DETAILED ACTION
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
This Office Action is in response to the communication filed on 08/20/2026.
Claims 21-26 have been added.
Claims 3, 7, 11, 15, 19, and 20 have been cancelled.
Claims 1, 8, 9, 12-14, 16, and 17 have been amended.
Claims 1, 2, 4-6, 8, 9, 10, 12-14, 16-18, and 21-26 are pending for consideration.
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 08/20/2026 has been entered.
Response to Arguments
Regarding claim 1, Applicant argues that Kunchakarra does not disclose "storing context information about specific entitlements in a knowledge base" and "retrieving context information relating to the access entitlement stored in the knowledge base"; in contrast, Kunchakarra discloses a receiving user feedback to report inaccuracies and update training datasets to retrain the model, wherein the present application utilizes the localized knowledge base to remove the need to train the model on the contextual information. Examiner disagrees. Kunchakarra teaches the extracted contents from the one or more data sources include one or more security policies (Col 6 lines 29-51) and periodic reviews, monitoring, and updates to the security policies and other content of the data sources (Col 49 lines 54-67 – Col 50 lines 1-3). Kunchakarra teaches retrieving data such as job role descriptions, key responsibilities, etc. from a data source that is internal or external to an organization (Col 64 lines 32-56; Col 6 lines 33-35; Col 74 lines 24-25).
Applicant argues that the data retrieved by Kunchakarra relates to contextual inputs to determine organizational structures, roles, and responsibilities. Applicant argues that the data retrieved in the present application is "capability-specific context information relating to a technical access entitlement". Examiner disagrees. The Specification of the present application teaches the knowledge base contains context and additional information about a specific organization, industry, etc. and metadata (e.g. roles, organization specific information, industry specific information) (paragraph 0027). There is no support for "capability-specific context information relating to a technical access entitlement" in the Specification or Claims, and under its broadest reasonable interpretation includes organizational structures, roles, and responsibilities.
Applicant argues that Kunchakarra does not teach "generating the description of the access entitlement using the LLM based on the retrieved context information and the prompt" because Kunchakarra generates a "job description" for a human user or principal for the purpose of configuring access controls and verifying compliance. Examiner disagrees. The present application generates the description of the access entitlement based on organization specific metadata from a knowledge base (paragraph 0027) and a prompt to specify rules for the LLM to follow when generating the descriptions (paragraph 0029). Kunchakarra generates job descriptions based on organization specific metadata from one or more internal or external data sources (Col 64 lines 32-56) and a prompt generated using prompt engineering. The present application utilizes the method of Kunchakarra to generate a description for access entitlements which is an intended use of Kunchakarra's LLM.
Applicant argues that Maschmeyer in view of Kunchakarra does not teach "fine-tuning the LLM using training data, the training data including a plurality of input/output pairs" to translate raw computer access credentials into natural language capability explanations . Examiner disagrees. Maschmeyer teaches fine-tuning a trained ML model using input that is closely related to the inputs used to train the models initially (Col 8 lines 33-40) and output from previously fine-tuned ML models (Col 7 lines 65-67 Col 8 lines 1-5). Fine-tuning a LLM using training data that may be user provided or historical, is well-known to POSITA. Furthermore, "to translate raw computer access credentials into natural language capability explanations" is an intended use of the ML model of Maschmeyer.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 21, 23, and 25 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
The term “near-duplicate” in claims 21, 23, and 25 is a relative term which renders the claim indefinite. The term “near-duplicate” is not defined by the claim, the specification does not provide a standard for ascertaining the requisite degree, and one of ordinary skill in the art would not be reasonably apprised of the scope of the invention.
Claims 22, 24, and 26 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
The term “measuring a closeness” in claims 22, 24, and 26 is a relative term which renders the claim indefinite. The term “measuring a closeness” is not defined by the claim, the specification does not provide a standard for ascertaining the requisite degree, and one of ordinary skill in the art would not be reasonably apprised of the scope of the invention.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 2, 4-6, 8, 9, 10, 12-14, 16-18 are rejected under 35 U.S.C. 103 as being unpatentable over Maschmeyer et al. (U.S. 12,468,878) (hereinafter Maschmeyer) in view of Kunchakarra et al. (U.S. 12,541,726) (hereinafter Kunchakarra).
