Prosecution Insights
Last updated: August 17, 2026
Application No. 18/924,925

FRAMEWORK FOR LEARNING BASED RECOMMENDATION AND SCORING FOR OPERATOR ACCESS TO INFRASTRUCTURE

Final Rejection §101§103
Filed
Oct 23, 2024
Examiner
GADALLA, HANY S
Art Unit
2493
Tech Center
2400 — Computer Networks
Assignee
ORACLE INTERNATIONAL Corporation
OA Round
2 (Final)
72%
Grant Probability
Favorable
3-4
OA Rounds
1y 0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 72% — above average
72%
Career Allowance Rate
135 granted / 187 resolved
+14.2% vs TC avg
Strong +37% interview lift
Without
With
+37.2%
Interview Lift
resolved cases with interview
Typical timeline
2y 10m
Avg Prosecution
18 currently pending
Career history
203
Total Applications
across all art units

Statute-Specific Performance

§101
8.4%
-31.6% vs TC avg
§103
55.7%
+15.7% vs TC avg
§102
15.7%
-24.3% vs TC avg
§112
14.7%
-25.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 187 resolved cases

Office Action

§101 §103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION The present office action is responsive to communications received on 06/17/2026. Information Disclosure Statement The information disclosure statement (IDS) submitted on 06/12/2026 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Status of Claims Claims 1-5, 8-12 and 14-18 were amended. Claims 1-20 are pending. Response to Arguments Applicant arguments regarding the 35 USC § 101 rejection are not persuasive. Reciting a machine learning model or a processor in a computing device executing to process data to results in certain steps of adjusting level of access privileges does not overcome the rejection. The examiner maintains that the claims recite a mental process or steps of organizing human activities. With respect to the 35 USC § 102 rejection the arguments are most not persuasive given the broadest reasonable interpretation because the dependent claims show that past actions are used to calculate risk and actions for events moving forward which is what is taught by the prior art. Additionally a secondary reference is used for minor clarification and to advance compact prosecution that teaches the inventive concept as discussed during the applicant interview on June 17, 2026. See also the pertinent prior art section in the conclusion section that recites additional prior art that also have the same inventive concept and therefore the examiner believes that the instant application is not allowable. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-20 the are rejected under 35 U.S.C. §101 because the claimed invention is directed to mathematical or mental steps (step 2A, prong 1) without significantly more. 2019 Revised Patent Eligibility Guidance (PEG): Step 1: As claims 1-20 are directed to a method, system and non-transitory computer readable medium therefore they are all within at least one of the four statutory categories. 2019 PEG: Step 2A - Prong One: Regarding Prong One of Step 2A of the 2019 PEG (which collectively includes the guidance in the January 7, 2019 Federal Register notice and the October 2019 update issued by the USPTO), the claim limitations are to be analyzed to determine whether, under their broadest reasonable interpretation, they “recite” a judicial exception or in other words whether a judicial exception is “set forth” or “described” in the claims. An “abstract idea” judicial exception is subject matter that falls within at least one of the following groupings: a) certain methods of organizing human activity, b) mental processes, and/or c) mathematical concepts. Representative independent claims 1, 8 and 14 include limitations that recite at least one abstract idea. For instance, independent claim 1 recites: implementing an operator access mechanism; generating a machine learning model for operator access; providing recommendations for the operator access using the machine learning model; and performing scoring for the operator access. The Examiner submits that the foregoing underlined limitations constitute mathematical or mental steps using generic computing device (see MPEP § 2106.05(f) and § 2106.05(g)). Accordingly, the claim recites at least one abstract idea. While the other independent claims 1, 8 and 14 although might have slight variations but essentially recites the same scope of claim limitations as independent claim 1. Furthermore, dependent claims 2-7, 9-13 and 15-20 further fail to make the abstract parent claims any less abstract by reciting insignificant extra-solution activities. Therefore, dependent claims 2-7, 9-13 and 15-20 fail to make the abstract parent claims any less abstract because claims 2-7, 9-13 and 15-20 all recite limitations for mathematical and/or mental process while using generic computing devices or components. 