Prosecution Insights
Last updated: October 01, 2026
Application No. 18/898,976

METHOD FOR DETECTING RANSOMWARE, RELATED SYSTEM, AND STORAGE MEDIUM

Final Rejection §103
Filed
Sep 27, 2024
Priority
Mar 29, 2022 — CN 202210318593.0 +1 more
Examiner
LESNIEWSKI, VICTOR D
Art Unit
2493
Tech Center
2400 — Computer Networks
Assignee
Huawei Technologies Co., Ltd.
OA Round
2 (Final)
58%
Grant Probability
Moderate
3-4
OA Rounds
1y 3m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 58% of resolved cases
58%
Career Allowance Rate
287 granted / 491 resolved
+0.5% vs TC avg
Strong +55% interview lift
Without
With
+55.3%
Interview Lift
resolved cases with interview
Typical timeline
3y 3m
Avg Prosecution
18 currently pending
Career history
518
Total Applications
across all art units

Statute-Specific Performance

§101
8.8%
-31.2% vs TC avg
§103
58.1%
+18.1% vs TC avg
§102
16.8%
-23.2% vs TC avg
§112
13.0%
-27.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 491 resolved cases

Office Action

§103
DETAILED ACTION The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . The amendment filed 6/8/2026 has been placed of record in the file. Claims 1, 8, and 15 have been amended. Claims 2, 9, 17, and 19 have been canceled. Claims 20-22 have been added. The objection to the specification is withdrawn in view of the amendment. Claims 1, 3-8, 10-16, 18, and 20-22 are now pending. The applicant’s arguments with respect to claims 1, 3-8, 10-16, 18, and 20-22 have been considered but are moot in view of the following new grounds of rejection. The IDS filed 3/18/2026 has been considered. Response to Amendment Claims have been amended to further define use of histogram data. The amendment proves a change in scope to the independent claims as the independent claims now explicitly state that the partial feature comprises partial histogram statistical data. However, none of the amended claims show a patentable distinction over the prior art as evidenced by the following new grounds of rejection. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1, 3, 6-8, 10, 13-16, 18, and 20-22 are rejected under 35 U.S.C. 103 as being unpatentable over Chen et al. (U.S. Patent Application Publication Number 2020/0034537), hereinafter referred to as Chen, in view of Adams (U.S. Patent Number 10,121,003), further in view of Linnen et al. (U.S. Patent Application Publication Number 2019/0294507). as listed on the Notice of References Cited dated 3/10/2026, hereinafter referred to as Linnen. Chen disclosed techniques for detecting ransomware infection. In an analogous art, Adams disclosed techniques for detecting ransomware. Also in an analogous art, Linnen disclosed techniques for entropy indicator analysis and encryption detection. All of these systems are directed toward the detection of ransomware. Regarding claim 1, Chen discloses a method for detecting ransomware, the method comprising: obtaining a partial feature of a target file based on preset data in the target file, wherein the partial feature comprises partial entropy data (paragraph 19, determines entropy features); determining, based on the partial feature of the target file, whether the target file is an encrypted file (paragraph 19, analyzes content to determine whether file is encrypted); and determining, based on the determination that the target file is the encrypted file, that the target file is attacked by the ransomware (paragraph 29, determines whether file is infected with ransomware). Chen does not explicitly state wherein the method further comprises: obtaining a magic number and a file name extension of the target file; determining, based on a preset correspondence between the magic number and the file name extension, whether the magic number corresponds to the file name extension in the target file; and triggering, based on the determination that the magic number corresponds to the file name extension in the target file, the operation of the obtaining of the partial feature of the target file based on the preset data in the target file. However, using a magic number in ransomware detection in such a fashion was well known in the art as evidenced by Adams. Since the inventions encompass the same field of endeavor, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the system of Chen by adding the ability that the method further comprises: obtaining a magic number and a file name extension of the target file; determining, based on a preset correspondence between the magic number and the file name extension, whether the magic number corresponds to the file name extension in the target file; and triggering, based on the determination that the magic number corresponds to the file name extension in the target file, the operation of the obtaining of the partial feature of the target file based on the preset data in the target file as provided by Adams (see column 8, lines 39-43, determines entropy values when magic number matches file type suffix). One of ordinary skill in the art would have recognized the benefit that analyzing the magic number of a file would assist in detecting ransomware (see Adams, column 1, lines 36-44). The combination of Chen and Adams does not explicitly state that the partial entropy data is partial histogram statistical data. However, using histogram data in ransomware detection in such a fashion was well known in the art as evidenced by Linnen. Since the inventions encompass the same field of endeavor, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the