Prosecution Insights
Last updated: August 17, 2026
Application No. 18/970,259

DATA GOVERNANCE FOR SANITIZATION AND MANIPULATION OF RESTRICTED DATA BASED ON DETECTED SECURITY THREAT

Final Rejection §101§103
Filed
Dec 05, 2024
Examiner
FENSTERMACHER, JASON B
Art Unit
3698
Tech Center
3600 — Transportation & Electronic Commerce
Assignee
Bank of America Corporation
OA Round
2 (Final)
46%
Grant Probability
Moderate
3-4
OA Rounds
2y 3m
Est. Remaining
86%
With Interview

Examiner Intelligence

Grants 46% of resolved cases
46%
Career Allowance Rate
119 granted / 257 resolved
-5.7% vs TC avg
Strong +39% interview lift
Without
With
+39.2%
Interview Lift
resolved cases with interview
Typical timeline
3y 11m
Avg Prosecution
15 currently pending
Career history
282
Total Applications
across all art units

Statute-Specific Performance

§101
27.6%
-12.4% vs TC avg
§103
36.2%
-3.8% vs TC avg
§102
3.4%
-36.6% vs TC avg
§112
29.5%
-10.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 257 resolved cases

Office Action

§101 §103
DETAILED ACTION Response to Amendment The amendment filed on May 11, 2026 has been entered. Applicant has: amended claims 1, 10 and 19; and cancelled claims 8 and 17. Claims 1-7, 9-16 and 18-20 are now pending, have been examined and currently stand rejected. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. Information Disclosure Statement The information disclosure statement (IDS) submitted on 5/26/2026 is in compliance with provisions of 37 CFR 1.97. Accordingly, the information disclosure statement has been considered by the examiner. Claim Interpretation Claims 1, 5, 6, 10, 14, 15 and 19 recite limitations where some action/step is “caused” to occur (e.g., cause the plurality of endpoint devices to modify original data, cause a transfer of the modified data, etc.). While there is nothing wrong with using this type of language, Examiner contends that “causing” an action/step to occur is significantly broader than actually performing the action/step. For example, “causing the plurality of endpoint device to modify original data” could simply involve sending a request/instruction to the plurality of endpoint devices to modify the data, whereas “modifying, by the plurality of endpoint devices, the original data” would require the actual manipulation/modification of the original data. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-7, 9-16 and 18-20 are rejected under 35 U.S.C. 101 because the claimed invention recites and is directed to a judicial exception to patentability (i.e., an abstract idea) and does not provide an integration of the recited abstract idea into a practical application nor include an inventive concept that is “significantly more” than the recited abstract idea to which the claim is directed. MPEP §2106. In determining subject matter eligibility in an Alice rejection under 35 U.S.C. §101, it is first determined as Step 1 whether the claims are directed to one of the four statutory categories of an invention (i.e., a process, a machine, a manufacture, or a composition of matter). MPEP §2106.03. Here, it is determined that the claims 1-7 and 9 are directed to the statutory category of a machine, claims 10-16 and 18 are directed to the statutory category of a process, and claims 19-20 are directed to the statutory category of a machine. Under a Step 2A, Prong 1 analysis, it must be determined whether the claims recite an abstract idea that falls within one or more enumerated categories of patent ineligible subject matter that amounts to a judicial exception to patentability. MPEP §2106.04. Independent claim 10, the method claim, is selected as being representative of the independent claims in the instant application. Claim 10 recites: A method for sanitizing restricted data transmitted through a distributed network, the method comprising: monitoring requests to transfer data between a plurality of endpoint devices coupled through the distributed network; determining a plurality of data classification ratings for the plurality of endpoint devices, wherein each of the plurality of data classification ratings indicates storage and transmission security restrictions for data stored on a respective one of the plurality of endpoint devices; based on the plurality of data classification ratings, autonomously causing the plurality of endpoint devices to modify original data, identified in the requests, to modified data with a different data classification rating than that of the original data, wherein the modified data comprises a summary of the original data produced using a large language model; and causing a transfer of the modified data in place of the original data between the plurality of endpoint devices in response to the requests. Here, the claims recite the abstract idea, or combination of abstract ideas, of determining a classification for a device based on attributes associated with one or more items in a network, causing data to be modified based on the classification, and causing the transmission of the modified data. This concept/abstract idea, which is identified in the bolded sections seen above, falls within the Certain Methods of