2019 PEG: Step 2A - Prong Two: Regarding Prong Two of Step 2A of the 2019 PEG, it must be determined whether the claim as a whole integrates the abstract idea into a practical application. As noted in the 2019 PEG, it must be determined whether any additional elements in the claim beyond the abstract idea integrate the exception into a practical application in a manner that imposes a meaningful limit on the judicial exception. The courts have indicated that additional elements merely using a computer to implement an abstract idea, adding insignificant extra solution activity, or generally linking use of a judicial exception to a particular technological environment or field of use do not integrate a judicial exception into a “practical application.” In the present case, the additional limitations beyond the above-noted at least one abstract idea recited in the claim are as follows (where the bolded portions are the “additional limitations” while the underlined portions continue to represent the at least one “abstract idea”): Claim 1 recites: implementing an operator access mechanism; generating a machine learning model for operator access; providing recommendations for the operator access using the machine learning model; (Mental process or Human activity combined with conventional computer implementation, see MPEP § 2106.05(g) and MPEP § 2106.05(f)). While the other independent claims 8 and 14 although might have slight variations but essentially recites the same scope of claim limitations as independent claim 1. For the following reasons, the Examiner submits that the above identified additional limitations do not integrate the above-noted at least one abstract idea into a practical application. Thus, taken alone, the additional elements do not integrate the at least one abstract idea into a practical application. Looking at the additional limitations as an ordered combination adds nothing that is not already present when looking at the elements taken individually. For instance, there is no indication that the additional elements, when considered as a whole, reflect an improvement in the functioning of a computer or an improvement to another technology or technical field, apply or use the above-noted judicial exception to effect a particular authentication apparatus that is integral to the claim, effect a transformation or reduction of a particular article to a different state or thing, or apply or use the judicial exception in some other meaningful way beyond generally linking the use of the judicial exception to a particular technological environment, such that the claim as a whole is not more than a drafting effort designed to monopolize the exception (see 2019 PEG and MPEP § 2106.05). For these reasons, representative independent claims 1, 8 and 14 do not recite additional elements that integrate the judicial exception into a practical application. Accordingly, representative independent claims 1, 8 and 14 are directed to at least one abstract idea. The remaining dependent claim limitations not addressed above fail to integrate the abstract idea into a practical application. Thus, taken alone, any additional elements do not integrate the at least one abstract idea into a practical application. Therefore, the claims are directed to at least one abstract idea. 2019 PEG: Step 2B: Regarding Step 2B of the 2019 PEG, representative independent claim 1 does not include additional elements (considered both individually and as an ordered combination) that are sufficient to amount to significantly more than the judicial exception for reasons the same as those discussed above with respect to determining that the claim does not integrate the abstract idea into a practical application. Regarding the additional limitation of “implementing an operator access mechanism; generating a machine learning model for operator access; providing recommendations for the operator access using the machine learning model;”, which the Examiner submits merely disclose generic computing devices or components (such as illustrated in applicant’s drawings Figs. 1 and 14) to implement the abstract idea. Furthermore, the Examiner further submits that such steps that are recited in the rest of the claim are not unconventional as they merely consist of collecting and computing data in a system and perform an action based on the analysis. See MPEP 2106.05(d)(II). While the other independent claims 8 and 14 although might have slight variations but essentially recites the same scope of claim limitations as independent claim 1. The dependent claims do not include additional elements (considered both individually and as an ordered combination) that are sufficient to amount to significantly more than the judicial exception. Therefore, the dependent claims add additional elements that are considered to be generic computer devices and/or components (such as illustrated in applicant’s drawings Figs. 1 and 14) and that are simply applying a generic computer to implement the abstract idea, the Examiner further submits that such steps are not unconventional as they merely consist of collecting and analyzing data in a system and perform an action based on the computation and analysis. The steps of receiving data, analyzing data, and transmitting data are considered well-understood routine and conventional (See MPEP 2106.05(d)(II)). Therefore, claims 1-20 are ineligible under 35 USC §101. