Prosecution Insights
Last updated: August 18, 2026
Application No. 18/867,030

SOFTWARE TOOL AND METHOD FOR ANALYSIS OF CYBERSECURITY VULNERABILITIES

Final Rejection §101§112
Filed
Nov 19, 2024
Priority
Jun 20, 2022 — provisional 63/353,769 +1 more
Examiner
ALI, AFAQ
Art Unit
2434
Tech Center
2400 — Computer Networks
Assignee
Siemens Aktiengesellschaft
OA Round
2 (Final)
89%
Grant Probability
Favorable
3-4
OA Rounds
8m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 89% — above average
89%
Career Allowance Rate
126 granted / 141 resolved
+31.4% vs TC avg
Moderate +12% lift
Without
With
+11.7%
Interview Lift
resolved cases with interview
Typical timeline
2y 5m
Avg Prosecution
24 currently pending
Career history
172
Total Applications
across all art units

Statute-Specific Performance

§101
8.8%
-31.2% vs TC avg
§103
50.6%
+10.6% vs TC avg
§102
5.1%
-34.9% vs TC avg
§112
22.5%
-17.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 141 resolved cases

Office Action

§101 §112
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Detailed Action Claims 1, 2,3, 5, 6, 10, 14, and 16 are amended Claims 4, 17, and 18 are cancelled Claims 1-3, 5-16, 19, and 20 are pending Priority This application is a 371 of PCT/US2023/025721 06/20/2023 which claims the benefit of PRO 63/353,769 06/20/2022. Therefore, the effective filing date of this application is 06/20/2022. Response to Arguments Applicant’s arguments filed on 05/05/2026 have been fully considered. With respect to the objection to the drawings. The objection has not been overcome due to Applicant not filing an amended replacement drawing sheet or amending the specification to include recitation of reference number 220 of figure 2. With respect to the objection to the abstract. The objection has not been overcome due to Applicant not filing a separate abstract that commences on a separate sheet in accordance with 37 CFR 1.52(b)(4) and 1.72(b). With respect to claim objection for claims 10, and 17-20 the objection has only been overcome for claims 17 and 18 due to these claims being cancelled. Examiner suggests amending the claims as suggested to overcome the objections. With respect to the USC 112(b) rejection for claims 5-7, and 13-20 the rejection has been overcome for claims 5, 6, 14, and 16. However, claims 13-15 recite the limitation " the AI-based sequential decision-making optimization". However, claim 1 is now amended to recite of “an iterative AI-based sequential decision-making optimization”. Examiner suggests amending claims 13-15 to recite of “the iterative AI-based sequential decision-making optimization” to overcome the 112(b) rejection. With respect to the USC 101 abstract rejection Applicant has argued that the rejection is improper. Examiner respectfully disagrees. With respect to the arguments of Step 2A Prong One, Applicant has argued that the claims are not directed to a mental process. Examiner respectfully disagrees. The claim currently recites of storing information relating to cybersecurity in a cyberattack information layer, the cyberattack layer comprising information about a topology and devices in the engineered system from a computer network perspective, and information on an amount of effort required to carry out possible attacks affecting each device or communication link in the engineered system; performing a functional simulation of the operation of the engineered system, based in part on the information stored in the cyberattack information layer; and performing an iterative AI-based sequential decision-making optimization between the functional simulation and the cyberattack information layer to identify a sequence of attacker steps constituting a most impactful cyberattack vector with respect to a key performance indicator (KPI) relating to the operation of the engineered system. The limitation of storing information relating to cybersecurity in a cyberattack information layer is simply directed towards data storage regardless what information is stored in the cyberattack information layer. A user can manually store information relating to cybersecurity. As for the limitation of performing a functional simulation of the operation of the engineered system, based in part on the information stored in the cyberattack information layer. This limitation is simply directed towards data analysis, the functional simulation is analyzing the engineered system using the information stored. A user can manually perform functional simulation representative of an engineered system. As for the limitation performing an iterative AI-based sequential decision-making optimization between the functional simulation and the cyberattack information layer to identify a sequence of attacker steps constituting a most impactful cyberattack vector with respect to a key performance indicator (KPI) relating to the operation of the engineered system is simply identifying cyberattack vectors using “AI-based” sequential decision making optimization. Broadly reciting “AI-based” does not overcome the 101 abstract rejection when all the “AI” is doing is identifying attack vectors which can be done by a user of the engineered system using the functional simulation and cyberattack information. Even taken as a whole the entire claim is simply storing data, analyzing data, and identifying cyberattack vectors based on the data. Therefore, the claim is directed towards a mental process. As for the arguments for Step 2A prong 2. The claim limitations do not integrate the claim into a practical limitation. Simply reciting “identify a sequence of attacker steps constituting a most impactful cyberattack vector with respect to a key performance indicator (KPI) relating to the operation of the engineered system” does not integrate into a practical application. The claim does not recite what the identified cyberattack vector is used for. Just by identifying the sequence of attacker