Organizing Human Activity grouping because it describes a fundamental economic practice (e.g., risk mitigation of transferred data), and/or a legal interaction (e.g., mitigating risk, processing data based on determined conditions, etc.), and/or managing interactions between people (e.g., between a data requestor and a data provider, etc.). Accordingly, it is determined that the claims recite an abstract idea since they fall within one or more of the three enumerated categories of patent ineligible subject matter. MPEP §2106.04. It is further noted that, the performance of the one or more process steps using a generic computer component does not preclude the claim limitation(s) from being in the certain methods of organizing human activity grouping. Since it is determined that the claim(s) contain a judicial exception, it must then be determined, under Step 2A, Prong 2, whether the judicial exception is integrated into a practical application of the exception. MPEP §2106.04. In order to make this determination, the additional element(s), or combination of elements, are analyzed to determine if the claim as a whole integrates the recited judicial exception into a practical application of that exception. A claim that integrates a judicial exception into a practical application will apply, rely on, or use the judicial exception in a manner that imposes a meaningful limit on the judicial exception, such that the claim is more than a drafting effort designed to monopolize the judicial exception. In this instance, claim 10 recites the additional elements of a plurality of endpoint devices coupled through the distributed network. Independent claim 1 recites the additional elements of: a plurality of endpoint devices coupled through the distributed network; and at least one processor and memory comprising a data security application. Independent claim 19 recites the additional elements of: an apparatus comprising at least one processor and memory including a data security application; and a plurality of endpoint devices coupled through the distributed network. The plurality of endpoint devices coupled through the distributed network, apparatus, at least one processor and memory comprising a data security application are all recited at a high-level of generality such they amount to no more than mere instructions to apply the exception, or a portion thereof, using a generic computer component. See MPEP 2106.05(f). The claims’ use of the apparatus, processor(s) and/or memory does not transform the claimed subject matter into a patent-eligible application because the claims do not require any nonconventional computer components, or even a “non-conventional and non-generic arrangement of known, conventional pieces,” but merely call for the performance of the abstract idea on a generic computing/processing device. Bascom Global Internet Servs., Inc. v. AT&T Mobility LLC, No. 2015-1763, 2016 WL 3514158, at *6-7 (Fed. Cir. June 27, 2016). Additionally, Examiner finds no indication in the Specification, that the operations recited in the independent claims require any specialized computer hardware or other inventive computer components (See e.g., Specification [0086-0089]), i.e., a particular machine, invoke any allegedly inventive programming, or that the claimed invention is implemented using other than generic computer components to perform generic computer functions. See DDR Holdings, LLC v. Hotels.com, L.P., 773 F.3d 1245, 1256 (Fed. Cir. 2014) ("[A]fter Alice, there can remain no doubt: recitation of generic computer limitations does not make an otherwise ineligible claim patent-eligible."). Furthermore, there is no indication in the claim(s) that the computing components in combination with the abstract idea leads to an improvement of the computing components, or another technology, or to a technical field. Additionally, the tying of this concept to a particular environment (e.g., a distributed network environment, a data security environment, etc.) fails to move the claims beyond a general link of the use of the abstract idea in a particular environment. Accordingly, these additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea. Looking at the elements as a combination does not add anything more than the elements analyzed individually. Examiner further notes that even though the claims may not preempt all forms of the abstract idea, this alone, does not make them any less abstract. See OIP Techs., Inc. v. Amazon.com, Inc., 788 F.3d 1359, 1362-63 (Fed. Cir. 2015). Under the Step 2B analysis, it is determined whether the recited additional elements amount to something “significantly more” than the recited abstract idea to which the claims are directed (i.e., provide an inventive concept). MPEP §2106.05. As discussed above with respect to integration of the abstract idea into a practical application, the additional element of using a generic computing component (e.g., a processor, a memory, etc.) to implement the abstract idea amounts to no more than mere instructions to apply the exception using a generic computer component and/or system. Mere instructions to apply an exception using a