistant (PDA) or a server.”). Regarding claim 7: The combination of Fenner and Silva Pinto discloses: The method of claim 1, wherein during the data exchange, data are read from a memory of the further device (¶60: “remote device 106 can include a reader device configured to read information from NFC device 110 and implantable device 108.”), an update is loaded on the further device, the further device is reconfigured, or a combination thereof. Regarding claim 8: The combination of Fenner and Silva Pinto discloses: The method of claim 1, wherein the further device comprises circuitry (see Fig. 8, Communication Component 814), and a memory (see Fig. 8, Processor 810 and Memory 812). Regarding claim 9: The combination of Fenner and Silva Pinto discloses: The method of claim 1, wherein on the authentication server and the further device, private keys for generating the encrypted challenge and respectively authentication and verification of the encrypted challenge are present (¶37: “server 102 employs a PKI infrastructure to facilitate authenticating and authorizing pairing between remote device 106 and implantable device 108 … PKI provides each party in an authentication agreement with a pair of keys, a private key, and a public key, used in every signed transaction.”). Regarding claim 14: The combination of Fenner and Silva Pinto discloses: (Currently Amended) A system for carrying out the method of claim 1 (see the system of Fig. 1), wherein the system comprises an authentication server (see Fig. 1, Server 102), at least one mobile device (see Fig. 1, Implantable Device 108) and at least one further device (see Fig. 1, Remote Device 106), and wherein a data connection is present between the authentication server and the mobile device (see Fig. 1, Implantable device 108 connected to Server 102 via Network 104), and the mobile device and the further device comprise at least one common interface for data exchange (¶27: “system 100 employs NFC device 110 attached to implantable device 108 to facilitate transmitting and/or receiving information using NFC protocol in associating with pairing implantable device 108 and remote device 106.”). In addition to the above limitations claim 14 recites substantially the same limitations as claim 1 in the form of a system implementing the corresponding method. Therefore, it is rejected by the same rationale. Regarding claim 15: The combination of Fenner and Silva Pinto discloses: A non-transitory computer readable medium having instructions stored thereon which when executed by a processing circuitry cause the processing circuitry to execute the method of claim 1 (¶06: “a method is disclosed that includes employing at least one processor executing computer-executable instructions embodied on at least one computer-readable storage medium to perform the following operations:”), wherein the processing circuitry communicates on the mobile device with an output interface (¶62: “ Implantable device 202 and NFC device 204 include respective communication components 208 and 206.”). See also the rejection of claim 1. Regarding claim 16: The combination of Fenner and Silva Pinto discloses: (New) The method of claim 1, further comprising a data exchange between the further device and the authentication server (¶26: “remote device 106 and/or server 102 are configured to communicate with one another over one or more networks 104.”). Regarding claim 17: The combination of Fenner and Silva Pinto discloses: The method of claim 2, wherein the data exchange between the further device and the authentication server is effected via the mobile device (¶29: “… the message transmitted from the server 102 to the implantable device 108 via remote device 106 …”), and parameters which supervise the further device and are stored on the authentication server (¶84: “The key or password can be generated and provided to the remote device by a server (e.g., in association with authenticating and authorizing NFC tag identification information for the implantable device 800).”), or are applied to the server by the user, are written to the further device from the server via the mobile device, without direct and/or indirect influencing by the user with or without logging of the data exchange via a display of the mobile device to the user. Regarding claim 18: The combination of Fenner and Silva Pinto discloses: The method of claim 3, wherein the common interface is a Bluetooth, BLE, WLAN, NFC (¶27: “system 100 employs NFC device 110”), RFID, and/or sound interface, and/or the common interface is a wired serial interface, a USB interface, Ethernet, and/or CAN bus. Regarding claim 19: The combination of Fenner and Silva Pinto discloses: The method of claim 1, wherein the encrypted authentication includes authentication information about a scope of the access authorization (¶54: “information stored in memory of the NFC device 110 can be partitioned into different areas that can be restrictively accessed.”), the authentication information comprising user information (¶54: “patient information”), time information, location information, permitted intervention depth (¶34: “the message can indicate and