Prosecution Insights
Last updated: August 17, 2026
Application No. 18/899,005

RAPID ALLOWED RESOURCE REFLECTION

Final Rejection §103§112
Filed
Sep 27, 2024
Examiner
FARAMARZI, GITA
Art Unit
2496
Tech Center
2400 — Computer Networks
Assignee
CyberArk Software Ltd.
OA Round
2 (Final)
52%
Grant Probability
Moderate
3-4
OA Rounds
1y 9m
Est. Remaining
70%
With Interview

Examiner Intelligence

Grants 52% of resolved cases
52%
Career Allowance Rate
41 granted / 79 resolved
-6.1% vs TC avg
Strong +18% interview lift
Without
With
+18.1%
Interview Lift
resolved cases with interview
Typical timeline
3y 7m
Avg Prosecution
21 currently pending
Career history
117
Total Applications
across all art units

Statute-Specific Performance

§101
8.4%
-31.6% vs TC avg
§103
56.1%
+16.1% vs TC avg
§102
5.3%
-34.7% vs TC avg
§112
29.1%
-10.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 79 resolved cases

Office Action

§103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Status of Claims The following is a Final Office Action in response to applicant’s filing on May 11, 2026. Claims 1, 2, 12, and 20 were amended. As a result, claims 1-20 are pending, of which claim 1 is in independent form. Response to Amendment Applicant’s amendment regarding the specification obviates the objection, therefore the specification objection is withdrawn. Applicant’s amendments regarding the claims 1, 12, and 20 obviate the 112(b) rejection, therefore the 112(b) objection is withdrawn. However, upon new amendments, a new ground of rejection under 35 USC § 112(b) is made. Response to Arguments In view of the remarks, submitted on May 11, 2026, applicant’s arguments have been carefully and respectfully considered but are not persuasive. On pages 8-10 of remarks, Applicant argues that Coffing “fails to explicitly teach or suggest "multiple policy engines associated with different policy types or different types of resources" let alone "wherein fetching the two or more up-to-date policies associated with the network identity comprises fetching the two or more policies from multiple policy engines associated with different policy types or different types of resources" as recited in amended claim 1”. The Examiner disagrees with Applicant and has a different view of prior art teachings and claim interpretation. Coffing expressly teaches the API gateway invokes all other policies associated with the API and that security sidecars validate one or more policies for requests directed to different microservices, see paragraphs [0027]-[0028]. Moreover, Coffing teaches that different APIs and microservices maybe governed by different authorization policies and permissions, including different authorization policies different parts of an API, in paragraphs [0048]-[0052]. In addition, Coffing discloses “which may then call on the security sidecar 160 to validate a request or a token exchange service to augment the request. The security sidecar 160 may look for a policy rule that matches the request and then validate one or more policies for the request. The security sidecar 160 may further check if the incoming JWT token is valid and signed using the key that was issued by the Certificate Authority (Vault)” in paragraph [0028], Thus, under the broadest reasonable interpretation, the security sidecar is equated to multiple policy engines. Therefore, the applicant’s argument is not persuasive and the rejection under 103 is maintained. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 1-20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claim 1 is rejected as being indefinite. Claim 1 recites “a batch of one or more up-to-date policies”. The term “up-to-date” is a relative term which renders the claim indefinite. The term is not defined by the claim, the specification does not provide a standard for ascertaining the requisite degree, and one of ordinary skill in the art would not be reasonably apprised of the scope of the invention. The use of term “up-to-date” renders the scope of the claim unclear because it lacks objective temporal boundaries for determining when a policy is up-to-date, such metes and bounds of the claim cannot be determined with reasonable certainty. Claim 12 is rejected as being indefinite. Claim 12 recites “wherein identifying the one or more network resources accessible to the network identity is performed dynamically”. The term “dynamically” renders the claim indefinite because it fails to provide reasonable certainty as to the scope of the claimed invention. It is not clear whether “dynamically” requires real-time processing, or adaptive operation. Therefore, it is unclear what is the intended scope of the claim invention and the metes and bounds of the claim cannot be determined with reasonable certainty. Claim 20 is rejected as being indefinite. Claim 20 recites “a batch of one or more up-to-date policies”. The term “up-to-date” is a relative term which renders the claim indefinite. The term is not defined by the claim, the specification does not provide a standard for ascertaining the requisite degree, and one of ordinary skill in the art would not be reasonably apprised of the scope of the invention. The use of term “up-to-date” renders the scope of the claim unclear because it lacks objective temporal boundaries for determining when a policy is up-to-date, such metes and bounds of the claim cannot be determined with reasonable certainty. The same reasons apply to dependent claims 2-11, 13-19. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claims 1-2, 4-7, 9-13, 15-18, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Coffing (US 2022/0224535 A1), hereinafter Coffing in view of Hwang et al. (US 11,860,869 B1), hereinafter Hwang. In regards to claim 1, Coffing discloses a non-transitory computer readable medium including instructions that, when executed by at least one processor (Coffing, Para. 0068, Non-transitory computer-readable storage media refer to any medium or media that participate in providing instructions to a central processing unit (“CPU”) for execution. Such media can take many forms, including, but not limited to, non-volatile and volatile media such as optical or magnetic disks and dynamic memory, respectively), cause the at least one processor to perform operations for dynamically identifying at least one network resource accessible to a network identity (Coffing, Para. 0048, FIG. 5 illustrates an interface of an API management system of the dynamic authorization system), the operations comprising: receiving a request associated with a network identity (Coffing, Para. 0028, an exemplary incoming request may be received by the proxy, which may then call on the security sidecar 160 to validate a request or a token exchange service to augment the request); identifying a first data element associated with the network identity (Coffing, Para. 0028, the security sidecar 160 may further check if the incoming JWT token is valid and signed using the key that was issued by the Certificate Authority (Vault)); fetching(Coffing, Para. 0028, the security sidecar 160 may look for a policy rule that matches the request and then validate one or more policies for the request. The security sidecar 160 may further check if the incoming JWT token is valid and signed using the key that was issued by the Certificate Authority (Vault)) and (Coffing, Para. 0059, may involve real-time risk profiles/scoring on a transaction basis, as well as step-up authentications on a transactional basis and risk mitigation by combining behavioral baseline and risk attribute decision access control into a non-binary authorization platform), two or more policies associated with the network identity, wherein fetching the two or more policies associated with the network identity comprises fetching the two or more policies from multiple policy engines associated with different policy types or different types of resources (Coffing, Para. 0025, in certain default scenarios, the security sidecar 160 may validate if incoming requests were signed using a key generated by internal CA and inject a token (JWT)-signed using a private key of a microservice. The user context may be propagated, abridged or augmented depending on policy between microservices via minting or updates to the JWT) and (Coffing, Para. 0028, which may then call on the security sidecar 160 to validate a request or a token exchange service to augment the request. The security sidecar 160 may look for a policy rule that matches the request and then validate one or more policies for the request. The security sidecar 160 may further check if the incoming JWT token is valid and signed using the key that was issued by the Certificate Authority (Vault)), and wherein the two or more policies are at least one of (Coffing, Para. 0048, the interface may be utilized for security policy management of endpoints, such as API and microservices. For each microservice, different authorization policy may be set for different parts of API. Functions A, B, and C of FIG. 5 may be different parts of an API or microservice, or different privileges given to a user): located in two or more data storage locations, associated with two or more policy types, or associated with two or more types of resources (Coffing, Para. 0035, the authorization control plane 304 may also store security policies regarding accessing APIs, store user context received from the identity provider and authenticator 303, store user requests for data from APIs and user consents, define how a user may be authorized and authenticated, select proxy and security sidecar associated with each API, and store rules regarding how a sidecar may grant access to each APIs by requesting additional context validation) and (Coffing, Para. 0035, the authorization policy information point 660 may store user authorization level information representing a plurality of different policies governing permission