generic computer component and/or system cannot provide an inventive concept. That is, simply implementing the abstract idea on a generic computer or merely using a computer as a tool to perform an abstract idea cannot integrate a judicial exception into a practical application at Step 2A or provide an inventive concept in Step 2B. Accordingly, taken alone, the additional elements do not amount to significantly more than a judicial exception. Looking at the limitations as an ordered combination adds nothing that is not already present when looking at the elements taken individually. Therefore, independent claims 1, 10 and 19 are rejected under 35 U.S.C. §101 and are not patent eligible. Dependent claims 2-7, 9, 11-16, 18 and 20 when analyzed are held to be patent ineligible under 35 U.S.C. §101 because the additional recited limitation(s) fail to establish that the claim(s) is/are not directed to an abstract idea. Dependent claim 2 further refines the abstract idea by describing what attributes (e.g., geographic regions) are used to classify the devices. The claim also indicates that the at least one processor and the memory comprise multiple processors and multiple memory located in the multiple geographic regions, however the fact that the abstract idea is implemented on multiple processors and memory in multiple geographic regions fails to provide any indication that the abstract idea is integrated into a practical application or that these additional elements provide significantly more. As indicated above, simply implementing the abstract idea on a generic computer or merely using a computer as a tool to perform an abstract idea cannot integrate a judicial exception into a practical application at Step 2A or provide an inventive concept in Step 2B. Dependent claims 3 and 12 refine the abstract idea by describing what data is modified (i.e., the source of the original data). These claims fail to include any new additional elements that integrate the abstract idea into a practical application or provide significantly more than the abstract idea. Dependent claims 4, 13 and 20 refine the abstract idea by describing what attributes (i.e., data traffic) are evaluated to determine the device classifications. Claims 4, 13 and 20 also recite the additional element of an artificial intelligence model utilized by the at least one processor to monitor, in real time, data traffic in the distributed network. The use of the AI model and the monitoring of the traffic are both recited at a high level of generality. Examiner fails to find any evidence that the mere use of a AI model, when recited at a high level of generality, as it is here, leads to an improvement of the computing components, or another technology, or to a technical field. Additionally, the monitoring of traffic, as currently recited, is merely being used as a data gathering step which is an example of insignificant extra-solution activity. See MPEP 2106.05(g). Taken alone, the additional elements do not integrate the abstract idea into a practical application or provide significantly more than the abstract idea. Looking at the limitations as an ordered combination adds nothing that is not already present when looking at the elements taken individually. Accordingly, this claim fails to integrate the abstract idea into a practical application or provide significantly more than the abstract idea. Dependent claims 5 and 14 refine the abstract idea by indicating that the classifications of the devices can change (e.g., dynamically) and that original data is modified based on the change to the classification. These claims fail to include any new additional elements that integrate the abstract idea into a practical application or provide significantly more than the abstract idea. Dependent claims 6 and 15 refine the abstract idea by describing under what conditions the modified data is transferred. These claims fail to include any new additional elements that integrate the abstract idea into a practical application or provide significantly more than the abstract idea. Dependent claims 7 and 16 refine the abstract idea by describing the type of data utilized in the abstract idea (e.g., a transactional website and a modified transactional website). These claims fail to include any new additional elements that integrate the abstract idea into a practical application or provide significantly more than the abstract idea. Dependent claims 9 and 18 refine the abstract idea by describing the contents of the modified data. These claims fail to include any new additional elements that integrate the abstract idea into a practical application or provide significantly more than the abstract idea. Dependent claim 11 further refines the abstract idea by describing what attributes (e.g., geographic regions) are used to classify the devices. The claim also indicates that the monitoring of the requests is performed by multiple processors located in the multiple geographic regions, however the fact that the abstract idea, or a portion thereof, is implemented on multiple processors in multiple geographic regions fails to provide any indication that the