thus authorize data transfer of a first set of information (e.g., information rated as mildly sensitive) yet deny data transfer of a second set of information (e.g., information rated as highly sensitive).”). Regarding claim 20: The combination of Fenner and Silva Pinto discloses: The method of claim 1, wherein checking the access authorization in the authentication server takes into account the encrypted challenge and information about the mobile device, the information about the mobile device comprising hardware-specific and individualized information, and/or information about the user logged on at the mobile device (¶41: “… the remote device 106 would first be authorized/authenticated to communicate with the NFC device 110 based on the authentication code/password provided thereto by the user 112.”) and/or at the authentication server, and/or information from a token of the user. Regarding claim 21: The combination of Fenner and Silva Pinto discloses: The method of claim 1, wherein the further device comprises a data processing circuitry (see Fig. 9, Remote Device 900 comprising Processor 906 and Memory 908), a memory and at least one of a sensor, an output interface including a display (see Fig. 9, Remote Device 900 comprising Display component 916), or a loudspeaker, or any combination thereof. Regarding claim 22: The combination of Fenner and Silva Pinto discloses: (New) The method of claim 1, wherein on the authentication server and the further device, private keys for the generating of the encrypted challenge and respectively authentication and verification of the encrypted challenge are present (¶36: “the identification information can include private keys …”), corresponding associated public keys being present on the further device (¶36: “the identification information can include … public keys associated with a public key infrastructure (PKI). …”), wherein an incrementing number can be managed on the further device (¶36: “… the identification information for implantable device 108 can include a secret or private key associated with the implantable device and required for user authorization in association with a public key.”). Regarding claim 25: The combination of Fenner and Silva Pinto discloses: (New) The system of claim 14, wherein the system comprises a server and/or an authentication server (see Fig. 1, Server 102, ¶30: “Server 102 can include one or more suitable interconnected computing devices that have authorization and authentication capabilities.”), at least one mobile device (¶109: “a smart phone,”) and a plurality of further devices (¶30: “one or more implanted devices”). Regarding claim 26: The combination of Fenner and Silva Pinto discloses: The non-transitory computer readable medium of claim 15, wherein the processing circuitry communicates on the mobile device with an output interface comprising a display of the mobile device for communication with the user (¶92: “Remote device 900 can also include display component 916 to display information to a user. … display component 916 can display instructions to be transmitted to an implantable device and/or information received from an implantable device.”). Claims 10 is rejected under 35 U.S.C. 103 as being unpatentable over Fenner, Silva Pinto and further in view of US-PGPUB No. 2022/0161039 A1 to Manicka Regarding claim 10: The combination of Fenner and Silva Pinto discloses the method of claim 9, but fails to disclose the following limitation taught by Manicka: wherein a plurality of keys are kept available on the authentication server and the further device (Manicka, ¶46: “Gatekeeping device 14 can then generate a public key based on the private key generated. This public key can be communicated to the remote internet-based server, such as hosting server 20, for use in decoding communications originated by gatekeeping device 14. Similarly, the remote internet-based server can also generate a private/public key combination and transmit the public key to gatekeeping device 14.”), and are then changed either randomly or after a specific time (Manicka, ¶46: “a new private key can be generated by the paired proximate device every new day, new hour, or at five-minute intervals, for communications conducted by gatekeeping device 14 and remote internet-based servers. … Such frequent changing of these private/public key combinations …”) and/or after a specific incrementing number has been reached. It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to modify the teachings of the combination of Fenner and Silva Pinto to incorporate the functionality of the method to frequently change private/public keys, as disclosed by Manicka, such modification would enable the system to limit the time for a hacker to hack the private key to one day or less—a small fraction of the time required for such hacking for today's most powerful computers. Claims 11 and 23 are rejected under 35 U.S.C. 103 as being unpatentable over Fenner, Silva Pinto, and further in view of US-PGPUB No. 2017/0345019 A1 to Radocchia et al. (hereinafter “Radocchia”) Regarding claim 11: The combination of Fenner and Silva Pinto discloses the method of claim 