Regarding claims 1, 9, and 17, Maschmeyer teaches an automated access description generation system, comprising:
a processor; a non-transitory, computer-readable storage medium (Maschmeyer: see Col 26 lines 57-62, “In some embodiments, and as described further herein, the e-commerce platform 100 may be implemented through a processing facility. Such a processing facility may include a processor and a memory. The processor may be a hardware processor. The memory may be and/or may include a non-transitory computer-readable medium”, including computer instructions for:
receiving a request to generate a description (Maschmeyer: see Col 20 lines 54-58, "The UI 600 may as in the example shown in FIG. 3A, include an autofill option 616 that may be selected to cause the text-editor 550 to assist in completion of the generated description 612, as will be discussed further below with respect to FIGS. 3C and 3D");
providing a prompt to a large language model models (LLM), the prompt specifying one or more rules for the LLM to follow when generating the description for the access entitlement (Maschmeyer: see Col 2 lines 33-40, "...generate a prompt to a large language model (LLM) to generate a description of an object, the prompt including one or more object attributes to include in the generated description, and also including an instruction for the LLM to annotate, according to a defined format, any portions of the generated description that include unsubstantiated information; provide the prompt to the LLM..");
generating the description of the access entitlement using the LLM based on the prompt (Maschmeyer: see Col 36 claim 1 lines 12-14, "provide the prompt to the LLM; causing the LLM to generate the generated description; receive the generated description"; Kunchakarra: see Col 64 lines 50-56, "The processor, in association with the large language models, generates the one or more job descriptions based on at least one of the organizational structure, the one or more roles, the one or more responsibilities, the one or more hierarchical relationships, the one or more access levels, the one or more service actions, and the one or more departments");
fine-tuning the LLM using training data (Maschmeyer: see Col 8 lines 33-40, "In some examples, a trained ML model may be fine-tuned, meaning that the values of the learned parameters may be adjusted slightly in order for the ML model to better model a specific task. Fine-tuning of a ML model typically involves further training the ML model on a number of data samples (which may be smaller in number/cardinality than those used to train the model initially) that closely target the specific task"), the training data including a plurality of input/output pairs (Maschmeyer: see Col 7 lines 45-54, "The training data may be a subset of a larger data set. For example, a data set may be split into three mutually exclusive subsets: a training set, a validation (or cross-validation) set, and a testing set. The three subsets of data may be used sequentially during ML model training. For example, the training set may be first used to train one or more ML models, each ML model, e.g., having a particular architecture, having a particular training procedure, being describable by a set of model hyperparameters, and/or otherwise being varied from the other of the one or more ML models"; Col 7 lines 65-67 Col 8 lines 1-5, "Once such a trained ML model is obtained (e.g., after the hyperparameters have been adjusted to achieve a desired level of performance), a third step of collecting the output generated by the trained ML model applied to the third subset (the testing set) may begin. The output generated from the testing set may be compared with the corresponding desired target values to give a final assessment of the trained ML model's accuracy"); and
presenting, over a graphical user interface, the generated description of the access entitlement (Maschmeyer: see Col 2 lines 43-44, "...and present the generated description for display via a user device").
However, Maschmeyer does not explicitly teach an access entitlement in an identity governance and administration system; storing context information about specific entitlements in a knowledge base.
retrieving context information relating to the access entitlement stored in the knowledge base; providing context information with the prompt to the large language model; and generating the description of the access entitlement using the LLM based on the retrieved context information for an access entitlement in an identity governance and administration.
Nevertheless, Kunchakarra-which is in the same field of endeavor- teaches
storing context information about specific entitlements in a knowledge base (Kunchakarra: see Col 49 lines 54-67 – Col 50 lines 1-3, “The system also continuously looks for any updates to the description (e.g., job role description, service task description, spatial and temporal information). The system may specifically look for any updates such as an event related to accessing the description and/or modifying the description (e.g., spatial and temporal information)... The system may also specifically look for any changes to the description”);
retrieving context information relating to the access entitlement stored in the knowledge base (Kunchakarra: see Col 75 lines 64-67, "extracting one or more contents related to an organization from one or more data sources based on one or more job role names and one or more contextual inputs (at step 1603)");
providing context information with the prompt to the large language model (Kunchakarra: see Col 64 lines 50-56, "The processor, in association with the large language models, generates the one or more job descriptions based on at least one of the organizational structure, the one or more roles, the one or more responsibilities, the one or more hierarchical relationships, the one or more access levels, the one or more service actions, and the one or more departments
generating the description of the access entitlement using the LLM based on the retrieved context information for an access entitlement in an identity governance and administration (Kunchakarra: see Col 64 lines 50-56, "The processor, in association with the large language models, generates the one or more job descriptions based on at least one of the organizational structure, the one or more roles, the one or more responsibilities, the one or more hierarchical relationships, the one or more access levels, the one or more service actions, and the one or more departments").