abstract idea is integrated into a practical application or that these additional elements provide significantly more. As indicated above, simply implementing the abstract idea on a generic computer or merely using a computer as a tool to perform an abstract idea cannot integrate a judicial exception into a practical application at Step 2A or provide an inventive concept in Step 2B. In summary, the dependent claims considered both individually and as an ordered combination do not provide meaningful limitations to transform the abstract idea into a patent eligible application of the abstract idea such that the claims amount to significantly more than the abstract idea itself. The claims do not recite an improvement to another technology or technical field, an improvement to the functioning of the computer itself, or provide meaningful limitations beyond generally linking an abstract idea to a particular technological environment. Therefore, the dependent claims are also not patent eligible. Accordingly, it is determined that all claims are directed to non-statutory subject matter under 35 U.S.C. 101 and are ineligible. Claim Rejections - 35 USC § 103 This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention. The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1, 2, 9-11 and 18-19 are rejected under 35 U.S.C. 103 as being unpatentable over Beveridge et al. (US 2023/0026253 A1) (hereinafter “Beveridge”) in view of Mack (US 2022/0222356 A1) in view of Marcus et al. (US 2025/0390879 A1) (hereinafter “Marcus”). Regarding Claims 1, 10 and 19: Beveridge discloses: Claim 1: A system for sanitizing restricted data transmitted through a distributed network, the system comprising: a plurality of endpoint devices coupled through [a] network (See at least Beveridge [0048]; Fig. 2. Beveridge discloses a plurality of endpoint devices (e.g., devices 212, 222, 232) coupled through a network (i.e., network, e.g., network 210).); and at least one processor and memory comprising a data security application (See at least Beveridge [0033-0035]; [0082]; Beveridge Claim 10. Beveridge discloses at least one processor and memory (i.e., crypto server, e.g., a computing device) comprising a data security application (i.e., comprising a crypto provider).) that, when executed, configures the at least one processor to: Claim 10: A method for sanitizing restricted data transmitted through a distributed network, the method comprising: Claim 19: An apparatus for sanitizing restricted data transmitted through a distributed network, the apparatus comprising at least one processor and memory including a data security application (See at least Beveridge [0033-0035]; [0082]; Beveridge Claim 10. Beveridge discloses an apparatus comprising at least one processor and memory (i.e., crypto server, e.g., a computing device) including a data security application (i.e., including a crypto provider).) that, when executed, configures the at least one processor to: monitoring requests to transfer data between a plurality of endpoint devices coupled through the network (See at least Beveridge [0014]; [0020]; [0049]. Beveridge discloses monitoring requests (i.e., cryptographic requests) to transfer data (i.e., data, e.g., transaction data) between a plurality of endpoint devices (i.e., source and destination devices) coupled through the network.); determining a plurality of data classification ratings for the plurality of endpoint devices, wherein each of the plurality of data classification ratings indicates storage and transmission security restrictions for data stored on a respective one of the plurality of endpoint devices (See at least Beveridge [0020-0021]; [0035-0037]; [0050-0052]; [0076]; Fig. 5 steps 504 and 506. Beveridge discloses determining a plurality of data classification ratings (i.e., cryptographic techniques) for the plurality of endpoint devices (i.e., for the devices, e.g., devices 212, 222, 232), wherein each of the plurality of data classification ratings indicates storage and transmission security restrictions for data stored on a respective one of the plurality of endpoint devices (i.e., indicates storage and transmission mandates for the data).); based on the plurality of data classification ratings, autonomously causing the plurality of endpoint devices to modify original data, identified in the requests, to modified data with a different data classification rating than that of the original data (See at least Beveridge [0021-0023]; [0045]; [0050-0055]; [0075-0077]; Fig. 5 steps 506 and 508. Beveridge discloses based on the plurality of data classification ratings (i.e., based on the identified/selected cryptographic technique(s)), autonomously causing the plurality of endpoint devices (i.e., cause the devices, e.g., devices 212, 222, 232) to modify original data (i.e., data, e.g., transaction data), identified in the requests, to modified data (i.e., cryptographically modified data) with a different data classification rating than that of the original data (i.e., where non-cryptographically modified data and cryptographically modified data are different classification ratings).); and As indicated