Prosecution Insights
Last updated: August 17, 2026
Application No. 18/953,617

A system and method for detecting and managing a data breach in a computing network

Non-Final OA §102
Filed
Nov 20, 2024
Examiner
POWERS, WILLIAM S
Art Unit
2496
Tech Center
2400 — Computer Networks
Assignee
Bank of America Corporation
OA Round
1 (Non-Final)
80%
Grant Probability
Favorable
1-2
OA Rounds
1y 1m
Est. Remaining
82%
With Interview

Examiner Intelligence

Grants 80% — above average
80%
Career Allowance Rate
547 granted / 687 resolved
+21.6% vs TC avg
Minimal +2% lift
Without
With
+2.5%
Interview Lift
resolved cases with interview
Typical timeline
2y 10m
Avg Prosecution
14 currently pending
Career history
704
Total Applications
across all art units

Statute-Specific Performance

§101
8.9%
-31.1% vs TC avg
§103
47.5%
+7.5% vs TC avg
§102
10.0%
-30.0% vs TC avg
§112
15.6%
-24.4% vs TC avg
Black line = Tech Center average estimate • Based on career data from 687 resolved cases

Office Action

§102
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claims 1-20 are pending. Information Disclosure Statement The IDS filed 11/20/2024 has been considered by the Examiner. Claim Rejections - 35 USC § 102 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. Claims 1-20 are rejected under 35 U.S.C. 102(a) as being anticipated by US Patent No. 12,536071 to Skarphedinsson et al. (hereinafter Skarphedinsson). As to claims 1, 8, and 15, Skarphedinsson teaches: a. A memory that stores historical interaction logs associated with previous data interactions performed in relation to a first user (Skarphedinsson, 7:21-37). b. A processor communicatively coupled to the memory (Skarphedinsson, 7:21-37)and configured to: i. Detect that a first data interaction has been performed in relation to the first user (alert generator monitors user behavior including initial authentication to gain access within the data center) (Skarphedinsson, 26:1-43). ii. Determine, based on one or more historical interaction logs associated with the previous data interactions, that the first data interaction does not at least partially match with the previous data interactions performed in relation to the first user (anomalies occur when current user behavior does not match historic user behavior) (Skarphedinsson, 97:17-57). iii. In response to determining that the first data interaction does not at least partially match with the previous data interactions performed in relation to the first user, determine that a data breach has potentially occurred (data breach is one example of anomalous activity) (Skarphedinsson, 97:17-57). iv. Verify the data breach to confirm whether the data breach has occurred, wherein the verifying comprises one or more of the following: a. Determining whether the first data interaction is in accordance with an interaction behavior pattern associated with the first user (there are four tiers of user behavior that are checked in order to determine if a data breach has occurred) (Skarphedinsson, 48:16-51). b. Determining whether the first data interaction is in accordance with one or more relations between nodes of a knowledge graph that represents the previous data interactions performed in relation to the first user (knowledge graph can be used to determine any anomalies in user behavior) (Skarphedinsson, 104:63-105:28 (graph definition) and 106:27-44 (using the graph)). c. Determine, based on the verifying, that the data breach is confirmed (determining that an anomalous event(s) has occurred) (Skarphedinsson, 111:31-53). d. In response to determining that the data breach is confirmed, determine one or more remediation methods that are to be used to avoid theft of data as a result of the data breach (data platforms have remediation services) (Skarphedinsson, 4:21-34). e. Implement the one or more remediation methods to avoid theft of data as a result [of] the data breach (carrying out remedial actions) (Skarphedinsson, 74:54-75:8). As to claims 2, 9, and 16, Skarphedinsson teaches: a. Obtaining the interaction behavior pattern associated with the first user, wherein the interaction behavior pattern comprises a first set of interaction parameters associated with a plurality of previous data interactions performed in relation to the first user (the login graph tracks myriad parameters (user, machine class, location…) of a particular user’s usage history and the current usage) (Skarphedinsson, 48:1-51 and 52:60-67). b. Extracting, from a first interaction log of the first data interaction, a second set of interaction parameters associated with the first data interaction (the login graph tracks myriad parameters (user, machine class, location…) of a particular user’s usage history and the current usage) (Skarphedinsson, 48:1-51 and 52:60-67). c. Comparing the second set of interaction parameters with the first set of interaction parameters (deviation from past logins indicates anomalous behavior and triggers an alert) (the login graph tracks myriad parameters (user, machine class, location…) of a particular user’s usage history and the current usage) (Skarphedinsson, 48:1-51 and 52:60-67). d. In response to determining that at least a threshold number of interaction parameters from the second set match with corresponding interaction parameters from the first set, determining that the data breach is not confirmed (matching parameters do not indicate anomalous behavior) (the login graph tracks myriad parameters (user, machine class, location…) of a particular user’s usage history and the current usage) (Skarphedinsson, 48:1-51 and 52:60-67). e. In response to determining that at least a threshold number of interaction parameters from the second set do not match with corresponding interaction parameters from the first set, determining that the data breach is confirmed (deviation from past behavior indicates anomalous behavior and triggers an alert) (Skarphedinsson, 48:1-51, 52:60-67, and 111:31-53). As