Prosecution Insights
Last updated: October 02, 2026
Application No. 18/931,143

DYNAMIC SECURITY EVENTS FRAMEWORK FOR ADAPTIVE AUTHENTICATION

Final Rejection §103§112
Filed
Oct 30, 2024
Examiner
CARNES, THOMAS A
Art Unit
2436
Tech Center
2400 — Computer Networks
Assignee
Workday Inc.
OA Round
2 (Final)
71%
Grant Probability
Favorable
3-4
OA Rounds
1y 3m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 71% — above average
71%
Career Allowance Rate
60 granted / 85 resolved
+12.6% vs TC avg
Strong +71% interview lift
Without
With
+70.6%
Interview Lift
resolved cases with interview
Typical timeline
3y 2m
Avg Prosecution
17 currently pending
Career history
110
Total Applications
across all art units

Statute-Specific Performance

§101
6.0%
-34.0% vs TC avg
§103
61.4%
+21.4% vs TC avg
§102
9.4%
-30.6% vs TC avg
§112
20.1%
-19.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 85 resolved cases

Office Action

§103 §112
DETAILED ACTION This Office Action is in response to the communication filed on 5/12/2026. Claims 1-20 are pending. Claims 1, 3, 7-8, 10, 14-15, 17 and 20 have been amended Claims 1-20 are rejected. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Objections Claim objections, recited in the previous office action, are withdrawn. Claims 1, 8 and 15 are objected to because of the following informalities: The limitations recite “a plurality of analyzers”, the amended limitations recite “processors comprising… one or more analyzers”. A plurality does not include a single analyzer whereas one or more includes a single analyzer. It is not clear is applicant intends these analyzers to be the same as the plurality of analyzers or different analyzers. Additionally, applicant’s arguments implied that the analyzer is a separate device/downstream from the evaluator but the evaluation step contains analyzers. The limitation “the plurality of independent processors comprising one or more evaluators and one or more analyzers”. It is not clear is multiple processors comprise a single evaluator and a single analyzer or if applicant intends each processor to correspond to each evaluator+analyzer or if a processor corresponds an analyzer and a second processer corresponds to an evaluator. Appropriate correction is required. Claim Rejections - 35 USC § 112 Claims rejections under 112, recited in the previous office action, are withdrawn. The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 3, 10, 17 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claims 1, 8 and 15 recites the limitation "a plurality of analyzers" and “one or more analyzers”. Claims 3, 10 and 17 recite “analyzers” in line 3 and “the analyzers” in lines 5-6. There is insufficient antecedent basis for this limitation in the claim. It is not clear if the antecedent basis for “the analyzers” is “plurality of analyzers” or “one or more analyzers” recited in claims 1, 8 and 15 or “analyzers” recited in claim 3, 10 and 17. Response to Arguments Applicant's arguments (Remarks filed 5/12/2026) have been fully considered but they are not persuasive. Applicant argues (Page 9-10 of Remarks) that Wang does not disclose 3 separate devices: (2) signal source between (1) analyzers and (3) aggregators which routes the data to a [4th device?] (4) evaluator and then [a 5th device?] executes a security response. Wang teaches different “engines” performing different tasks which reads on the different devices applicant is arguing; and The claims do not require 3 (or 4) separate devices/engines. The claims recite: Receiving… at an event source (device 1) Generating…. by analyzers (no device specified) This could be done by device 1 Aggregating... at a signal source (device 2)… data which is received Evaluating… using independent processors This could be done by device 2 Determining… based on output of the processors This could be done by device 2 Executing… based on combined output This could be done by device 2 Overall Applicant is arguing that the at least 3 separate (and it appears a 4th) devices are in operation, however, the claims only require 2 separate devices. In response to applicant's argument that the examiner's conclusion of obviousness is based upon improper hindsight reasoning, it must be recognized that any judgment on obviousness is in a sense necessarily a reconstruction based upon hindsight reasoning. But so long as it takes into account only knowledge which was within the level of ordinary skill at the time the claimed invention was made, and does not include knowledge gleaned only from the applicant's disclosure, such a reconstruction is proper. See In re McLaughlin, 443 F.2d 1392, 170 USPQ 209 (CCPA 1971). A POSITA would be motivated to include aggregation before evaluation because aggregating prior to evaluation would improve evaluation efficiency. Applicant asserts that the dependent claims are allowable by virtue of allowance in independent claims, however Examiner does not find the independent claims to be allowable therefore does not find the dependent claims to be allowable. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claims 1-6, 8-13 and 15-19 are rejected under 35 U.S.C. 103 as being unpatentable over Wang (U.S. 20190081968), in view of Lonas (U.S. 20180077146). Regarding claims 1, 8 and 15, Lonas discloses: A method comprising: receiving, at an event source, a plurality of security events from a plurality of event generators; (Wang [0016-0027, 0051-0057, 0062-0066, 0076-0077] teaches receiving a stream, in real-time, of events from a plurality of entities) generating, by a plurality of analyzers, security signals based on the security events, the security signals comprising a subset of the security events; (Wang [0018-0019, 0023-0024, 0040-0047, 0058-0065] teaches generating subsets of the events according to category, assigning a value to each, normalizing those values and building an entity profile using multi-dimensional arrays for each parameter type) the security signals received from the plurality of analyzers (Wang [0018-0019, 0023-0024, 0040-0047, 0051-0075, Fig. 4 and Fig. 5] teach receiving security signals from engines that analyze) evaluating the security signals and determining risk levels using a plurality of independent processors, the plurality of independent processors comprising one or more evaluators and one or more analyzers; (Wang [0016-0020, 0023-0027, 0053-0057, 0062-0085] teaches a risk assessment engine which determine a risk score/level; [0113] teaches that the operations can be performed by one or more processors) determining that an action is required based on a combined output of the plurality of independent processors evaluating the security signals and determined risk levels; and (Wang [0021, 0026, 0054-0057, 0062-0074, 0076-0085] teaches determining an action is required based on the risk score/level. The risk score/level is based on the risk assessment engine analysis of the multi-dimensional arrays) executing a security response, responsive to the action. (Wang [0021, 0026, 0067-0074, 0077-0079, 0085] teaches remedial actions to preventing or limit activity in response to a specific risk score) While Wang teaches storing events, clustering and aggregation Wang does not explicitly perform all these tasks by a “signal source” therefore does not explicitly disclose: aggregating and correlating, at a signal source, the security signals ; aggregated and correlated security signals However, in the same field of endeavor Lonas discloses: aggregating and correlating, at a signal source, the security signals ; aggregated and correlated security signals (Lonas [0018, 0021-0022, 0027-0030, 0034-0036, 0042-0043] teaches aggregating and corelating one or more portions of the received data, including security data, to generate a feature set/vector for analysis) Wang and Lonas are analogous art because they are from the same field of endeavor real-time event detection. Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art, having the teachings of Wang and Lonas before him or her, to modify the method of Wang to include the aggregating and correlating of Lonas because it will allow for mappings between different associated entities to be created. The motivation for doing so would be [“The data processing utility may then search the data store for online identities/entities that are associated with content having similar characteristics.”] (Paragraph 0022-0023, 0030, 0034-0036, 0041-0045 by Lonas )]. Therefore, it would have been obvious to combine Wang and Lonas to obtain the invention as specified in the instant claim. Regarding claims 2, 9 and 16, Wang in view of Lonas discloses: The method of claim 1, wherein receiving a stream of security events comprises: collecting raw events from the plurality of event generators; (Wang [0017-0030, 0058-0061, 0088-0090] teaches collecting event data) ingesting the raw events to a stream; (Wang [0052-0062, 0088-0090] teaches ingesting event data) enriching the ingested events; (Wang [0040-0050, 0063-0066, 0073, 0085-0095] teaches adding contextual information to the event data including event's date, time, location latitude, location longitude, device type, IP address, and number of log-in attempts] normalizing the enriched events; and (Wang [0052-0062]) teaches scale and normalize using well-known statistical techniques so that the values fall within a consistent and centered range when plotted in an array) filtering the normalized events. (Wang [0052-0062, 0088-0090] teaches filtering out events that are malformed or irrelevant, deleting unnecessary event data, and converting event data into values that the risk assessment engine can use)) Regarding claims 3, 10 and 17, Wang in view of Lonas discloses: The method of claim 1, wherein generating security signals based on the security events comprises: receiving normalized events; (Wang [0052-0062, 0088-0090] sending the normalized events to the risk assessment engine) distributing the normalized events to analyzers including one or more of a bot detection module, a machine learning profiler module, and an anomaly detection module; (Wang [0052-0062, 0065-0073, 0088-0090] teaches that the risk assessment engine can, which receives the normalized events, can perform anomaly detection) analyzing the normalized events distributed to the analyzers with the analyzers; (Wang [0052-0062, 0065-0073, 0088-0090] teaches that the risk assessment engine analyzes the received events) generating the