above, Beveridge discloses modifying original data (i.e., data, e.g., transaction data) into modified data (i.e., cryptographically modified data) causing a transfer of the modified data in place of the original data between the plurality of endpoint devices in response to the requests (See at least Beveridge [0014-0015]; [0029]; [0045]. Beveridge discloses causing a transfer of the modified data (i.e., cryptographically modified data) in place of the original data (i.e., in place of the data, e.g., transaction data) between the plurality of endpoint devices in response to the requests.). Beveridge discloses a plurality of endpoint devices (e.g., devices 212, 222, 232) coupled through a network (i.e., network, e.g., network 210). Beveridge [0048]; Fig. 2. Beveridge indicates that the network may be any sort of network over which data may be transmitted, such as a local area network (LAN), cellular network, satellite-based network, the Internet, or the like. Beveridge [0028]. Beveridge also indicates that aspects of the cryptographic agility system may be implemented in a distributed fashion across a plurality of computing devices. Beveridge [0032]; [0082]. However, Beveridge does not explicitly disclose where the network, through which the plurality of endpoint devices are coupled, is a distributed network. Mack, on the other hand, teaches where the network, through which the plurality of endpoint devices are coupled, is a distributed network (See at least Mack [0046]; [0049]; [0051]; Fig. 1; Fig. 2. Mack teaches where the network, through which the plurality of endpoint devices (e.g., database server 500, cyber security system 600, Internet servers/websites 400-1, 400-2 and 400-3) are coupled, is a distributed network (i.e., distributed communication network).). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teachings of Mack into Beveridge’s method of using a network to couple devices and to transmit data, where aspects of the method may be implemented in a distributed fashion across a plurality of computing devices. One of ordinary skill in the art would have been motivated to include such features in order to allow for initiating and maintaining communications and exchanging data with other networked devices on the distributed communications network (Mack [0051]). Additionally, substituting one type of network for another type of network (e.g., substituting a LAN for a distributed network) is merely a simple substitution of the utilized network. As indicated above, Beveridge discloses autonomously causing the plurality of endpoint devices (i.e., cause the devices, e.g., devices 212, 222, 232) to modify original data (i.e., data, e.g., transaction data), identified in the requests, to modified data (i.e., cryptographically modified data) with a different data classification rating than that of the original data (i.e., where non-cryptographically modified data and cryptographically modified data are different classification ratings). Beveridge [0021-0023]; [0045]; [0050-0055]; [0075-0077]; Fig. 5 steps 506 and 508. Beveridge also indicates that algorithms and/or configuration of algorithms may be selected based on performance and/or capabilities of a device and/or network associated with the request. Beveridge [0021]. However, Beveridge does not explicitly disclose wherein the modified data comprises a summary of the original data produced using a large language model. Marcus, on the other hand, teaches wherein the modified data comprises a summary of the original data produced using a large language model (See at least Marcus [0044] “provide an LLM based pipeline in which a user's transaction history (e.g., a sequence of past transaction events) may be compared to the user's current transaction, the deviation between which may be translated into a human-readable textual story that outlines and summarized details of changes in the user's typical transaction behavior ( e.g., cumulative behavior or patterns pertaining to multiple (a subset of, many or all) previous transactions).”; [0071]; [0091]; [0116]; Fig. 14. Marcus teaches wherein the modified data comprises a summary (i.e., a summary, e.g., a human-readable summary) of the original data (i.e., of the user’s current and past transactions / of the user’s transaction history) produced using a large language model (i.e., large language model (LLM)).). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teachings of Marcus into Beveridge’s method of modifying original data to modified data, where different algorithms could be selected based on performance and/or capabilities of a device and/or network. One of ordinary skill in the art would have been motivated to include such features in order to automatically create human-readable summaries using a Large Language Model (LLM) which enable humans to improve speed and accuracy of their reviews (Marcus [0001]; [0005]). Regarding Claim 2: The combination of Beveridge, Mack and Marcus discloses the system of claim 1. Beveridge further discloses wherein: the plurality of data classification ratings are based on where the plurality of endpoint devices are located in multiple geographic