steps constituting a most impactful cyberattack vector does not stop or mitigate the attacker or threat. With respect to the arguments for step 2B. The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. The recitation of a cybersecurity information layer is just a data storage layer that stores data pertaining to cybersecurity. A sequential decision making optimization framework is simply an algorithm to identify a sequence of attacker steps. Therefore, the claim is directed to an abstract idea. The claim is not patent eligible. With respect to the arguments of USC 103 rejection for claims 1-9, 13, and 15-20. The arguments are persuasive and the rejection is withdrawn. Drawings The drawings are objected to as failing to comply with 37 CFR 1.84(p)(5) because they include the following reference character(s) not mentioned in the description: Figure 2 reference number 220. Corrected drawing sheets in compliance with 37 CFR 1.121(d), or amendment to the specification to add the reference character(s) in the description in compliance with 37 CFR 1.121(b) are required in reply to the Office action to avoid abandonment of the application. Any amended replacement drawing sheet should include all of the figures appearing on the immediate prior version of the sheet, even if only one figure is being amended. Each drawing sheet submitted after the filing date of an application must be labeled in the top margin as either “Replacement Sheet” or “New Sheet” pursuant to 37 CFR 1.121(d). If the changes are not accepted by the examiner, the applicant will be notified and informed of any required corrective action in the next Office action. The objection to the drawings will not be held in abeyance. Specification The abstract of the disclosure is objected to because the abstract of the disclosure does not commence on a separate sheet in accordance with 37 CFR 1.52(b)(4) and 1.72(b). A corrected abstract of the disclosure is required and must be presented on a separate sheet, apart from any other text. See MPEP § 608.01(b). Claim Objections Claims 1 and 13-15 are objected to because of the following informalities: these claims recite of the acronym “AI”. For the purpose of examination examiner is interpreting this limitation as artificial intelligence (AI). Appropriate correction is required. Claim 10 is objected to because of the following informalities: this application recites of the acronym netJSON. For the purpose of examination examiner is interpreting this limitation as net JavaScript Object Notation (netJSON). Appropriate correction is required. Claims 19-20 recite of “The system”. However, independent claim 16 recites of “A computer-based system”. Examiner suggests amending claims 17-20 to recite “The computer-based system”. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. Claims 1-3, 5-16, 19, and 20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claims 1 and 16 recite the limitation “the operation”. There is insufficient antecedent basis for this limitation in the claim. For the purpose of examination examiner is interpreting this limitation as “an operation”. Appropriate correction is required. Claims 2, 3, 5-15, 19, and 20 depend on claims 1 and 16. Therefore, they also inherit the rejection. Claim 1 recites the limitation “the cyberattack layer”. There is insufficient antecedent basis for this limitation in the claim. For the purpose of examination examiner is interpreting this limitation as “the cyberattack information layer”. Appropriate correction is required. Claims 2, 3, 5-15 depends on claim 1. Therefore, they also inherit the rejection. Claims 13-15 recites the limitation " the AI-based sequential decision-making optimization". There is insufficient antecedent basis for this limitation in the claim. For the purpose of examination examiner is interpreting this limitation as “… the iterative AI-based sequential decision-making optimization”. Appropriate correction is required. The following is a quotation of 35 U.S.C. 112(d): (d) REFERENCE IN DEPENDENT FORMS.—Subject to subsection (e), a claim in dependent form shall contain a reference to a claim previously set forth and then specify a further limitation of the subject matter claimed. A claim in dependent form shall be construed to incorporate by reference all the limitations of the claim to which it refers. Claim 2 is rejected under 35 U.S.C. 112(d) or pre-AIA 35 U.S.C. 112, 4th paragraph, as being of improper dependent form for failing to further limit the subject matter of the claim upon which it depends, or for failing to include all the limitations of the claim upon which it depends. Claim 2 recites of “wherein the cyberattack information layer comprises information about potential cybersecurity attacks that may be performed affecting a device or communication link of the engineered system”. However, claim 1 already recites of this limitation. Claim 1 recites “method for identifying and analyzing potential cybersecurity threats in an engineered system comprising: storing information relating to cybersecurity in a cyberattack information layer, the cyberattack layer comprising information about a topology and devices in the engineered system from a computer network perspective”. Applicant may cancel the claim, amend the claim to place the claim in proper dependent form, rewrite the claim in independent form, or present a sufficient showing that the dependent claim complies with the statutory requirements. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-3, 5-16, 19, and 20 are rejected under 35 U.S.C. 101 because they directed to an abstract idea. Claim 1 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. The claim recites of a method for identifying and analyzing potential cybersecurity threats in an engineered system comprising: storing information storing information relating to cybersecurity in a cyberattack information layer, the cyberattack layer comprising information about a topology and devices in the engineered system from a computer network perspective, and information on an amount of effort required to carry out possible attacks affecting each device or communication link in the engineered system; performing a functional simulation of the operation of the engineered system, based in part on the information stored in the cyberattack information layer; and performing an iterative AI-based sequential decision-making optimization between the functional simulation and the cyberattack information layer to identify a sequence of attacker steps constituting a most impactful cyberattack vector with respect to a key performance indicator (KPI) relating to the operation of the engineered system. The limitation of identifying and analyzing potential cybersecurity threats in an engineered system, as drafted, is a process that, under its broadest reasonable interpretation, covers steps that can be performed in the mind. A user can manually identify and analyze potential cybersecurity threats. The limitation of storing information storing information relating to cybersecurity in a cyberattack information layer, the cyberattack layer comprising information about a topology and devices in the engineered system from a computer network perspective, and information on an amount of effort required to carry out possible attacks affecting each device or communication link in the engineered system, as drafted, is a process that, under its broadest reasonable interpretation, covers steps that can be performed in the mind. A user can manually store information relating to cybersecurity in a cybersecurity information layer. The limitation of performing a functional simulation of the operation of the engineered system, based in part on the information stored in the cyberattack information layer, as drafted, is a process that, under its broadest reasonable interpretation, covers steps that can be performed in the mind. A user can manually perform functional simulation representative of an engineered system. The limitation of performing an iterative AI-based sequential decision-making optimization between the functional simulation and the cyberattack information layer to identify a sequence of attacker steps constituting a most impactful cyberattack vector with respect to a key performance indicator (KPI) relating to the operation of the engineered system, as drafted, is a process that, under its broadest reasonable interpretation, covers steps that can be performed in the mind. A user can manually perform sequential decision-making optimization to identify a most impactful cyberattack vector with respect to a key performance indicator (KPI) of interest. This judicial exception is not integrated into a practical application. The claim recites of a limitation of “performing an iterative AI-based sequential decision-making optimization between the functional simulation and the cyberattack information layer to identify a sequence of attacker steps constituting a most impactful cyberattack vector with respect to a key performance indicator (KPI) relating to the operation of the engineered system”. This limitation is used to generally apply AI based sequential decision-making optimization to identify a most impactful cyberattack vector without placing any limits on how the “optimization” functions and what is the outcome of identifying a most impactful cyberattack vector. Merely identifying a most impactful cyberattack vector does not integrate the abstract idea into a practical application. Accordingly, this additional element does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. The claim is directed to an abstract idea. The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. The claim is directed to an abstract idea. The claim is not patent eligible. Claim 2 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. This claim recites of wherein the cyberattack information layer comprises information about potential cybersecurity attacks that may be performed affecting a device or communication link of the engineered system. Therefore, the limitations of this claim, as drafted, is a process that, under its broadest reasonable interpretation, covers steps that can also be performed in the mind. A user can manually determine information about potential cybersecurity attacks that may be performed. Claim 3 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. This claim recites of wherein the cyberattack information layer further comprises information about measures of an associated effort required for implementation of each of the potential cybersecurity attacks affecting a communication link. Therefore, the limitations of this claim, as drafted, is a process that, under its broadest reasonable interpretation, covers steps that can also be performed in the mind. A user can manually determine information about measures of an associated effort required for implementation of each of the potential cybersecurity attacks. Claim 5 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. This claim recites of wherein the communication link is a logical link between a first device and a second device. Therefore, the limitations of this claim, as drafted, is a process that, under its broadest reasonable interpretation, covers steps that can also be performed in the mind. A user can manually determine a communication links is a logical link. Claim 6 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. This claim recites of wherein the communication link is a physical network link between a first device and a second device. Therefore, the limitations of this claim, as drafted, is a process that, under its broadest reasonable interpretation, covers steps that can also be performed in the mind. A user can manually determine a communication links is a physical network link. Claim 7 