combination of Chen and Adams by adding the ability that the partial entropy data is partial histogram statistical data as provided by Linnen (see paragraph 29, entropy indicator is histogram). One of ordinary skill in the art would have recognized the benefit that detecting unauthorized encryption would assist in mitigating data loss (see Linnen, paragraph 1). Regarding claim 3, the combination of Chen, Adams, and Linnen discloses obtaining a plurality of operation records of a plurality of operated files, wherein the plurality of operation records correspond to the plurality of operated files, and each of the plurality of operation records is for recording an operation on an operated file corresponding to the operation record; generating a plurality of operation mode sequences within a preset duration based on the plurality of operation records, wherein the plurality of operation mode sequences correspond to the plurality of operation records; obtaining, one by one from the plurality of operation mode sequences, an operation mode sequence that matches a preset operation mode sequence; and determining, when a quantity of operation mode sequences that match the preset operation mode sequence is greater than a preset quantity, an operated file corresponding to the operation mode sequence that matches the preset operation mode sequence as the target file (Chen, paragraph 16, examines pattern of file operations within time interval to determine whether behavior is normal or abnormal). Regarding claim 6, the combination of Chen, Adams, and Linnen discloses obtaining a plurality of operation records of a plurality of operated files, and obtaining an operated file corresponding to a second operation and a third operation based on the plurality of operation records, wherein the plurality of operation records correspond to the plurality of operated files, each of the plurality of operation records is for recording an operation on an operated file corresponding to the operation record, and the second operation and the third operation are operations corresponding to a same operated file; and determining, when a quantity of types of name extensions of operated files corresponding to the second operation is not less than a preset quantity, a quantity of types of name extensions of operated files corresponding to the third operation is not less than another preset quantity, and the quantity of types of the name extensions of the operated files corresponding to the second operation is greater than the quantity of types of the name extensions of the operated files corresponding to the third operation, the operated file corresponding to the second operation and the third operation as the target file (Chen, paragraph 17, examines ratios of particular operations across selected file types to determine whether behavior is normal or abnormal). Regarding claim 7, the combination of Chen, Adams, and Linnen discloses sending the target file to a user to determine whether the target file undergoes an encryption operation performed by the user; and sending an alarm prompt based on the determination that the user does not perform the encryption operation on the target file (Chen, paragraph 42, user runs analysis and reviews results). Regarding claim 8, Chen discloses an apparatus for detecting ransomware, the apparatus comprising: at least one processor; and a computer-readable storage medium coupled to the at least one processor and storing programming instructions, the programming instructions, when executed by the at least one processor, instruct the at least one processor to perform operations such that the processor is at least configured to: obtain a partial feature of a target file based on preset data in the target file, wherein the partial feature comprises partial entropy data (paragraph 19, determines entropy features); determine, based on the partial feature of the target file, whether the target file is an encrypted file (paragraph 19, analyzes content to determine whether file is encrypted); and determine, if the target file is the encrypted file, that the target file is attacked by the ransomware (paragraph 29, determines whether file is infected with ransomware). Chen does not explicitly state wherein the at least one processor is further configured to: obtain a magic number and a file name extension of the target file; determine, based on a preset correspondence between the magic number and the file name extension, whether the magic number corresponds to the file name extension in the target file; and trigger, if the magic number corresponds to the file name extension in the target file, the obtaining of the partial feature of the target file based on the preset data in the target file. However, using a magic number in ransomware detection in such a fashion was well known in the art as evidenced by Adams. Since the inventions encompass the same field of endeavor, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the system of Chen by adding the ability that the at least one processor is further configured to: obtain a magic number and a file name extension of the target file; determine, based on a preset correspondence between the magic number and the file name extension, whether the magic number corresponds to the file name extension in the target file; and trigger, if the magic number corresponds to the file name extension in the target file, the obtaining of the