9, but fails to disclose the following limitation taught by Radocchia: wherein the private keys, alone or together with hardware-specific and individualized information of the further device, are stored on a public blockchain (Radocchia, ¶07: “wirelessly reading the unique identifier from one or more of the identity tags with a mobile device … the blockchain associating and storing the unique identifier, a network accessible location identifier and a public key for each of the items,”). It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to modify the teachings of the combination of Fenner and Silva Pinto to incorporate the functionality of the method to associate, and store identification data, such as a unique identifier, a location identifier and a public key in a blockchain, as disclosed by Radocchia, such modification enables public access to the identification data with optional item registration anonymity. Regarding claim 23: The combination of Fenner and Silva Pinto discloses the method of claim 9, but fails to disclose the following limitation taught by Radocchia: wherein keys, together with hardware-specific and individualized information of the further device, are stored on a public blockchain (Radochia, ¶07: “wirelessly reading the unique identifier from one or more of the identity tags with a mobile device … the blockchain associating and storing the unique identifier, a network accessible location identifier and a public key for each of the items,”). It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to modify the teachings of the combination of Fenner and Silva Pinto to incorporate the functionality of the method to associate, and store identification data, such as a unique identifier, a location identifier and a public key in a blockchain, as disclosed by Radocchia, such modification enables public access to the identification data with optional item registration anonymity. Claims 12 is rejected under 35 U.S.C. 103 as being unpatentable over Fenner, Silva Pinto, USPAT No. 9980140 B1 to Spencer et al. (hereinafter “Spencer”), and further in view of US-PGPUB No. 2018/0181737 A1 to Tussy Regarding claim 12: The combination of Fenner and Silva Pinto discloses the method of claim 1, but fails to disclose the following limitation taught by Tussy: wherein, if the encrypted challenge leads to a non- authorization during checking on the authentication server, the authentication server transmits an authentication to the mobile device (Tussy, ¶103: “if the credentials provided by the user are not verified, the authentication server may transmit a message to display on the screen of the mobile device 112 …”), which either is recognized as non-authorization directly at the mobile device and leads to the outputting of a corresponding message to the user at the mobile device (Tussy, ¶103: “… the authentication server may transmit a message to display on the screen of the mobile device 112 indicating that the login attempt failed.”), or the authentication is transmitted to the further device and the corresponding message is output on the further device, or the authentication is transmitted back from the further device to the mobile device and the corresponding message is output on the mobile device. It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to modify the teachings of the combination of Fenner and Silva Pinto to incorporate the functionality of the authentication server to send a message to be displayed on a mobile device of a user to indicate a failed authentication attempt, as disclosed by Tussy, such modification allows the user to correct credentials and attempt to login a second time if the first attempt was a failure. Claims 13 and 24 are rejected under 35 U.S.C. 103 as being unpatentable over Fenner, Silva Pinto, USPAT No. 9980140 B1 to Spencer et al. (hereinafter “Spencer”), and further in view of US-PGPUB No. 2017/0295174 A1 to Kim et al. (hereinafter “Kim”) Regarding claim 13: The combination of Fenner and Silva Pinto discloses the method of claim 1, but fails to disclose the following limitation taught by Spencer: wherein an identifier is provided on the further device (Spencer, col 2, lines 12-13: “a unique identifier for a medical device,”), the identifier can be read by the mobile device and the identifier is used for the identification of the further device and for the communication connection with the authentication server when the identifier is being transmitted […] to the authentication server (Spencer, col 2, lines 11-16: “a mobile computing device can obtain a unique identifier for a medical device, such as through optical scanning (e.g., barcode/QR code scanner) and/or radio frequency detection (e.g., RFID), and transmit the unique identifier to a server system.”) It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to modify the teachings of the combination of Fenner and Silva Pinto to incorporate the functionality of the mobile computing device to obtain a unique identifier for a medical device, such as through optical scanning (e.g., barcode/QR code scanner) and/or radio frequency detection (e.g., RFID), and transmit the unique identifier to a