security signals based on output from the analyzers; and (Wang [0052-0062, 0065-0074, 0088-0090] teaches that the risk assessment engine generates and assigns a risk score, which is used to determine a risk level) transmitting the generated security signals to the signal source. (Wang [0047, 0052-0062, 0065-0079, 0085, 0088-0090, 0096, 0106-0108] teaches that the risk assessment engine generates and assigns a risk score, which is used to determine a risk level. The risk level is output which is then transmitted) Regarding claims 4, 11 and 18, Wang in view of Lonas discloses: The method of claim 1, wherein aggregating and correlating the security signals comprises: receiving the security signals at the signal source; (Wang [0016-0027, 0051-0057, 0062-0066, 0076-0077] teaches receiving a stream, in real-time, of events from a plurality of entities) enriching the correlated signals with context data; and (Wang [0040-0050, 0063-0066, 0073, 0085-0095] teaches adding contextual information to the event data including event's date, time, location latitude, location longitude, device type, IP address, and number of log-in attempts] routing the enriched signals to the plurality of independent processors. (Wang [0016-0020, 0023-0027, 0053-0057, 0062-0085] teaches determining a risk assessment engine which determine a risk score/level; [0113] teaches that the operations can be performed by one or more processors) While Wang teaches collecting data and aggregation of evaluations Wang does not explicitly disclose: collecting and aggregating the received signals; correlating the aggregated signals to identify patterns; However, in the same field of endeavor Lonas discloses: collecting and aggregating the received signals; correlating the aggregated signals to identify patterns; (Lonas [0018, 0021-0022, 0027-0030, 0034-0036, 0042-0043] teaches aggregating and corelating one or more portions of the received data, including security data, to generate a feature set/vector for analysis) It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify with Lonas for similar reasons as cited in claim 1. Regarding claims 5, 12 and 19, Wang in view of Lonas discloses: The method of claim 1, wherein evaluating the security signals comprises: receiving (Wang [0016-0020, 0023-0027, 0057-0062] teaches a risk assessment engine which receives a stream of entity events from the event ingestion service; [0113] teaches that the operations can be performed by one or more processors) evaluating the (Wang [0016-0020, 0062-0081, 0086-0098] teaches a streaming risk assessment engine for handling executed events; [0080-0085, 0099-111] teaches an on-demand risk assessment engine for handling attempted events) evaluating the (Wang [0016-0020, 0076-0085] teaches a rule queue where a rule can test event attributes to determine whether to perform more or less assessments of the event, including a rule which required analysis by additional rules) While Wang teaches storing events, clustering and aggregation Wang does not explicitly perform all these tasks by a “signal source” therefore does not explicitly disclose: correlated signals However, in the same field of endeavor Lonas teaches: correlated signals (Lonas [0018, 0021-0022, 0027-0030, 0034-0036, 0042-0043] teaches aggregating and corelating one or more portions of the received data, including security data, to generate a feature set/vector for analysis) It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify with Lonas for similar reasons as cited in claim 1. Regarding claims 6 and 13, Wang in view of Lonas discloses: The method of claim 1, wherein determining that action is required comprises: comparing the determined risk levels against predefined thresholds or policies; (Wang [0053 0066-0074, 0085] the risk assessment engine can compare an event or attempted event to the entity's profile to determine a threat level for the event and take action such as denying log-in through the access control service if the attempted log-in's threat level is too high) determining a confidence level of a risk assessment; and (Wang [0066-0076, 0075-0075, 085, 0094-0097] teaches determining a confidence score for an assessed event) proceeding to execute the security response if the risk meets or exceeds an action threshold. (Wang [0053 0066-0074, 0085] the risk assessment engine can compare an event or attempted event to the entity's profile to determine a threat level for the event and take action such as denying log-in through the access control service if the attempted log-in's threat level is too high) Claims 7, 14 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Wang (U.S. 20190081968), in view of Lonas (U.S. 20180077146) and in further view of Ahmed (U.S. 20190297096). Regarding claims 7, 14 and 20, Wang in view of Lonas discloses: The method of claim 1, wherein executing the security response comprises: selecting a specific response from a predefined set of actions based on a nature and severity of a detected risk; (Wang [0053, 0066-0074, 0080-0085] the risk assessment engine can compare an event or attempted event to the entity's profile to determine a threat level for the event and take one or more actions such as executing scripts or