partial feature of the target file based on the preset data in the target file as provided by Adams (see column 8, lines 39-43, determines entropy values when magic number matches file type suffix). One of ordinary skill in the art would have recognized the benefit that analyzing the magic number of a file would assist in detecting ransomware (see Adams, column 1, lines 36-44). The combination of Chen and Adams does not explicitly state that the partial entropy data is partial histogram statistical data. However, using histogram data in ransomware detection in such a fashion was well known in the art as evidenced by Linnen. Since the inventions encompass the same field of endeavor, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the combination of Chen and Adams by adding the ability that the partial entropy data is partial histogram statistical data as provided by Linnen (see paragraph 29, entropy indicator is histogram). One of ordinary skill in the art would have recognized the benefit that detecting unauthorized encryption would assist in mitigating data loss (see Linnen, paragraph 1). Regarding claim 10, the combination of Chen, Adams, and Linnen discloses wherein the at least one processor is further configured to: obtain a plurality of operation records of a plurality of operated files, wherein the plurality of operation records correspond to the plurality of operated files, and each of the plurality of operation records is for recording an operation on an operated file corresponding to the operation record; generate a plurality of operation mode sequences within a preset duration based on the plurality of operation records, wherein the plurality of operation mode sequences correspond to the plurality of operation records; obtain, one by one from the plurality of operation mode sequences, an operation mode sequence that matches a preset operation mode sequence; and determine, when a quantity of operation mode sequences that match the preset operation mode sequence is greater than a preset quantity, an operated file corresponding to the operation mode sequence that matches the preset operation mode sequence as the target file (Chen, paragraph 16, examines pattern of file operations within time interval to determine whether behavior is normal or abnormal). Regarding claim 13, the combination of Chen, Adams, and Linnen discloses wherein the at least one processor is further configured to: obtain a plurality of operation records of a plurality of operated files, and obtain an operated file corresponding to a second operation and a third operation based on the plurality of operation records, wherein the plurality of operation records correspond to the plurality of operated files, each of the plurality of operation records is for recording an operation on an operated file corresponding to the operation record, and the second operation and the third operation are operations corresponding to a same operated file; and determine, if a quantity of types of name extensions of operated files corresponding to the second operation is not less than a preset quantity, a quantity of types of name extensions of operated files corresponding to the third operation is not less than another preset quantity, and the quantity of types of the name extensions of the operated files corresponding to the second operation is greater than the quantity of types of the name extensions of the operated files corresponding to the third operation, the operated file corresponding to the second operation and the third operation as the target file (Chen, paragraph 17, examines ratios of particular operations across selected file types to determine whether behavior is normal or abnormal). Regarding claim 14, the combination of Chen, Adams, and Linnen discloses wherein the at least one processor is further configured to: send the target file to a user to determine whether the target file undergoes an encryption operation performed by the user; and send an alarm prompt if the user does not perform the encryption operation on the target file (Chen, paragraph 42, user runs analysis and reviews results). Regarding claim 15, Chen discloses a chip system, wherein the chip system is applied to an electronic device, the chip system comprises one or more interface circuits and one or more processors, the interface circuit and the processor are interconnected by a line; the interface circuit is configured to receive a signal from a memory of the electronic device and send the signal to the processor, wherein the signal comprises computer instructions stored in the memory; and when the processor executes the computer instructions, the electronic device is for detecting ransomware and is configured to: obtain a partial feature of a target file based on preset data in the target file, wherein the partial feature comprises partial entropy data (paragraph 19, determines entropy features); determine, based on the partial feature of the target file, whether the target file is an encrypted file (paragraph 19, analyzes content to determine whether file is encrypted); and determine, if the target file is the encrypted file, that the target file is attacked by the ransomware (paragraph 29, determines whether file is infected with ransomware). Chen does not explicitly state wherein the electronic device is further configured to: obtain a magic number and a file name extension of the target file; determine, based on a preset correspondence between