to access a protected resource or microservice); evaluating based on the first data element and in association with at least one of the plurality of instances of the request (Coffing, Para. 0025, in certain default scenarios, the security sidecar 160 may validate if incoming requests were signed using a key generated by internal CA and inject a token (JWT)-signed using a private key of a microservice), a batch of one or more up-to-date policies (Coffing, Para. 0025, the security sidecar 160 allows in-place validation of policies (enforcement and decisions) for incoming requests and transformation of outgoing requests); and identifying, based on the evaluation, one or more network resources accessible to the network identity (Coffing, Paras. 0047-0048, At step 480, the API management 305 verifies whether the user has authorization to access the desired information from the particular API by validating the enriched token received from the client application 210). Coffing does not explicitly disclose generating a plurality of instances of the request; However, Hwang teaches generating a plurality of instances of the request (Hwang, Col. 3, Lines 46-52, in FIG. 1 , query engine 110 may receive query 140 and generate an initial plan to perform query 140 (as discussed below with regard to FIGS. 5, 6, and 9 ). Query engine 110 may then apply one or more cross-type optimization rules to identify a portion (or all) of query 140 that could be optimally performed by another type of query engine, query engine 130. Query engine 110 may then send a request 152 to query engine 130 to perform the portion of the query (e.g., a query formulated in a query language supported by query engine 130). Coffing and Hwang are both considered to be analogous to the claim invention because they are in the same field of distributing the evaluation of accessible network resources between a plurality of different policy engines and distribute the policies among different network entities. Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Coffing to incorporate the teachings of Hwang to include generating a plurality of instances of the request (Hwang, Col. 3, Lines 46-52, in FIG. 1). Doing so would aid to improve the performance of client applications by utilizing for the client applications the different, optimized features of different types of query engines (e.g., by providing a significant increase in the performance of OLAP style queries to a data set stored for an OLTP database(Hwang, Col. 3, Lines 9-14). In regards to claim 2, the combination of Coffing in view of Hwang teaches the non-transitory computer readable medium of claim 1, wherein the multiple policy engines (Coffing, Para. 0027, Such a client application 210 may trigger a request (e.g., by a button click). Such request may contain a payload and the access token (e.g., in the request header). The API gateway 130 may authenticate the call and perform authorization, not only checking the scope of authorizations but also invoking all other policies associated with the API) and (Coffing, Para. 0028, the security sidecar 160 may look for a policy rule that matches the request and then validate one or more policies for the request. The security sidecar 160 may further check if the incoming JWT token is valid and signed using the key that was issued by the Certificate Authority (Vault)) and (Coffing, Para. 0059, may involve real-time risk profiles/scoring on a transaction basis, as well as step-up authentications on a transactional basis and risk mitigation by combining behavioral baseline and risk attribute decision access control into a non-binary authorization platform). In regards to claim 4, the combination of Coffing in view of Hwang teaches the non-transitory computer readable medium of claim 1, wherein generating a plurality of instances of the request comprises at least one of: fragmenting the request (Hwang, Col. 3, Lines 52-60, Query engine 110 may then send a request 152 to query engine 130 to perform the portion of the query (e.g., a query formulated in a query language supported by query engine 130). Additionally, query engine 110 may provide a consistent view 154 of data set 122 to query engine 130 in order to perform the portion of the query—as query engine 110 may also support multiple concurrent updates or transactions to data 122 in addition to receiving and performing query 140.), modifying the request, or duplicating the request. Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Coffing to incorporate the teachings of Hwang to include wherein generating a plurality of instances of the request comprises at least one of: fragmenting the request (Hwang, Col. 3, Lines 52-60). Doing so would aid to improve the performance of client applications by utilizing for the client applications the different, optimized features of different types of query engines (e.g., by providing a significant increase in the performance of OLAP style queries to a data set stored for an OLTP database(Hwang, Col. 3, Lines 9-14). In regards to claim 5, the combination of Coffing in view of Hwang teaches the non-transitory computer readable medium of claim 1, wherein the first data element comprises at least one of: an authentication token, or identification information associated with the network identity (Coffing, Para. 0027, Such a client application 210 may trigger a request (e.g., by a button click). Such request may contain a payload and the access token (e.g., in the request header)). In regards to claim 6, the combination of Coffing in view of Hwang teaches the non-transitory computer readable medium of claim 1, wherein the two or more policy types comprise at least two of: a policy for accessing a virtual machine zero standing access, a policy for accessing a database zero standing access, a policy for standing access, a policy for accessing a cloud console, a policy for accessing a web application (Coffing, Para. 0027, the client application 210 may be a web application that may be accessible and visible via a web browser. Such a client application 210 may trigger a request (e.g., by a button click). Such request may contain a payload and the access token (e.g., in the request header). The API gateway 130 may authenticate the call and perform authorization, not only checking the scope of authorizations but also invoking all other policies associated with the API), a policy for accessing a second policy, or a policy for authorizing one or more identities (Coffing, Para. 0054, the users/services/things 605 may wish to access one or more microservices (e.g., business applications & workloads & microservices) 615, each of which may be associated with different security and authorization policies (described above in relation to FIG. 5) directed at not only granting or denying access, but also evaluating and scoring various attributes for risk). In regards to claim 7, the combination of Coffing in view of Hwang teaches the non-transitory computer readable medium of claim 1, wherein the first data element is further associated with the one or more network resources accessible to the network identity (Coffing, Para. 0046, this request includes the enriched token from step 450 and an API call to the particular API, referred to as an API endpoint. For example, the request may include an API path, such as “/account/123/transactions,” for the API management 305 to search for transactions at an account 123). In regards to claim 9, the combination of Coffing in view of Hwang teaches the non-transitory computer readable medium of claim 1, wherein the two or more data storage locations comprise at least two of: a relational database management system, a database (Coffing, Para. 0045, information utilized by a digital wallet application may be stored in a database of a bank), a data warehouse, a key-value store, a document store (Coffing, Para. 0033, the identity provider and authenticator 303 may store user credentials, such as login ID and password, and a user profile that includes information relevant to granting access to the user.), a columnar database, a graph database, an in-memory data grid, a file system, or an object storage. In regards to claim 10, the combination of Coffing in view of Hwang teaches the non-transitory computer readable medium of claim 1, wherein the two or more data storage locations are at least one of a cloud storage location or an on-premises storage location (Coffing, Para. 0018, the intelligent authorization system may be deployed in a hybrid-cloud or multi-cloud environment that includes services or microservices). In regards to claim 11, the combination of Coffing in view of Hwang teaches the non-transitory computer readable medium of claim 1, wherein the two or more policies are encrypted or are stored as plain text (Coffing, Para. 0027, the API gateway 130 may authenticate the call and perform authorization, not only checking the scope of authorizations but also invoking all other policies associated with the API. Upon successful authentication and authorization, the request may then be proxied to the appropriate microservice 140 in the mesh with an added JWT token that has been enriched with user data (e.g., from payload). Since the API gateway 130 is a microservice itself, the API gateway 130 may be aware of other microservices 140A-N in the network. The API gateway 130 may further sign the JWT token with its individual private key (e.g., generated with Vault), so that other microservices can verify the signed JWT token and identify the microservice). In regards to claim 12, the combination of Coffing in view of Hwang teaches the non-transitory computer readable medium of claim 1, wherein identifying the one or more network resources accessible to the network identity is performed dynamically (Coffing, Para. 0025, the security sidecar 160 allows in-place validation of policies (enforcement and decisions) for