to claims 3, 10, and 17, teaches: a. Obtaining the knowledge graph that represents the previous data interactions performed in relation to the first user, wherein the knowledge graph represents the previous data interactions performed in relation to the first user as a plurality of nodes and relationships between the nodes (knowledge graph can be used to determine any anomalies in user behavior) (Skarphedinsson, 104:63-105:28 (graph definition) and 106:27-44 (using the graph)). b. Determining whether the first data interaction matches with the nodes and corresponding relationships from the knowledge graph that are associated with one or more same or similar previous data interactions (matching patterns includes variations of the patterns) (Skarphedinsson, 111:24-53). c. In response to determining that the first data interaction matches with at least a threshold number of the nodes and the corresponding relations from the knowledge graph, determining that the data breach is not confirmed (matching patterns do not indicate anomalous behavior) (Skarphedinsson, 48:1-51, 52:60-67, and 111:24-53 ). d. In response to determining that the first data interaction does not match with at least the threshold number of the nodes and the corresponding relations from the knowledge graph, determining that the data breach is confirmed (mismatching patterns indicate anomalous behavior) (Skarphedinsson, 48:1-51, 52:60-67, and 111:24-53 ). As to claims 4, 11, and 18, teaches: a. Verify the data breach using an Artificial Intelligence (AI) mode, wherein the AI model is trained using the interaction behavior pattern and the knowledge graph (determining that an anomalous event(s) has occurred) (Skarphedinsson, 111:31-53). b. Inputting to the AI model a first interaction log associated with the first data interaction (AI model uses at least a knowledge graph in processing interaction data) (Skarphedinsson, 103:45-62). c. Obtaining an indication of whether the data breach is confirmed as a result output by the AI model (AI model outputs alerts of anomalous behavior) (Skarphedinsson, 105:1-20). As to claims 5, 12, and 19, teaches: a. Obtaining a first interaction log associated with the first data interaction (the login graph tracks myriad parameters (user, machine class, location…) of a particular user’s usage history and the current usage) (Skarphedinsson, 48:1-51 and 52:60-67). b. Identifying, from the historical interaction logs, the one or more historical interaction logs that are associated with previous data interactions that are [the] same or similar to the first data interaction (the login graph tracks myriad parameters (user, machine class, location…) of a particular user’s usage history and the current usage and compares them) (Skarphedinsson, 48:1-51 and 52:60-67). c. Determining that the data breach has potentially occurred to response to determining that the first interaction log at least partially does not match with the one or more historical interaction logs (mismatching patterns indicate anomalous behavior) (Skarphedinsson, 48:1-51, 52:60-67, and 111:24-53 ). As to claims 6, 13, and 20, teaches: a. The processor is further configured to monitor a plurality of communication channels configured for performing data interactions by users (monitoring a plurality of connections (communication channels)) (Skarphedinsson, 20:5-10 and fig. 2E). b. Detect, based on the monitoring, that the first data interaction has been performed in relation to the first user using a first communication channel of the plurality of communication channels (monitoring the extended user session tracking) (Skarphedinsson, 39:42-64). c. Determine that the data breach associated with the first communication channel can cause a second data breach associated with a second communication channel of the plurality of communication channels (a pattern associated with anomalous behavior (data breach) includes variations of the pattern) (Skarphedinsson, 111:24-53). d. Determine one or more second remediation methods that are to be used to avoid theft of data associated with the second communication channel (data platforms have remediation services) (Skarphedinsson, 4:21-34). e. Implement the one or more second remediation methods in real time to avoid theft of data associated with the second communication channel (carrying out remedial actions) (Skarphedinsson, 74:54-75:8). As to claims 7 and 14, teaches the plurality of communication channels comprise email, social media, mobile application, and web application (email) (Skarphedinsson, 23:33-45). Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to WILLIAM S POWERS whose telephone number is (571)272-8573. The examiner can normally be reached M-F 7:30-17:30. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jorge L Ortiz-Criado can be reached at (571) 272-7624. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /WILLIAM S POWERS/Primary Examiner, Art Unit 2496
Read full office action

Prosecution Timeline

Nov 20, 2024
Application Filed
Jul 28, 2026
Non-Final Rejection mailed — §102 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12705378
SYSTEM AND METHOD FOR SECURELY TRANSFERRING DATA USING PSEUDO RANDOMLY GENERATED TOKENS
2y 4m to grant Granted Aug 11, 2026
Patent 12701420
MANAGING END-TO-END DATA PROTECTION
3y 1m to grant Granted Aug 04, 2026
Patent 12695601
PAYLOAD LEVEL ENCRYPTION
2y 3m to grant Granted Jul 28, 2026
Patent 12689528
METHOD FOR IMPLEMENTING MUTUAL AUTHENTICATION PROTOCOL BASED ON RADIO FREQUENCY FINGERPRINT AND FUZZY EXTRACTOR
2y 11m to grant Granted Jul 21, 2026
Patent 12688303
Processor Environment Agnostic Information Handling System Firmware Forensic Vulnerability Acceleration Operation
2y 2m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
80%
Grant Probability
82%
With Interview (+2.5%)
2y 10m (~1y 1m remaining)
Median Time to Grant
Low
PTA Risk
Based on 687 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month