the magic number and the file name extension, whether the magic number corresponds to the file name extension in the target file; and trigger, if the magic number corresponds to the file name extension in the target file, the obtaining of the partial feature of the target file based on the preset data in the target file. However, using a magic number in ransomware detection in such a fashion was well known in the art as evidenced by Adams. Since the inventions encompass the same field of endeavor, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the system of Chen by adding the ability that the electronic device is further configured to: obtain a magic number and a file name extension of the target file; determine, based on a preset correspondence between the magic number and the file name extension, whether the magic number corresponds to the file name extension in the target file; and trigger, if the magic number corresponds to the file name extension in the target file, the obtaining of the partial feature of the target file based on the preset data in the target file as provided by Adams (see column 8, lines 39-43, determines entropy values when magic number matches file type suffix). One of ordinary skill in the art would have recognized the benefit that analyzing the magic number of a file would assist in detecting ransomware (see Adams, column 1, lines 36-44). The combination of Chen and Adams does not explicitly state that the partial entropy data is partial histogram statistical data. However, using histogram data in ransomware detection in such a fashion was well known in the art as evidenced by Linnen. Since the inventions encompass the same field of endeavor, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the combination of Chen and Adams by adding the ability that the partial entropy data is partial histogram statistical data as provided by Linnen (see paragraph 29, entropy indicator is histogram). One of ordinary skill in the art would have recognized the benefit that detecting unauthorized encryption would assist in mitigating data loss (see Linnen, paragraph 1). Regarding claim 16, the combination of Chen, Adams, and Linnen discloses wherein the at least one processor is further configured to: obtain a plurality of operation records of a plurality of operated files; perform a screening for abnormal operation behaviors based on the plurality of operation records of the plurality of operated files; and determine an operated file corresponding to the abnormal operation behaviors as the target file (Chen, paragraph 16, examines pattern of file operations within time interval to determine whether behavior is normal or abnormal). Regarding claim 18, the combination of Chen, Adams, and Linnen discloses obtaining a plurality of operation records of a plurality of operated files; performing a screening for abnormal operation behaviors based on the plurality of operation records of the plurality of operated files; and determining an operated file corresponding to the abnormal operation behaviors as the target file (Chen, paragraph 16, examines pattern of file operations within time interval to determine whether behavior is normal or abnormal). Regarding claim 20, the combination of Chen, Adams, and Linnen discloses wherein the preset data is partial byte data in the target file and the partial histogram statistical data is constructed based on the partial byte data (Linnen, paragraph 31, histogram depicts character count using values formed by 8 bit words). Regarding claim 21, the combination of Chen, Adams, and Linnen discloses wherein the preset data is partial byte data in the target file and the partial histogram statistical data is constructed based on the partial byte data (Linnen, paragraph 31, histogram depicts character count using values formed by 8 bit words). Regarding claim 22, the combination of Chen, Adams, and Linnen discloses wherein the preset data is partial byte data in the target file and the partial histogram statistical data is constructed based on the partial byte data (Linnen, paragraph 31, histogram depicts character count using values formed by 8 bit words). Claims 4, 5, 11, and 12 are rejected under 35 U.S.C. 103 as being unpatentable over Chen in view of Adams, in view of Linnen, further in view of Massiglia et al. (U.S. Patent Application Publication Number 2021/0382992), hereinafter referred to as Massiglia. The combination of Chen, Adams, and Linnen disclosed techniques for detecting ransomware infection. In an analogous art, Massiglia disclosed techniques for analyzing potentially corrupt data written to storage. Both systems are directed toward the detection of ransomware. Regarding claim 4, the combination of Chen, Adams, and Linnen discloses obtaining a plurality of operation records of a plurality of operated files, and obtaining, based on the plurality of operation records, a same operated file on which an operation is performed by a same device, wherein the plurality of operation records correspond to the plurality of operated files, and each of the plurality of operation records is for recording an operation on an operated file corresponding to the operation record (Chen, paragraph 16, file operations). The combination of Chen, Adams, and Linnen does not explicitly state that the performed operation is a write operation and further successively obtaining a write offset and a write length of the same operated file on which the write operation