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claim(s) 1-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Bhargava et al. (US 20250267157 A1) hereinafter referred to as Bhargava in view of Vasudevan et al. (US 20250165632 A1) hereinafter referred to as Vasudevan. With respect to claim 14, Bhargava discloses: A computer program product embodied on a non-transitory computer readable medium, the non-transitory computer readable medium having stored thereon a sequence of instructions which, when executed by a processor, causes the processor to perform a set of acts, the set of acts comprising: implementing an operator access control mechanism; (Bhargava Abstract teaches “determining security risks related to local administrator rights (LAR) [operator access control mechanism] activity are provided herein. An example computer-implemented method includes obtaining data pertaining to one or more activities performed by at least one user acting in connection with at least one granted set of LAR”). generating a machine learning model that generates one or more recommendations for operator access requests; (Bhargava ¶44 teaches the process using a machine model when reciting “a state machine model is built from one or more functional security requirements” ¶45 and 47 teaches generating recommendations of types of risks and actions). and providing, in response to receipt of a respective operator access request, a recommendation for the respective operator access request using the machine learning model; (Bhargava ¶47 “determining and providing, to the given user, at least one suggestion (e.g., associated with the best or optimized option) based at least in part on the security risk level of the corresponding action [request] and/or activity in question.”) Bhargava does not explicitly disclose: wherein the recommendation comprises at least a privilege level to be granted for the respective operator access request by the operator access control mechanism. However, Vasudevan in an analogous art discloses: wherein the recommendation comprises at least a privilege level to be granted for the respective operator access request by the operator access control mechanism. (Vasudevan Fig. 2C teaches a request that passes by the “Dynamic Permissions Calculator 250” from the “Gate Keeper 248” [mechanism]. Additionally, ¶65 recites “the risk score may attempt to identify whether the data access request is valid for the dynamically calculated permissions [privilege level to be granted] enforced on a granular basis for the particular data. At step 410, a decision is executed on whether to present the data on the page or take a remedial action based on the risk.”). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Bhargava wherein the recommendation comprises at least a privilege level to be granted for the respective operator access request by the operator access control mechanism as taught by Vasudevan to allow for dynamic privilege control (see Vasudevan ¶65). Claims 1 and 8 recite “method” and “system” respectively. While the claims have slight variation in language but recite the same matter as claim 14 and therefore rejected based on the same rationale. With respect to claim 15, Bhargava discloses: The computer program product of claim 14, wherein the one or more recommendations for the operator access requests using the machine learning model are provided by classifying incident tickets behind a privileged access, and using risk categorization to classify operator actions for a given problem class. (Bhargava Abstract “local administrator rights (LAR) activity are provided herein. An example computer-implemented method includes obtaining data pertaining to one or more activities performed by at least one user acting in connection with at least one granted set of LAR; classifying the one or more activities into one or more security risk-based categories by processing at least a portion of the obtained data;”). Claims 2 and 9 recite “method” and “system” respectively. While the claims have slight variation in language but recite the same matter as claim 15 and therefore rejected based on the same rationale. With respect to claim 16, Bhargava discloses: The computer program product of claim 14, wherein the machine learning model is used to identify a dominant cluster of operator action for a given problem class to provide the recommendation for the respective operator access request. (Bhargava ¶69 “machine learning algorithms can include one or more clustering algorithms, which can identify groups of normal behavior and detect outliers, helping categorize user activities into risk categories. By way of illustration, consider a scenario wherein a clustering algorithm categorizes certain user activities into high risk, medium risk, and low risk categories based at least in part on deviations from established patterns in historical data.”) Claims 3 and 10 recite “method” and “system” respectively. While the claims have slight variation in language but recite the same matter as claim 16 and therefore rejected based on the same rationale. With