Prosecution Insights
Last updated: October 04, 2026
Application No. 18/873,694

METHOD, APPARATUS AND SYSTEM FOR MANAGING CLUSTER ACCESS PERMISSION

Non-Final OA §103
Filed
Dec 10, 2024
Priority
Sep 01, 2022 — CN 202211064945.0 +1 more
Examiner
ULLAH, SHARIF E
Art Unit
2495
Tech Center
2400 — Computer Networks
Assignee
Jingdong Technology Information Technology Co. Ltd.
OA Round
1 (Non-Final)
85%
Grant Probability
Favorable
1-2
OA Rounds
8m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 85% — above average
85%
Career Allowance Rate
393 granted / 464 resolved
+26.7% vs TC avg
Strong +22% interview lift
Without
With
+21.5%
Interview Lift
resolved cases with interview
Typical timeline
2y 6m
Avg Prosecution
23 currently pending
Career history
481
Total Applications
across all art units

Statute-Specific Performance

§101
13.6%
-26.4% vs TC avg
§103
60.4%
+20.4% vs TC avg
§102
6.8%
-33.2% vs TC avg
§112
11.9%
-28.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 464 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Information Disclosure Statement The information disclosure statement (IDS) submitted on 12/04/2025 & 02/03/2025 are in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-6 are rejected under 35 U.S.C 103 as being unpatentable over Sivaswamy et al. (US 2023/0188531), hereon referred to as Siv, in view of Miriyala et al. (US 2023/0104568), and hereon referred to as Miri. In regards to claims 13, 20 & 23, Siv discloses acquiring an access permission policy of a first cluster; the access permission policy including access permission information between the first cluster and one or more second clusters associated therewith (The first dependency chain matrix 250 may be a dependency chain matrix which compiles, converges, aggregates or otherwise puts together the service matrices provided to the first ingress computer system 16 for the first cluster; Paragraphs 0025-0030); managing the access permission between the first cluster and the second cluster associated therewith by using the updated access permission policy (looking up, by the one or more processors of the computer system, in the inter cluster label matrix in response to an inter cluster service request received that requests a service in the different cluster, and a step 460 of validating, by the one or more processors of the computer system, an inter cluster authorization for the inter cluster service request based on the inter cluster label matrix; Paragraphs 0040-0045). However, Siv does not disclose updating, in a case where it is monitored that resources of any of the associated second clusters have changed, the access permission information corresponding to the second cluster that is included in the access permission policy in accordance with a change result of the resources of the second cluster. In an analogous art Miri discloses updating, in a case where it is monitored that resources of any of the associated second clusters have changed, the access permission information corresponding to the second cluster that is included in the access permission policy in accordance with a change result of the resources of the second cluster ( SDN controller manager 303-1 watches API server 300-1 of workload cluster 930-1 for changes on native resources of the orchestration platform for workload cluster 930-1. SDN controller manager 303-1 also watches custom API server 301 for central cluster 902. This is known as a “double watch”; Paragraphs 0280-0290). At the time before the effective filing date of the invention, it would have been obvious to the one with ordinary skill in the art to combine the teachings disclosed by Siv, with the teachings disclosed by Miri regarding updating, in a case where it is monitored that resources of any of the associated second clusters have changed, the access permission information corresponding to the second cluster that is included in the access permission policy in accordance with a change result of the resources of the second cluster. The suggestion/motivation of the combination would have been to provide additional security in cloud native networking (Miri; Paragraph 0002). In regards to claims 14 & 21, Siv discloses updating, in a case where it is monitored that resources of the first cluster have changed, the access permission information corresponding to the first cluster that is included in the access permission policy in accordance with a change result of the resources of the first cluster; managing the access permission between the first cluster and the second cluster associated therewith by using the updated access permission policy (the receiving module 61 may be configured to receive an updated dependency chain matrix from service endpoints based on triggering events; an updated dependency chain matrix from one of the plurality of service end points when a triggering event occurs. For example, the triggering event may be that the one of the plurality of service end points restarts, or that there is a change in service end points hosted by the one of the plurality of service end points; Paragraphs 0034-0042). In regards