Prosecution Insights
Last updated: August 17, 2026
Application No. 18/889,648

DATA SECURITY SYSTEM ASSET AND USER IDENTITY MANAGEMENT

Final Rejection §101
Filed
Sep 19, 2024
Examiner
GRIJALVA LOBOS, BORIS D
Art Unit
2446
Tech Center
2400 — Computer Networks
Assignee
Lucidum Inc.
OA Round
2 (Final)
83%
Grant Probability
Favorable
3-4
OA Rounds
5m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 83% — above average
83%
Career Allowance Rate
327 granted / 396 resolved
+24.6% vs TC avg
Strong +20% interview lift
Without
With
+19.7%
Interview Lift
resolved cases with interview
Typical timeline
2y 4m
Avg Prosecution
24 currently pending
Career history
416
Total Applications
across all art units

Statute-Specific Performance

§101
12.4%
-27.6% vs TC avg
§103
40.9%
+0.9% vs TC avg
§102
16.1%
-23.9% vs TC avg
§112
20.6%
-19.4% vs TC avg
Black line = Tech Center average estimate • Based on career data from 396 resolved cases

Office Action

§101
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This Office action is in response to communications filed on 6/5/2026. Claims 1-20 are pending. DETAILED ACTION Response to Arguments Applicant's arguments filed ON 6/5/2026 have been fully considered but they are not persuasive. In the response filed applicant argues, in substance: a) In pages 11-12 of the response filed, applicant argues that the claimed invention is not directed towards an abstract idea and in the non-final Office action dated 12/8/2025 (hereinafter non-final Office action) “elements of the claim that make clear that the claim limitations are not capable of being performed by a human or as a mental process” are excluded from analysis. For example, “claim 1 recites that the first input record and the second input record are received “by a data security system that provides data security services for a plurality of computing assets associated with a client account of the data security system,” and “A data security system, as described in this application, is not human. Humans do not run machine learning models” and humans “are also not databases”. In response to argument (a), the examiner respectfully disagrees. The test performed by Step 2A is not concerned with determining whether the invention as claimed is performed by a human or a machine. As admitted by applicant in page 11 of the response filed, the test is “a two-prong inquiry” where the first prong determines if “the claim recites a judicial exception” and the second prong determines if the judicial exception is integrated “into a practical application”. The non-final Office action did not exclude the elements argued by applicant, it’s clear from pages 3-4 of the non-final Office action that the machines used by the system where not underlined as those elements were not part of a judicial exception. The examiner did underline the judicial exception to show that the claim recites a judicial exception (first prong) and in page 5 the examiner evaluated the elements argued by applicant concluding that the additional elements did not improve the functioning of a computer or a technical field. b) In page 12 of the response filed, applicant argues that the claims “recite features that integrate any alleged judicial exception into a practical application” because “the claims do not merely recite generic computer elements, but instead recite components that receive and process information so as to improve the technical field of “data security risks associated with one or more computing assets” where the assets are devices such as computing devices. For example, to “monitor and assess data security risks associated with computing assets, the present application recites the use of similarly complex data security systems” and the “application of machine learning models to identify correspondence between events and entities” to allow “for a more comprehensive and accurate risk analysis and mitigation”. In response to argument (b), the examiner respectfully disagrees. Initially the examiner notes that the claimed subject matter excludes any elements that make apparent how a “more comprehensive and accurate risk analysis and mitigation” is achieved. While machine-learning has advanced a lot recently, whether it can surpass human driven risk analysis and mitigation is up for debate. For example, if a human is provided with two different event records, one identifying a first asset identifier such as an IP address and the other identifying another asset identifier such as a MAC address, a human with access to relevant information would be able to either successfully correlate the first asset identifier with the second asset identifier or determine that no correlation exists (first determination). Similarly, if the first record includes a first user identifier, such as an email address, and the second record includes a second user identifier such as a name, the human with access to relevant information would be able to either successfully correlate the first user identifier with the second user identifier or determine that no correlation exists (second determination). The use of a first machine learning model to make the first determination does not automatically improve the accuracy given a same set of relevant information. For example, if the relevant information is simply that the MAC address and IP address are related, the machine learning model and the human could both equally make an accurate determination. While other sets of data may exist beyond the exemplified relevant information, above, applicant has not demonstrated the existence of any information or algorithm that would make the machine learning model more accurate or comprehensive than a human. Similarly, the use of a second machine learning model to make the second determination does not automatically improve the accuracy given the same set of relevant information. For example, if the relevant information is simply that the name and email address are related, the second machine learning model and the human could both equally make an accurate determination. While other sets of data may exist beyond the exemplified relevant information, above, applicant has not demonstrated the existence of any information or algorithm that would make the second machine learning model more accurate or comprehensive than a human. c) In page 13 of the response filed, applicant