server system, as disclosed by Spencer, such modification would enable the mobile computing device to establish a secure connection with the medical device using the medical device's information, for example, as a secret shared between the mobile computing device and the medical device. The combination of Fenner, Silva Pinto and Spencer does not explicitly disclose the following limitation taught by Kim: […] together with the encrypted challenge (Kim, ¶153: “… the user terminal 200 may transmit the generated OTP to the service providing server 100. The user terminal 200 may transmit the module identification information associated with the OTP … to the service providing server 100 together with the OTP”). It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to modify the teachings of the combination of Fenner, Silva Pinto and Spencer to incorporate the functionality of the user terminal to transmit a generated OTP together with a module identification information associated with the OTP to a service providing server, as disclosed by Kim, such modification would enable the system to verify the authenticity of both the user terminal and the server to protect the service provider from a security breach. Regarding claim 24: The combination of Fenner and Silva Pinto discloses the method of claim 1, but fails to disclose the following limitation taught by Spencer: wherein an identifier, the identifier comprising a barcode or a QR code (col 2, lines 12-14: “a unique identifier for a medical device, such as through optical scanning (e.g., barcode/QR code scanner)”), is provided on the further device, wherein the identifier can be read by the mobile device and is used for the identification of the further device and for the communication connection with the authentication server when the identifier is transmitted […] to the authentication server (Spencer, col 2, lines 11-16: “a mobile computing device can obtain a unique identifier for a medical device, such as through optical scanning (e.g., barcode/QR code scanner) and/or radio frequency detection (e.g., RFID), and transmit the unique identifier to a server system.”) It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to modify the teachings of the combination of Fenner and Silva Pinto to incorporate the functionality of the mobile computing device to obtain a unique identifier for a medical device, such as through optical scanning (e.g., barcode/QR code scanner) and/or radio frequency detection (e.g., RFID), and transmit the unique identifier to a server system, as disclosed by Spencer, such modification would enable the mobile computing device to establish a secure connection with the medical device using the medical device's information, for example, as a secret shared between the mobile computing device and the medical device. The combination of Fenner, Silva Pinto and Spencer does not explicitly disclose the following limitation taught by Kim: […] together with the encrypted challenge (Kim, ¶153: “… the user terminal 200 may transmit the generated OTP to the service providing server 100. The user terminal 200 may transmit the module identification information associated with the OTP … to the service providing server 100 together with the OTP”). It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention, to modify the teachings of the combination of Fenner, Silva Pinto and Spencer to incorporate the functionality of the user terminal to transmit a generated OTP together with a module identification information associated with the OTP to a service providing server, as disclosed by Kim, such modification would enable the system to verify the authenticity of both the user terminal and the server to protect the service provider from a security breach. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to MATTHIAS HABTEGEORGIS whose telephone number is (571)272-1916. The examiner can normally be reached M-F 8am-5pm ET. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, William R. Korzuch can be reached at (571)272-7589. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /MATTHIAS HABTEGEORGIS/Examiner, Art Unit 2491
Read full office action

Prosecution Timeline

Nov 08, 2024
Application Filed
Apr 02, 2026
Non-Final Rejection mailed — §103, §112
Jul 02, 2026
Response Filed
Aug 18, 2026
Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12739275
SYSTEM AND METHOD FOR DETECTION AND MITIGATION OF NETWORK-BASED COMPUTING THREATS
2y 1m to grant Granted Sep 15, 2026
Patent 12711265
CENTRALIZED AND DECENTRALIZED DATA PROTECTION THROUGH REDACTION
3y 10m to grant Granted Aug 18, 2026
Patent 12712848
FLOW BASED BREAKOUT OF FIREWALL USAGE BASED ON TRUST
3y 5m to grant Granted Aug 18, 2026
Patent 12706939
Prioritizing Vulnerability Based on Application Security Context
3y 7m to grant Granted Aug 11, 2026
Patent 12671714
LIMITING THE ABILITY OF RANSOMWARE TO SPREAD WITHIN A DATA CENTER
3y 2m to grant Granted Jun 30, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
79%
Grant Probability
96%
With Interview (+16.7%)
3y 0m (~1y 2m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 118 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month