Maschmeyer and Kunchakarra are analogous art because they are from the same field of endeavor. Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art to combine Maschmeyer’s prompt generation technique for a generated description using large language model with Kunchakarra’s method for identifying excessive privileges in an Identity and Access Management System. The suggestion/motivation for doing so would be to improve the quality, reliability, and specificity of the security information associated with industry standards and remove redundancy in organizational hierarchies that may provide privileges that aren’t approved or necessary.
Regarding claims 2, 10, and 18, Maschmeyer teaches the prompt provided to the LLM includes one or more of: a string identifier, a source of the access entitlement, and roles of users who have access to the access entitlement (Maschmeyer: see Col 14 lines 34-42, "For example, the object database 560 may include, for each object, data about one or more object attributes (e.g., object name, object size, object type, object features, etc.). Object attribute(s) for a given object may for example, be stored in a lookup table that can be referenced using the name of the object, a unique identifier (e.g., identification number) of the object, etc. Each object attribute of a given object may be stored as a text string (which may include one or more words)"); Col 16 lines 46-47, "The prompt generator 500 performs operations to generate a prompt to a LLM to generate the object description, where the prompt includes the object attribute(s) that should be included in the generated description").
Regarding claims 4 and 12, Maschmeyer and Kunchakarra teach the context information relating to the access entitlement includes information about an organization (Kunchakarra: see Col 62 lines 43-49, "In one embodiment, the one or more contents comprise at least one of one or more security contents and one or more organizational structural contents"..."In one embodiment, the one or more data sources, from which the contents extracted, are related to the organization"). Motivation to combine Maschmeyer and Kunchakarra in the instant claims is the same as that in claims 1, 9, and 17.
Regarding claims 5 and 13, Maschmeyer and Kunchakarra teach the context information relating to the access entitlement includes information about an organization the context information relating to the access entitlement includes information about an industry (Kunchakarra: see Col 62 lines 52-60, "The one or more data sources comprise at least one of databases, object stores, document management system, file systems, and through application programming interfaces. In an embodiment, the job role names and the one or more contextual inputs may be fed as an input query to the processor. The contextual inputs may comprise organizational inputs. The contextual inputs comprise at least one of an organization size, an industry, a field, a tier classification, and employee count"). Motivation to combine Maschmeyer and Kunchakarra in the instant claims is the same as that in claims 1, 9, and 17.
Regarding claims 6 and 14, Maschmeyer teaches providing feedback from a reviewer of the description generated by the LLM to the knowledge base (Maschmeyer: see Col 19 lines 46-47, "The generated description is received from the LLM and may be presented to a user device"; Col 19 lines 54-55, "The text-editor 550 may provide a UI that enables a user to review the generated description"; Col 20 lines 59-65, "The UI 600 may include an accept option 618 that may be selected to confirm that the generated description 612 (which may have been modified by the user, for example to provide the unsubstantiated information) is approved. Selection of the accept option 618 may cause the generated description 612 (with the user modifications that have been made) to be saved by the platform").
Regarding claims 8 and 16, Maschmeyer and Kunchakarra teach the input/output pairs include training data including one or more of: an identifier of the access entitlement, a source application of the access entitlement, roles of users who have access to the access entitlement, and activity data about usage of the access entitlement (Kunchakarra: see Col 7 lines 44-51, "annotating the one or more custom datasets by highlighting the one or more roles, and the one or more service actions and the one or more access levels, respectively; and training the artificial intelligence engine/large language models) using the one or more custom datasets"; Col 68 lines 49-54, "annotating the one or more custom datasets by highlighting the one or more roles, and the one or more service actions and the one or more access levels, respectively; and training the artificial intelligence engine/large language models) using the one or more custom datasets"). Motivation to combine Maschmeyer and Kunchakarra in the instant claims is the same as that in claims 1, 9, and 17.