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. This claim recites of wherein the physical network link connects the first device and a router. Therefore, the limitations of this claim, as drafted, is a process that, under its broadest reasonable interpretation, covers steps that can also be performed in the mind. A user can manually determine a physical network link connects the first device and a router. Claim 8 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. This claim recites of iteratively performing the sequential decision-making optimization to produce a sequence of attacker steps that generates a maximum disruption to operation of the engineered system. Therefore, the limitations of this claim, as drafted, is a process that, under its broadest reasonable interpretation, covers steps that can also be performed in the mind. A user can manually iteratively perform sequential decision-making optimization to produce a sequence of attacker steps that generates a maximum disruption to operation of the engineered system. Claim 9 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. This claim recites of measuring and optimizing the sequential decision-making optimization based on configurable key performance indicators (KPIs) associated with operation of the engineered system. Therefore, the limitations of this claim, as drafted, is a process that, under its broadest reasonable interpretation, covers steps that can also be performed in the mind. A user can manually measure and optimize the sequential decision-making optimization based on configurable key performance indicators. Claim 10 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. This claim recites of storing in the cyberattack information layer, information about the engineered system's topology encoded as netJSON format. Therefore, the limitations of this claim, as drafted, is a process that, under its broadest reasonable interpretation, covers steps that can also be performed in the mind. A user can manually store in the cybersecurity information layer, information about the engineered system's topology encoded as netJSON format. Claim 11 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. This claim recites of wherein a device in the engineered system's topology adversary actions are encoded in layers including an exposure layer, an exploitability layer and an end-effect layer. Therefore, the limitations of this claim, as drafted, is a process that, under its broadest reasonable interpretation, covers steps that can also be performed in the mind. A user can manually encode engineered system's topology adversary actions in layers including an exposure layer, an exploitability layer and an end-effect layer. Claim 12 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. This claim recites of wherein a communication link in the engineered system's topology adversary actions are encoded in layers including an exposure layer and an end-effect layer. Therefore, the limitations of this claim, as drafted, is a process that, under its broadest reasonable interpretation, covers steps that can also be performed in the mind. A user can manually determine communication link in the engineered system's topology adversary actions are encoded in layers including an exposure layer and an end-effect layer. Claim 13 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. This claim recites of considering during the AI-based sequential decision-making optimization, an associated effort required for each possible action taken by an attacker. Therefore, the limitations of this claim, as drafted, is a process that, under its broadest reasonable interpretation, covers steps that can also be performed in the mind. A user can manually determine an associated effort required for each possible action taken by an attacker. Claim 14 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. This claim recites of considering during the AI-based sequential decision-making optimization, an attacker profile representative of a skill level of an attacker. Therefore, the limitations of this claim, as drafted, is a process that, under its broadest reasonable interpretation, covers steps that can also be performed in the mind. A user can manually determine an attacker profile representative of the skill level of an attacker. Claim 15 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. This claim recites of wherein the AI-based sequential decision-making optimization is performed using a Monte Carlo Tree Search. Therefore, the limitations of this claim, as drafted, is a process that, under its broadest reasonable interpretation, covers steps that can also be performed in the mind. A user can manually determine AI-based sequential decision-making optimization is performed using a Monte Carlo Tree Search. Claim 16 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Furthermore, this claim recites of features similar to that of claim1. Therefore claim 16 is rejected in a similar manner as in the rejection of claim 1. As for the limitation of perform an artificial intelligence (AI) based sequential decision-making optimization to identify a sequence of attacker actions. This limitation as drafted, is a process that, under its broadest reasonable interpretation, covers steps that can also be performed in the mind. A user can manually perform an artificial intelligence (AI) based sequential decision-making optimization to identify a sequence of attacker actions. If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic statement such as “computer-based system”, then it falls within the “Mental Processes” grouping of abstract ideas. Accordingly, the claim recites an abstract idea. This judicial exception is not integrated into a practical application. The claim recites of a limitation of “performing an iterative AI-based sequential decision-making optimization between the functional simulation and the