explains that, according to Ex Parte Desjardins, Appeal No. 2024-000567 (ARP September 26, 2025), “the ARP concluded that “[s]oftware can make non-abstract improvements to computer technology, just as hardware improvements can” and Examiners “should not evaluate claims” at a high level of generality such as to categorically exclude “AI innovations from Patent protection”. Applicant then argues that the non-final Office action “falls into the “high level of generality” trap” because the limitations “include the use of machine learning models to determine that different computing asset identifiers “correspond to a same computing asset identifier for a computing asset,” and that different user identifiers “correspond to a same user identifier associated with the client account”” but the “Office Action merely states that the machine learning models are simply “to process information” and are thus generic” but “the claims recite specific correspondences – conclusions – that able to be made specifically because machine learning models are being applied.” In response to argument (c), the examiner respectfully disagrees. The examiner first notes that in Ex Parte Desjardins, the panel concluded that the claims were not directed towards a judicial exception because the claimed invention recites steps that improve how the claimed machine learning model itself “learns” and it was not a claim that simply added a machine learning capability to a process that is capable of being performed by a human in order to, for example, make the process faster. In the present application, the claimed process (correlating identifiers) is capable of being performed by a human. Adding a machine learning model to perform the steps without a specialized algorithm that can only be performed by a machine learning model simply substitutes the human. The present application does not claim any specialized algorithms that are only capable of being performed by the machine learning models, therefore, the claimed models simply substitute a human. For example, a human is more than capable of determining if two computing asset identifiers are related to a single device. Similarly, a human is also capable of identifying if two user identifiers correspond to a same user. If there was any information that only a machine learning model is capable of analyzing to make the determinations, then the machine learning model would not be substituting a human, but creating a system that outperforms human analysis capacity. But none of this is claimed nor recited in the specification. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception (i.e., a law of nature, a natural phenomenon, or an abstract idea) without significantly more. The following is the Principles of Law: A patent may be obtained for "any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof'. The Supreme Court has "long held that this provision contains an important implicit exception [:] Laws of nature, natural phenomena, and abstract ideas are not patentable". Under the now familiar two-part test described by the Supreme Court in Alice, “[W]e must first determine whether the claims at issue are directed to a patent-ineligible concept”, such as an abstract idea. Alice Corp. Pty. Ltd. v. CLS Bank Int'l, 134 S. Ct. 2347, 2355 (2014). If so, we must then “consider the elements of each claim both individually and 'as an ordered combination' to determine whether the additional elements 'transform the nature of the claim' into a patent-eligible application. Id. (quoting Mayo, 132 S. Ct. at 1298, 1297). For the reasons set forth below, we find that the claims are directed to the abstract idea of classifying and storing digital images in an organized manner and fail to add an inventive concept sufficient to confer patent eligibility. The examiner is bound by and applies the framework as set forth by the Court in Mayo and reaffirmed by the Court in Alice for determining whether the claims are directed to patent-eligible subject matter. As reference, the examiner relies on the steps outlined by the 2019 Revised Subject Matter Eligibility Guidance published on Monday, January 7, 2019. The steps are as follows: Step one: Are the claims at issue directed to a process, machine, manufacture, or composition of matter? The examiner concludes that claims 1-20, are directed towards at least one of the four statutory categories. Step two: Are the claims directed to a law of nature, a natural phenomenon, or an abstract idea? In accordance with judicial precedent, and to increase consistency in examination practice, the 2019 Revised Patent Subject Matter Eligibility Guidance sets forth a procedure to determine whether a claim is ‘‘directed to’’ a judicial exception. The procedures for step two includes two sub-steps: Step 2A: This is a two prong inquiry. In Prong One, examiners evaluate whether the claim recites a judicial exception. Regarding claim 1, the examiner has determined that the limitations include an abstract idea. For example, the limitations recite A method, comprising: receiving, by a data security system that provides data security services for a plurality of computing assets associated with a client account of the data security system, a first input record from a first event information source, wherein the first input record is associated with a first event, and wherein the first input record includes a first computing asset identifier and a first user identifier associated with the first event; receiving, by the data security system, a second input record from a second event information source different from the first event information source, wherein the second input record is associated with a second event, wherein the second input record includes a second computing asset identifier and a second user identifier associated with the second event, wherein the second computing asset identifier is different than the first computing asset identifier, and wherein the second user identifier is different than the first user identifier; determining, by the data security system and based on application of a first machine learning model to the first computing asset identifier and the second computing asset identifier, that the first computing asset identifier and the second computing asset identifier each correspond to a same computing asset identifier for a computing