Claims 21, 23, and 25 are rejected under 35 U.S.C. 103 as being unpatentable over Maschmeyer in view of Kunchakarra, as applied to claims 1, 2, 4-6, 8, 9, 10, 12-14, 16-18 above, and in further view of Lu et al. (U.S. 12,579,974)(hereinafter Lu).
Regarding claims 21, 23, and 25, Maschmeyer and Kunchakarra teach the invention detailed above.
However, Maschmeyer and Kunchakarra do not teach storing previously generated descriptions of access entitlements in a query cache- retrieval database; performing a similarity detection check on the received request against previous requests in the query cache-retrieval database to detect a duplicate or near-duplicate request; reusing a previously generated description in response to detecting the duplicate or near-duplicate request to optimize direct queries to the LLM.
Nevertheless, Lu-which is in the same field of endeavor- teaches storing previously generated descriptions of access entitlements in a query cache- retrieval database (Lu: see Col 3 lines 55-59, "An LLM output corresponding to the context data, which may be determined by the LLM via prior processing of the context data (that may be determined for a different previous interaction), may be stored in a cache along with the unique key");
performing a similarity detection check on the received request against previous requests in the query cache-retrieval database to detect a duplicate or near-duplicate request (Lu: see Col 3 lines 59-63, "For an incoming user input, a cache lookup may performed using a key for context data corresponding to the user input. For a cache hit, the stored output can be used to respond to the user input"); and
reusing a previously generated description in response to detecting the duplicate or near-duplicate request to optimize direct queries to the LLM (Lu: see Col 3 lines 63-67 - Col 4 lines 1-2, "A cache hit, as used herein, can mean that the LLM has already previously processed a user input corresponding to the same context data (e.g., a user input received under the same or similar circumstances), and the system can use the previously determined output (stored in the cache) to respond to the current user input that corresponds to the same context data").
Maschmeyer, Kunchakarra, and Lu are analogous art because they are from the same field of endeavor. Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art to utilize the semantic caching technique of Lu with the large language model for generating textual descriptions of Maschmeyer and Kunchakarra. The suggestion/motivation for doing so would be to increase the response/output speed of the system and reduce the need for redundant calls to the large language model.
Claims 22, 24, and 26 are rejected under 35 U.S.C. 103 as being unpatentable over Maschmeyer in view of Kunchakarra, as applied to claims 1, 2, 4-6, 8, 9, 10, 12-14, 16-18 above, and in further view of Colgan (U.S. 2025/0077793)(hereinafter Colgan).
Regarding claims 22, 24, and 26, Maschmeyer and Kunchakarra teach the invention detailed above.
However, Maschmeyer and Kunchakarra do not teach storing previously generated descriptions in a vector database as output embeddings; and generating an output embedding for the received request and measuring a closeness between the generated output embedding and the stored output embeddings to determine consistency between generated descriptions.
Nevertheless, Colgan-which is in the same field of endeavor- teaches storing previously generated descriptions in a vector database as output embeddings (Colgan: see Page 10 Claim 9, "processing, by the computing system, the vector representation of the first data item with the machine-learned embedding model to obtain a first result embedding of the one or more result embeddings associated with the first data item; and storing, by the computing system, the result embedding and the vector representation of the first data item in the vector database"); and
generating an output embedding for the received request (Colgan: see Page 4 paragraph 0034, "The query embedding 42 can be an embedding of a vector representation of the query 44") and measuring a closeness between the generated output embedding and the stored output embeddings to determine consistency between generated descriptions (Colgan: see Page 4 paragraph 0035, "The embedding search module 40 can perform a nearest-neighbor, or approximate nearest-neighbor (ANN), search to identify result embedding(s) 54. Result embeddings 54 can be embeddings that are semantically similar to the query embedding 42").
Maschmeyer, Kunchakarra, and Colgan are analogous art because they are from the same field of endeavor. Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art to utilize Colgan’s method identifying result embeddings for a request with the large language model for generating textual descriptions of Maschmeyer and Kunchakarra. The suggestion/motivation for doing so would be to improve the accuracy of the large language model’s responses.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to KELAH JANAE MCFARLAND-BARNES whose telephone number is (571)272-5953. The examiner can normally be reached Monday through Friday 8:00am until 4:00pm Central Time.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn D Feild can be reached at 571-272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/KELAH JANAE MCFARLAND-BARNES/Examiner, Art Unit 2431
/SHIN-HON (ERIC) CHEN/Primary Examiner, Art Unit 2431