is performed by the same device; accumulating, when a current write offset is greater than a previous write offset for the same operated file on which the write operation is performed by the same device, a current write length and a previous write length for the same operated file to obtain an accumulated write length value of the same operated file; obtaining a write ratio of the same operated file based on a size of the same operated file and the accumulated write length value; and determining, when the write ratio of the same operated file within a preset duration is not less than a preset write ratio, the same operated file on which the write operation is performed by the same device as the target file. However, analyzing write operations for ransomware detection in such a fashion was well known in the art as evidenced by Massiglia. Since the inventions encompass the same field of endeavor, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the combination of Chen, Adams, and Linnen by adding the ability that the performed operation is a write operation and further successively obtaining a write offset and a write length of the same operated file on which the write operation is performed by the same device; accumulating, when a current write offset is greater than a previous write offset for the same operated file on which the write operation is performed by the same device, a current write length and a previous write length for the same operated file to obtain an accumulated write length value of the same operated file; obtaining a write ratio of the same operated file based on a size of the same operated file and the accumulated write length value; and determining, when the write ratio of the same operated file within a preset duration is not less than a preset write ratio, the same operated file on which the write operation is performed by the same device as the target file as provided by Massiglia (see paragraph 363, examines file compressibility, and paragraph 496, metrics include compressibility of writes). One of ordinary skill in the art would have recognized the benefit that analyzing compressibility metrics would assist in determining whether or not data is encrypted (see Massiglia, paragraph 363). Regarding claim 5, the combination of Chen, Adams, and Linnen discloses obtaining a plurality of operation records of a plurality of operated files, and obtaining operated files corresponding to a first operation based on the plurality of operation records, wherein the plurality of operation records correspond to the plurality of operated files, and each of the plurality of operation records is for recording an operation on an operated file corresponding to the operation record (Chen, paragraph 16, file operations). The combination of Chen, Adams, and Linnen does not explicitly state further obtaining, one by one from the operated files corresponding to the first operation, an operated file that matches a preset abnormal file name extension; and determining, when a quantity of operated files that match the preset abnormal file name extension is greater than a preset quantity, the operated file that matches the preset abnormal file name extension as the target file. However, analyzing file name extensions for ransomware detection in such a fashion was well known in the art as evidenced by Massiglia. Since the inventions encompass the same field of endeavor, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the combination of Chen, Adams, and Linnen by adding the ability for further obtaining, one by one from the operated files corresponding to the first operation, an operated file that matches a preset abnormal file name extension; and determining, when a quantity of operated files that match the preset abnormal file name extension is greater than a preset quantity, the operated file that matches the preset abnormal file name extension as the target file as provided by Massiglia (see paragraph 394, determines preponderance of files of particular file type with incorrect filename pattern, and paragraph 396, examining filename pattern includes suffixes of particular file types). One of ordinary skill in the art would have recognized the benefit that analyzing filename formats would assist in determining possible security threats (see Massiglia, paragraph 396). Regarding claim 11, the combination of Chen, Adams, and Linnen discloses wherein the at least one processor is further configured to: obtain a plurality of operation records of a plurality of operated files, and obtain, based on the plurality of operation records, an operated file on which an operation is performed by a same device, wherein the plurality of operation records correspond to the plurality of operated files, and each of the plurality of operation records is for recording an operation on an operated file corresponding to the operation record (Chen, paragraph 16, file operations). The combination of Chen, Adams, and Linnen does not explicitly state that the performed operation is a write operation and further successively obtaining a write offset and a write length of the operated file on which the write operation is performed by the same device; accumulating, if a current write offset is greater than a previous write offset for the operated file on which the write operation is performed by the same device, a current write length and a previous write length for the operated file to obtain an accumulated write