incoming requests and transformation of outgoing requests. In certain default scenarios, the security sidecar 160 may validate if incoming requests were signed using a key generated by internal CA and inject a token (JWT)-signed using a private key of a microservice) and (Coffing, Para. 0038, the micro perimeter authorizer 308 may vary the numbers of factors to verify user identity to determine scope of accessing each API or microservice. The defined policies for accessing each API may be easily and dynamically changed on an interface of the API management 305. To enforce the multi-factor authentication and authorization to each API, identity of the user is verified by each security sidecar associated with each API at every instance each API or microservice is invoked). In regards to claim 13, the combination of Coffing in view of Hwang teaches the non-transitory computer readable medium of claim 1, wherein the two or more types of resources comprise at least two of: a resource associated with a cloud virtual machine (Coffing, Para. 0018, the intelligent authorization system may be deployed in a hybrid-cloud or multi-cloud environment that includes services or microservices), a resource associated with an on-premises virtual machine, a resource associated with an account stored in a vault (Coffing, Para. 0021, the CA (e.g., Vault) may allow for reading and generation of dynamic digital certificates corresponding to security keys corresponding to service/workload/OAuth based API identity), or a resource associated with a cloud console workspace. In regards to claim 15, the non-transitory computer readable medium of claim 1, wherein two or more policies of a same type are stored in a hybrid data store (Coffing, Para. 0018, policies are able to constrain or augment existing identity related data to ensure each service gets only the data it needs to transact that function. The intelligent authorization system may be deployed in a hybrid-cloud or multi-cloud environment that includes services or microservices). In regards to claim 16, the combination of Coffing in view of Hwang teaches the non-transitory computer readable medium of claim 1, wherein the batch of one or more policies corresponds to a batch of one or more network resources associated with the network identity (Coffing, Para. 0051, same security policies for accessing a certain API may be set for a group of similar users). In regards to claim 17, the combination of Coffing in view of Hwang teaches the non-transitory computer readable medium of claim 16, wherein the batch of one or more network resources is associated with one of the plurality of instances of the request (Hwang, Col. 14, Lines 60-67, For example, node-specific query instructions 424 may be generated or compiled code that is distributed by leader node 420 to various ones of the compute nodes 430 to carry out the steps needed to perform a query, including executing the code to generate intermediate results of the query at individual compute nodes that may be sent back to the leader node 420). Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Coffing to incorporate the teachings of Hwang to include wherein the batch of one or more network resources is associated with one of the plurality of instances of the request (Hwang, Col. 14, Lines 60-67). Doing so would aid to improve the performance of client applications by utilizing for the client applications the different, optimized features of different types of query engines (e.g., by providing a significant increase in the performance of OLAP style queries to a data set stored for an OLTP database(Hwang, Col. 3, Lines 9-14). In regards to claim 18, the combination of Coffing in view of Hwang teaches the non-transitory computer readable medium of claim 8, wherein the first data element comprises the second data element (Coffing, Fig. 6) and (Coffing, Para. 0025, in certain default scenarios, the security sidecar 160 may validate if incoming requests were signed using a key generated by internal CA and inject a token (JWT)-signed using a private key of a microservice. The user context may be propagated, abridged or augmented depending on policy between microservices via minting or updates to the JWT). In regards to claim 20, the combination of Coffing in view of Hwang teaches the non-transitory computer readable medium of claim 1, wherein evaluating a batch of one or more up-to-date policies is performed in parallel (Hwang, Col. 3, Lines 55-60, Additionally query engine 110 may provide a consistent view 154 of data set 122 to query engine 130 in order to perform the portion of the query-as query engine 110 may also support multiple concurrent updates or transactions to data 122 in addition to receiving and performing query 140). Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Coffing to incorporate the teachings of Hwang to include wherein evaluating a batch of one or more up-to-date policies is performed in parallel (Hwang, Col. 3, Lines 55-60). Doing so would aid to improve the performance of client applications by utilizing for the client applications the different, optimized features of different types of query engines (e.g., by providing a significant increase in the performance of OLAP style queries to a data set stored for an OLTP database(Hwang, Col. 3, Lines 9-14). Claims 3, 8, and 14 are rejected under 35 U.S.C. 103 as being unpatentable over Coffing (US 2022/0224535 A1), hereinafter Coffing in view of Hwang et al. (US 11,860,869 B1), hereinafter Hwang, and further in view of Chang et al. (US 2009/0288136 A1), hereinafter Change. In regards to claim 3, the combination of Coffing in view of Hwang does not explicitly teach the non-transitory computer readable medium of claim 2, wherein fetching the two or more policies associated with the network identity comprises fetching the two or more policies in parallel in association with at least one of plurality of instances of the request. However, Chang teaches wherein fetching the two or more policies associated with the network identity comprises fetching the two or more policies in parallel in association with at least one of plurality of instances of the request (Chang, Para. 0007, techniques for highly parallel evaluation of XACML policies are described herein…one for each of the extracted attributes, in a policy store having stored therein rules and policies written in XACML (extensible access control markup language), where the rules and policies are optimally stored including being indexed using a bit vector algorithm). Coffing, Hwang and Chang are all considered to be analogous to the claim invention because they are in the same field of distributing the evaluation of accessible network resources between a plurality of different policy engines and distribute the policies among different network entities. Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Coffing and Hwang to incorporate the teachings of Chang to include wherein fetching the two or more policies associated with the network identity comprises fetching the two or more policies in parallel in association with at least one of plurality of instances of the request (Chang, Para. 0007). Doing so would aid to one or more efficient indexes to build and maintained based on the attributes of the rules and policies of the policy store for improving search speeds. In addition, the indexes and/or the rules and policies are optimized using a bit vector algorithm for further enhancing search efficiency (Change, Para. 0018). In regards to claim 8, the combination of Coffing in view of Hwang does not explicitly teach the non-transitory computer readable medium of claim 7, wherein a second data element is generated based on at least one policy index and at least one resource index. However, Chang teaches wherein a second data element is generated based on at least one policy index and at least one resource index (Chang, Para. 0022, individual search per attribute search results is then combined to generate a final single search result which is used to determine whether a particular client is eligible for accessing a particular resource of a datacenter) and (Chang, Para. 0018, one or more efficient indexes are built and maintained based on the attributes of the rules and policies of the policy store for improving search speeds. In addition, the indexes and/or the rules and policies are optimized using a bit vector algorithm for further enhancing search efficiency) and (Chang, Para. 0053, Policies can be grouped into one or more policy sets, which can also contain other policy sets, creating a hierarchy. Each policy and rule have a target. The target is a simple predicate that specifies which subjects, resources, actions, and environments the policy or rule applies to). Coffing, Hwang and Chang are all considered to be analogous to the claim invention because they are in the same field of distributing the evaluation of accessible network resources between a plurality of different policy engines and distribute the policies among different network entities. Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Coffing and Hwang to incorporate the teachings of Chang to include wherein a second data element is generated based on at least one policy index and at least one resource index (Chang, Para. 0022) and (Chang, Para. 0018) and (Chang, Para. 0053). Doing so would aid to one or more efficient indexes to build and maintained based on the attributes of the rules and policies of the policy store for improving search speeds. In addition, the indexes and/or the rules and policies are optimized using a bit vector algorithm for further enhancing search efficiency (Change, Para. 0018). In regards to claim 14, the combination of Coffing in view of Hwang does not explicitly teach the non-transitory computer readable medium of claim 1, wherein two or more policies of a same type are stored in a same storage location. However, Chang teaches wherein two or more policies of a same type are stored in a same storage location (Chang, Para. 0022, including a rule engine 108 for determining whether a particular client is eligible to access any of the servers 104-105 based on rules and policies of the policy store 109). Coffing, Hwang and Chang are all considered to be analogous to the claim invention because they are in the same field of distributing the evaluation of accessible network resources between a plurality of different policy engines and distribute the policies among different network entities. Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Coffing and Hwang to incorporate the teachings of Chang to include wherein two or more policies of a same type are stored in a same storage location (Chang, Para. 0022). Doing so would aid to one or more efficient indexes to build and maintained based on the attributes of the rules and policies of the policy store for improving search speeds. In addition, the indexes and/or the rules and policies are optimized using a bit vector algorithm for further enhancing search efficiency (Change, Para. 0018). Claim 19 is rejected under 35 U.S.C. 103 as being unpatentable over Coffing (US 2022/0224535 A1), hereinafter Coffing in view of Hwang et al. (US 11,860,869 B1), hereinafter Hwang, and further in view of Philbrick et al. (US 2005/0204058 A1), hereinafter Philbrick. In regards to claim 19, the combination of Coffing in view of Hwang does not explicitly teach the non-transitory computer readable medium of claim 1, wherein identifying one or more network resources accessible to the network identity comprises buffering the network resources accessible to the network identity to equal a page size. However, Philbrick teaches wherein identifying one or more network resources accessible to the network identity comprises buffering the network resources accessible to the network identity to equal a page size (Philbrick, Para. 0113, in the driver we allocate a block of contiguous memory (typically a page, which is typically 4 k). We write the address of that block to the INIC with the bottom bits of the address specifying the number of buffers in the block. In order to receive 1514-byte frames (maximum ether frame size), however, we can only fit two buffers in a 4-k page, which is not a substantial savings. Fortunately, network frames tend to be either large (˜1500 bytes), or small (<256 bytes)). Coffing, Hwang and Philbrick are all considered to be analogous to the claim invention because they are in the same field of distributing the evaluation of accessible network resources between a plurality of different policy engines and distribute the policies among different network entities. Therefore, it would have been obvious to someone ordinary skill in the art before the effective filling date of the claimed invention to have modified Coffing and Hwang to incorporate the teachings of Philbrick to include wherein identifying one or more network resources accessible to the network identity comprises buffering the network resources accessible to the network identity to equal a page size (Philbrick, Para. 0113). Doing so would aid to Interrupts may be reduced to four interrupts per 64 k SMB read and two interrupts per 64 k SMB write. Other advantages include a reduction of CPU reads over the PCI bus and fewer PCI operations per receive or transmit transaction (Philbrick, Para. 0013). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. See PTO-892. THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to GITA FARAMARZI whose telephone number is (571)272-0248. The examiner can normally be reached Monday- Friday 9:00 am- 6:00 pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jorge L. Ortiz-Criado can be reached at (571)272-7624. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /GITA FARAMARZI/Examiner, Art Unit 2496 /JORGE L ORTIZ CRIADO/Supervisory Patent Examiner, Art Unit 2496
Read full office action

Prosecution Timeline

Sep 27, 2024
Application Filed
Feb 11, 2026
Non-Final Rejection mailed — §103, §112
May 11, 2026
Response Filed
Jun 24, 2026
Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12627633
SYSTEM AND METHOD FOR APPLICATION TRAFFIC AND RUNTIME BEHAVIOR LEARNING AND ENFORCEMENT
5y 9m to grant Granted May 12, 2026
Patent 12339997
ENTITY FOCUSED NATURAL LANGUAGE GENERATION
2y 1m to grant Granted Jun 24, 2025
Patent 12316648
Data value classifier
5y 10m to grant Granted May 27, 2025
Patent 12301564
VIRTUAL SESSION ACCESS MANAGEMENT
4y 3m to grant Granted May 13, 2025
Patent 12256022
BLOCKCHAIN TRANSACTION COMPRISING RUNNABLE CODE FOR HASH-BASED VERIFICATION
3y 3m to grant Granted Mar 18, 2025
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
52%
Grant Probability
70%
With Interview (+18.1%)
3y 7m (~1y 9m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 79 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month