respect to claim 17, Bhargava discloses: The computer program product of claim 14, wherein the recommendation further comprises a duration of access (Bhargava ¶67 part of the recommendations process comprising “a user with LAR duration of access] and atypical sequence of system calls during the software installation, flagging it as a potential anomaly.”) Claims 4 and 11 recite “method” and “system” respectively. While the claims have slight variation in language but recite the same matter as claim 17 and therefore rejected based on the same rationale. With respect to claim 18, Bhargava discloses: The computer program product of claim 14, wherein a score is calculated for operator access associated with the respective operator access request based at least in part upon an amount of time associated with the operator access and an identification of resources actually accessed for the operator access. (Bhargava ¶67 part of determining severity level, interpreted as score, process comprising “a user with LAR [operator access] attempts to install unauthorized software. In at least one embodiment an anomaly detection algorithm can be implemented to detect an unusually short duration [amount of time for the operator access] and atypical sequence of system calls [resources actually accessed for the operator access] during the software installation, flagging it as a potential anomaly.”) Claims 5 and 12 recite “method” and “system” respectively. While the claims have slight variation in language but recite the same matter as claim 18 and therefore rejected based on the same rationale. With respect to claim 19, Bhargava discloses: The computer program product of claim 18, wherein the score is used as feedback for the machine learning model. (Bhargava ¶75 using information such as severity “performing at least one automated action (such as detailed in connection with step 606) can include re-training [feedback] the at least one machine learning-based outlier detection model based at least in part on feedback related to the at least a portion of the one or more security-related recommendations.”) Claim 6 recites a “method”. While the claim has slight variation in language but recites the same matter as claim 19 and therefore rejected based on the same rationale. With respect to claim 20, Bhargava discloses: The computer program product of claim 14, wherein the machine learning model uses a multi-phase approach for clustering comprising a first phase for activity clustering, a second phase for cluster identification, and a third phase for cluster fingerprinting. (Bhargava ¶69 “machine learning algorithms can include one or more clustering algorithms, which can identify groups [first phase] of normal behavior and detect outliers [a second phase], helping categorize user activities into risk categories [third phase]. By way of illustration, consider a scenario wherein a clustering algorithm categorizes certain user activities into high risk, medium risk, and low risk categories based at least in part on deviations from established patterns in historical data.”) Claims 7 and 13 recite “method” and “system” respectively. While the claims have slight variation in language but recite the same matter as claim 20 and therefore rejected based on the same rationale. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Kumar et al. (US 20240137368 A1) Fig. 12 discloses receiving a request and evaluating it based on risk and sending an admin (second user) a request to modify first user access request privileges level. Harres et al. (US 20230205903 A1) ¶133-135 teach intercepting requests to determine permission level. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to HANY S GADALLA whose telephone number is (571)272-2322. The examiner can normally be reached Mon to Fri 8:00AM - 4:00PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Carl Colin can be reached at (571) 272-3862. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /HANY S. GADALLA/ Primary Examiner, Art Unit 2493
Read full office action

Prosecution Timeline

Oct 23, 2024
Application Filed
Mar 18, 2026
Non-Final Rejection mailed — §101, §103
Jun 17, 2026
Applicant Interview (Telephonic)
Jun 17, 2026
Response Filed
Jun 17, 2026
Examiner Interview Summary
Aug 05, 2026
Final Rejection mailed — §101, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12705314
Using Ownership Identifiers in Metadata in a Memory for Protecting Encrypted Data Stored in the Memory
3y 8m to grant Granted Aug 11, 2026
Patent 12705399
INTERACTION DATA INTEGRITY PROTECTION FOR A DISTRIBUTED SYSTEM
2y 6m to grant Granted Aug 11, 2026
Patent 12700993
KEY MANAGEMENT USING ATTRIBUTE CERTIFICATES (KXAC)
3y 4m to grant Granted Aug 04, 2026
Patent 12695591
SECURITY IN NETWORKS
2y 4m to grant Granted Jul 28, 2026
Patent 12695603
KEY REUSE IN A CLOUD ENVIRONMENT
1y 12m to grant Granted Jul 28, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
72%
Grant Probability
99%
With Interview (+37.2%)
2y 10m (~1y 0m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 187 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month