length value of the operated file; obtaining a write ratio of the operated file based on a size of the operated file and the accumulated write length value; and determining, if the write ratio of the operated file within a preset duration is not less than a preset write ratio, the operated file on which the write operation is performed by the same device as the target file. However, analyzing write operations for ransomware detection in such a fashion was well known in the art as evidenced by Massiglia. Since the inventions encompass the same field of endeavor, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the combination of Chen, Adams, and Linnen by adding the ability that the performed operation is a write operation and further successively obtaining a write offset and a write length of the operated file on which the write operation is performed by the same device; accumulating, if a current write offset is greater than a previous write offset for the operated file on which the write operation is performed by the same device, a current write length and a previous write length for the operated file to obtain an accumulated write length value of the operated file; obtaining a write ratio of the operated file based on a size of the operated file and the accumulated write length value; and determining, if the write ratio of the operated file within a preset duration is not less than a preset write ratio, the operated file on which the write operation is performed by the same device as the target file as provided by Massiglia (see paragraph 363, examines file compressibility, and paragraph 496, metrics include compressibility of writes). One of ordinary skill in the art would have recognized the benefit that analyzing compressibility metrics would assist in determining whether or not data is encrypted (see Massiglia, paragraph 363). Regarding claim 12, the combination of Chen, Adams, and Linnen discloses wherein the at least one processor is further configured to perform the following operations: obtain a plurality of operation records of a plurality of operated files, and obtain operated files corresponding to a first operation based on the plurality of operation records, wherein the plurality of operation records correspond to the plurality of operated files, and each of the plurality of operation records is for recording an operation on an operated file corresponding to the operation record (Chen, paragraph 16, file operations). The combination of Chen, Adams, and Linnen does not explicitly state further obtaining, one by one from the operated files corresponding to the first operation, an operated file that matches a preset abnormal file name extension; and determining, when a quantity of operated files that match the preset abnormal file name extension is greater than a preset quantity, the operated file that matches the preset abnormal file name extension as the target file. However, analyzing file name extensions for ransomware detection in such a fashion was well known in the art as evidenced by Massiglia. Since the inventions encompass the same field of endeavor, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the combination of Chen, Adams, and Linnen by adding the ability for further obtaining, one by one from the operated files corresponding to the first operation, an operated file that matches a preset abnormal file name extension; and determining, when a quantity of operated files that match the preset abnormal file name extension is greater than a preset quantity, the operated file that matches the preset abnormal file name extension as the target file as provided by Massiglia (see paragraph 394, determines preponderance of files of particular file type with incorrect filename pattern, and paragraph 396, examining filename pattern includes suffixes of particular file types). One of ordinary skill in the art would have recognized the benefit that analyzing filename formats would assist in determining possible security threats (see Massiglia, paragraph 396). Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to Victor Lesniewski whose telephone number is (571)272-2812. The examiner can normally be reached Monday thru Friday, 9am to 5pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Carl Colin can be reached at 571-272-3862. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /Victor Lesniewski/Primary Examiner, Art Unit 2493
Read full office action

Prosecution Timeline

Sep 27, 2024
Application Filed
Dec 31, 2024
Response after Non-Final Action
Mar 10, 2026
Non-Final Rejection mailed — §103
Jun 08, 2026
Response Filed
Aug 10, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750362
SECURE ELEMENT ARRAYS IN INTERNET-OF-THINGS SYSTEMS
3y 5m to grant Granted Sep 29, 2026
Patent 12743512
SYSTEMS AND METHODS FOR REAL-TIME DATABASE SCANNING USING REPLICATION STREAM
2y 3m to grant Granted Sep 22, 2026
Patent 12739249
Method and Apparatus for Authentication and Authorization
3y 9m to grant Granted Sep 15, 2026
Patent 12730866
ADAPTIVE USER ENROLLMENT FOR ELECTRONIC DEVICES
3y 11m to grant Granted Sep 08, 2026
Patent 12713233
METHOD AND APPARATUS FOR UE AND APPLICATION FUNCTION SESSION PROTECTION FOR MODEL TRANSFER
1y 9m to grant Granted Aug 18, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
58%
Grant Probability
99%
With Interview (+55.3%)
3y 3m (~1y 3m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 491 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month