to claim 15, Miri discloses adding an annotation including a cluster identifier of the second cluster to the access permission information corresponding to the second cluster; indicating a case where the resources of the second cluster have changed by means of the cluster identifier included in the annotation, so as to limit the access permission of the first cluster to access the second cluster by combining the access permission policy with the annotation in a case where the first cluster accesses the second cluster (Custom resources may have namespace scope for different clusters. Custom resources that are associated with one of workload clusters 930 will have a corresponding namespace created in central cluster 902 along with a cluster identifier (e.g., cluster name or a unique identifier), with custom resources created under this namespace; SDN controller managers 303 validate and allow users or agents to only use custom resources for SDN architecture configuration that belong to a namespace that is associated with the workload cluster; Paragraphs 0199; 0285-0290). In regards to claim 16, Miri discloses acquiring configuration information of the first cluster; determining cluster information of the one or more second clusters associated with the first cluster in accordance with the configuration information; acquiring preset access permission information between the first cluster and the one or more second clusters, and generating the access permission policy of the first cluster based on the preset access permission information ( LCM will pick up the custom resource name for the corresponding SDN controller manager 303 as the cluster name for a workload cluster; Paragraphs 0287-0308). In regards to claim 17, Miri discloses parsing the preset access permission information from a preset configuration file, and/or parsing the preset access permission information from custom permission data included in the first cluster, wherein the custom permission data is obtained based on extension of native permission data of the cluster (configuration resources also include custom resources, which are used to extend the Kubernetes platform by defining an application program interface (API) that may not be available in a default installation of the Kubernetes platform; Paragraphs 0101; 0323). In regards to claim 18, Siv discloses performing the steps of acquiring the access permission policy of the first cluster and updating the access permission policy by using the permission controller (the ingress computer system 16 may include a module structure 60 that includes a receiving module 61, a converging module 62, and a sharing module 63, a validating module 64, and a label generating module 65; Paragraphs 0030-0035). In regards to claim 19, Miri discloses starting a first controller and a second controller for the first cluster to which the permission controller belongs by using the permission controller; monitoring a resource change of the first cluster by using the first controller; monitoring a resource change of the one or more second clusters associated with the first cluster by using the second controller (SDN controller manager 303-1 watches API server 300-1 of workload cluster 930-1 for changes on native resources of the orchestration platform for workload cluster 930-1. SDN controller manager 303-1 also watches custom API server 301 for central cluster 902. This is known as a “double watch”.; Paragraphs 0280-0230). In regards to claim 22, Siv discloses a plurality of communicatively connected clusters; wherein the apparatus is configured in the plurality of communicatively connected clusters (The ingress computer system 16 is shown connected via the network(s) 50 to the external user 26 and the external service 28, as well as other clusters; Paragraphs 0031). Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to SHARIF E ULLAH whose telephone number is (571)272-5453. The examiner can normally be reached Mon-Fri 7:00-5:30. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Farid Homayounmehr can be reached at 571-272-3739. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /SHARIF E ULLAH/Primary Examiner, Art Unit 2495
Read full office action

Prosecution Timeline

Dec 10, 2024
Application Filed
Jul 15, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12739108
BYPASSING TECHNIQUE TO ENABLE DIRECT ACCESS TO SNAPSHOT DATA IN OBJECT STORE
3y 0m to grant Granted Sep 15, 2026
Patent 12739111
KEY UPDATE METHOD, NETWORK ELEMENT, USER EQUIPMENT, AND STORAGE MEDIUM
2y 7m to grant Granted Sep 15, 2026
Patent 12711254
SECURE COMPUTING SYSTEM
1y 7m to grant Granted Aug 18, 2026
Patent 12695928
VIDEO TRANSMISSION METHOD, VIDEO TRANSMISSION APPARATUS, ELECTRONIC DEVICE AND READABLE MEDIUM
3y 3m to grant Granted Jul 28, 2026
Patent 12695605
METHOD AND APPARATUS FOR A SOFTWARE DEFINED NETWORK
2y 11m to grant Granted Jul 28, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
85%
Grant Probability
99%
With Interview (+21.5%)
2y 6m (~8m remaining)
Median Time to Grant
Low
PTA Risk
Based on 464 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month