asset of the plurality of computing assets; determining, by the data security system and based on application of a second machine learning model to the first user identifier and the second user identifier, that the first user identifier and the second user identifier each correspond to a same user identifier associated with the client account; and storing, by the data security system and in a database accessible to the data security system, first information associated with the first event and second information associated with the second event in association with an identifier for the computing asset based on determining that the first computing asset identifier and the second computing asset identifier each correspond to the computing asset and in association with the same user identifier based on determining that the first user identifier and the second user identifier each correspond to the same user identifier. The underlined limitations are directed to concepts relating to organizing or analyzing information in a way that can be performed mentally or is analogous to human mental work (i.e., “An Ide ‘Of Itself”), since the idea as a whole could be performed by a human. For example, receiving information with different identifiers and correlating the identifiers to a single user or system through observation, evaluation, and judgement or opinion. Storing information could be performed mentally. In prong two, the examiners evaluate whether the claim, as a whole, integrates the recited judicial exception into a practical application. To do this, additional elements recited in the claim are identified. The additional elements recited in claim 1 include “a data security system that provides data security services for a plurality of computing assets associated with a client account of the data security system”, a “first machine learning model”, a “second machine learning model”, and “a database”. The examiner concludes that the additional elements do not reflect an improvement in the functioning of a computer, or other technology or technical field (the devices, systems, and networks in the claim are simply there to transmit/receive and process information). Receiving, processing, and storing information in the manner claimed could be performed by generic computing systems that are well-known in the art and serve merely to replace the human. Replacing the functions of a human with a well-known computing system does not add significantly more to the abstract idea. The additional elements also fail to implement the judicial exception with a particular machine or manufacture integral to the claim. As mentioned above, transmitting, receiving, and processing data could be performed by any known computer in the art. The additional elements do not reflect a transformation or reduction of a particular article to a different state. The additional elements do not apply the judicial exception to effect a particular treatment or prophylaxis for a disease or medical condition. The additional elements do not apply the judicial exception in some other meaningful way beyond generally linking the use of the judicial exception to a particular technology environment. Therefore, under Step 2A, the claim is found to be directed towards a judicial exception. Step 2B: Does the claim provide an inventive concept? The examiner concludes that the claim lacks specific limitations that are not well-understood, routine, or conventional in the field. For example, machine learning algorithms capable of performing human tasks are well-known in the art. Therefore, claim 1 is rejected as being directed towards an abstract idea. Regarding claims 2-18, the claimed matter further limits the invention recited in claim 1. However, the limitations all could similarly be performed in the human mind. Claim 17 defines what the machine language algorithms could be but these algorithms would still be used to replace the functions that a human could perform. Therefore, claims 2-18 are rejected as being directed towards an abstract idea. Regarding claims 19-20, the claims recite features similar in scope to those of claim 1, with the addition of an “apparatus, comprising: one or more memories storing processor-executable code; and one or more processors coupled with the one or more memories and individually or collectively operable to execute the code” in claim 19 and a “non-transitory computer-readable medium storing code, the code comprising instructions executable by one or more processors” to perform the claimed limitations. As explained above, using known computer systems to perform functions that a human could does not transform the claimed matter into significantly more than the abstract idea. Therefore, claims 19-20 are rejected as being directed towards an abstract idea. Allowable Subject Matter Claims 1-20 would be allowable by overcoming all 35 USC 101 rejections set forth above without broadening the claimed subject matter. Conclusion THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to BORIS D GRIJALVA LOBOS whose telephone number is (571)272-0767. The examiner can normally be reached M-F 10:30AM to 6:30PM EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Brian Gillis can be reached at 571-272-7952. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /BORIS D GRIJALVA LOBOS/ Primary Patent Examiner, Art Unit 2446
Read full office action

Prosecution Timeline

Sep 19, 2024
Application Filed
Dec 08, 2025
Non-Final Rejection mailed — §101
Jun 05, 2026
Response Filed
Jun 17, 2026
Final Rejection mailed — §101 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12695955
COMMENT MANAGEMENT METHOD AND SYSTEM FOR DISPLAYING COMMENTS
2y 1m to grant Granted Jul 28, 2026
Patent 12657338
SYSTEMS AND METHODS TO MANAGE DATA SETS WHILE MAINTAINING DATA SET ISOLATION AND INTEGRITY
2y 0m to grant Granted Jun 16, 2026
Patent 12652273
ENCRYPTING DATA GENERATED FROM MEDICAL DEVICES
2y 1m to grant Granted Jun 09, 2026
Patent 12647415
Gesture-Based User Authentication
2y 1m to grant Granted Jun 02, 2026
Patent 12645781
AUTHENTICATION OF MEMORY EXPANSION CAPABILITIES
1y 10m to grant Granted Jun 02, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
83%
Grant Probability
99%
With Interview (+19.7%)
2y 4m (~5m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 396 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month