denying log-in through the access control service if the attempted log-in's threat level is too high) interacting with system components to implement the selected response as an executed response; (Wang [0051-0057, 0080-0085, 0112-0115] teaches embodiments of the invention may locate components in different locations that may be together within a core or scattered across various locations, and they may consolidate multiple components within a single component that performs the same functions as the consolidated components Wang in view of Lonas does not explicitly disclose: logging the executed response for auditing purposes; and recording a response to the action. However, in the same field of endeavor Ahmed discloses: logging the executed response for auditing purposes; and recording a response to the action. (Ahmed [0071-0089] teaches collecting data indicating a mitigation action that was taken and whether the action was appropriate) Wang and Ahmed are analogous art because they are from the same field of endeavor threat detection. Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art, having the teachings of Wang and Ahmed before him or her, to modify the method of Wang to include the event logging of Ahmed because it will improve accuracy mitigation actions. The motivation for doing so would be [“ by employing machine learning techniques in the inference engines of the security platforms, the quality of the classification results may be improved over those of existing security systems and may be continuously updated if and when additional training sets and live data indicate that modifying the rules for recognizing malicious behavior may lead to more accurate results”] (Paragraph 0025, 0075-0078, 0093 by Ahmed)]. Therefore, it would have been obvious to combine Wang and Lonas with Ahmed to obtain the invention as specified in the instant claim. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Cambric 2022-02-11 (US 20230262072) teaches methods, systems, apparatuses, and computer-readable storage mediums described herein are configured to detect anomalous post-authentication behavior with respect to a user identity. For example, one or more audit logs that specify a plurality of actions performed with respect to the user identity of a platform-based identity service, while the user identity is authenticated with the platform-based identity service, are analyzed. The audit log(s) are analyzed via an anomaly prediction model that generates an anomaly score indicating a probability whether a particular sequence of actions of the plurality of actions is indicative of anomalous behavior. A determination is made that an anomalous behavior has occurred based on the anomaly score. In response to determining that anomalous behavior has occurred, a mitigation action may be performed that mitigates the anomalous behavior. Gelman 2022-09-30 (US 20230362184) teaches A method for prioritizing security events comprises receiving a security event that includes security event data having been generated by an endpoint agent based on a detected activity, wherein the security event data includes one or more features; applying a first computing model to the security event data to automatically determine which of the one or more features are one or more input features to a machine learning system; applying a second computing model to historical data related to the security event data to determine time pattern information of the security event data as an input to the machine learning system; combining the one or more input features from the first computing model and the input from the second computing model to generate a computed feature result; and generating an updated security level value of the security event from the computed feature result. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to THOMAS A CARNES whose telephone number is (571)272-4378. The examiner can normally be reached Monday-Friday. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Shewaye Gelagay can be reached at (571) 272-4219. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. THOMAS A. CARNES Examiner Art Unit 2436 /THOMAS A CARNES/Examiner, Art Unit 2436 /MOEEN KHAN/Primary Examiner, Art Unit 2436
Read full office action

Prosecution Timeline

Oct 30, 2024
Application Filed
Feb 23, 2026
Non-Final Rejection mailed — §103, §112
May 12, 2026
Response Filed
Jul 06, 2026
Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12743529
AUTOMATED REVOCATION SYSTEM FOR LEAKED ACCESS CREDENTIALS
3y 11m to grant Granted Sep 22, 2026
Patent 12737465
VALIDATED MOVEMENT OF HARDWARE WITHIN AN IHS CLUSTER
2y 10m to grant Granted Sep 15, 2026
Patent 12701143
SECURITY POLICY GENERATION AND ENFORCEMENT FOR DEVICE CLUSTERS
5y 6m to grant Granted Aug 04, 2026
Patent 12682116
Trust Monitoring for Input to Messaging Group
4y 9m to grant Granted Jul 14, 2026
Patent 12675589
TIME-DELAY-BASED ACCESS CONTROL FOR CONTINUOUS INTEGRATION PIPELINES
3y 5m to grant Granted Jul 07, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
71%
Grant Probability
99%
With Interview (+70.6%)
3y 2m (~1y 3m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 85 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month