cyberattack information layer to identify a sequence of attacker steps constituting a most impactful cyberattack vector with respect to a key performance indicator (KPI) relating to the operation of the engineered system”. This limitation is used to generally apply AI based decision-making optimization to identify a sequence of attacker actions without placing any limits on how the “optimization” functions and what is the outcome of identifying a sequence of attacker actions. Merely identifying a sequence of attacker actions does not integrate the abstract idea into a practical application. Accordingly, this additional element does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. The claim is directed to an abstract idea. The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. In particular, the claim only recites one additional element of computer processor implemented system. The “computer processor” recited at a high-level of generality (i.e., as a generic computer processor performing the method) such that it amounts no more than mere instructions to apply the exception using a generic computer processor. Mere instructions to apply an exception using a generic computer processor cannot provide an inventive concept. The claim is not patent eligible. Claim 19 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. This claim recites of wherein the AI-based sequential decision-making optimization is performed using a Monte Carlo Tree Search. Therefore, the limitations of this claim, as drafted, is a process that, under its broadest reasonable interpretation, covers steps that can also be performed in the mind. A user can manually implement AI-based sequential decision-making optimization using a Monte Carlo Tree Search. Claim 20 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. This claim recites of for each possible attack affecting a device or communication link of the engineered system, computing a measure of associated effort required to carry out each possible attack. Therefore, the limitations of this claim, as drafted, is a process that, under its broadest reasonable interpretation, covers steps that can also be performed in the mind. A user can manually determine for each possible attack affecting a device or communication link of the engineered system, a measure of associated effort required to carry out each possible attack. The dependent claims 2, 3, 5-15, and 19-20 are directed to abstract ideas and do not include additional elements that are sufficient to amount to significantly more than the judicial exception. This judicial exception is not integrated into a practical application. Therefore the claims are not patent eligible. Allowable Subject Matter Clams 1-3, 5-16, 19, and 20 are considered allowable once all rejections and objections have been overcome. A reason for allowance will be stated in a Notice of Allowance. Pertinent Art The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure. WEI (US-20230315851-A1): This prior art teaches of method for detecting false data injection attacks (FDIAs) on a condition-based predictive maintenance (CBPM) system includes: collecting sensor data from sensors monitoring components of a system maintained by the CBPM system to extract features for a cyberattack detection model and gathering historical data of the system to build a cyberattack knowledge base about the system; combining the sensor data and the historical data to train the cyberattack detection model; using a graphical Bayesian network model to capture domain knowledge and condition-symptom relationships between the sensor-monitored components and the sensors; and based on the cyberattack detection model and the Bayesian network model, detecting the FDIAs on the CBPM system. CRABTREE (US-20220060511-A1): This prior art teaches of system and method for automated cybersecurity defensive strategy analysis that predicts the evolution of new cybersecurity attack strategies and makes recommendations for cybersecurity improvements to networked systems based on a cost/benefit analysis. The system and method use machine learning algorithms to run simulated attack and defense strategies against a model of the networked system created using a directed graph. Recommendations are generated based on an analysis of the simulation results against a variety of cost/benefit indicators. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to AFAQ ALI whose telephone number is (571)272-1571. The examiner can normally be reached Mon - Fri 7:30am - 5:30pm EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, ALI SHAYANFAR can be reached at (571) 270-1050. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /A.A./ 07/29/2026 /AFAQ ALI/Examiner, Art Unit 2434 /NOURA ZOUBAIR/Primary Examiner, Art Unit 2434
Read full office action

Prosecution Timeline

Nov 19, 2024
Application Filed
Feb 05, 2026
Non-Final Rejection mailed — §101, §112
May 05, 2026
Response Filed
Aug 03, 2026
Final Rejection mailed — §101, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12689649
DETERMINING ADDITIONAL SIGNALS FOR DETERMINING CYBERSECURITY RISK
1y 12m to grant Granted Jul 21, 2026
Patent 12665926
System And Methods Of Defense Against DDoS Attacks For Applications On A Multi-Substrate Multi-Ingress Shared Infrastructure With Multiple Cloud Architectures
1y 9m to grant Granted Jun 23, 2026
Patent 12639404
Authorization of Access Rights Licenses
2y 2m to grant Granted May 26, 2026
Patent 12627679
CYBER SECURITY SYSTEM APPLYING NETWORK SEQUENCE PREDICTION USING TRANSFORMERS
2y 3m to grant Granted May 12, 2026
Patent 12585791
ENCRYPTED COMMUNICATION METHOD AND ELECTRONIC DEVICE
3y 7m to grant Granted Mar 24, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
89%
Grant Probability
99%
With Interview (+11.7%)
2y 5m (~8m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 141 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month