regions of the distributed network (See at least Beveridge [0014] “geographic locations associated with a source and/or destination of the data”; [0036]; [0037] “device location ( e.g., geographic location information, such as based on a satellite positioning system associated with the device) […] then crypto provider 120 should select a cryptographic technique that meets one or more conditions”; [0039] “In some embodiments, policy table 132 maps various contextual conditions (e.g., relating to organizational context 136 and/or user context 138) to cryptographic technique characteristics ( e.g., security ratings, threats protected against, resource utilization ratings, and the like). For example, a contextual condition may be the use of a certain type of application, a certain type of data, or a particular geographic location.”; [0055]. Beveridge discloses where the plurality of data classification ratings (i.e., cryptographic techniques) are based on where the plurality of endpoint devices are located in multiple geographic regions of the distributed network (e.g., based on geographic locations associated with a source and/or destination of the data).); and the at least one processor and the memory comprise multiple processors and multiple memory located in the multiple geographic regions (See at least Beveridge [0032]; [0082]. Beveridge discloses where the at least one processor and the memory (i.e., crypto server, e.g., a computing device) comprise multiple processors and multiple memory (i.e., a plurality of computing devices) located in the multiple geographic regions (i.e., distributed, e.g., distributed over a network).). Regarding Claims 9 and 18: The combination of Beveridge, Mack and Marcus discloses the system of claim 1 and the method of claim 10. Beveridge discloses modifying original data (i.e., data, e.g., transaction data) and transferring modified data (i.e., cryptographically modified data) in place of the original data (i.e., in place of the data, e.g., transaction data). Beveridge [0014-0015]; [0021-0023]; [0029]; [0045]; [0050-0055]; [0075-0077]; Fig. 5. However, Beveridge does not explicitly disclose wherein the at least one processor is configured by the data security application to: include a watermark, false data, or a subset of the original data in the modified data. Mack, on the other hand, further teaches wherein the at least one processor is configured by the data security application to: include a watermark, false data, or a subset of the original data in the modified data (See at least Mack [0038]; [0045]; [0062-0063]. Mack teaches wherein the at least one processor is configured by the data security application to: include false data (i.e., mock/benign data), or a subset of the original data (e.g., a street number, street name, one or more digits in a social security number, etc.) in the modified data (i.e., in the modified data records).). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teachings of Mack into Beveridge’s method of modifying original data (i.e., data, e.g., transaction data) and transferring modified data (i.e., cryptographically modified data) in place of the original data (i.e., in place of the data, e.g., transaction data). One of ordinary skill in the art would have been motivated to include such features in order to mislead a would-be accessor/acquirer of the modified data records into believing that they have accessed/acquired valid/real data (Mack [0045]). Regarding Claim 11: The combination of Beveridge, Mack and Marcus discloses the method of claim 10. Beveridge further discloses wherein: the plurality of data classification ratings are based on where the plurality of endpoint devices are located in multiple geographic regions of the distributed network (See at least Beveridge [0014] “geographic locations associated with a source and/or destination of the data”; [0036]; [0037] “device location ( e.g., geographic location information, such as based on a satellite positioning system associated with the device) […] then crypto provider 120 should select a cryptographic technique that meets one or more conditions”; [0039] “In some embodiments, policy table 132 maps various contextual conditions (e.g., relating to organizational context 136 and/or user context 138) to cryptographic technique characteristics ( e.g., security ratings, threats protected against, resource utilization ratings, and the like). For example, a contextual condition may be the use of a certain type of application, a certain type of data, or a particular geographic location.”; [0055]. Beveridge discloses where the plurality of data classification ratings (i.e., cryptographic techniques) are based on where the plurality of endpoint devices are located in multiple geographic regions of the distributed network (e.g., based on geographic locations associated with a source and/or destination of the data).); and the monitoring of the requests is performed by multiple processors located in the multiple geographic regions (See at least Beveridge [0014]; [0020]; [0032]; [0049]; [0082]. Beveridge discloses wherein the monitoring of the requests (i.e., cryptographic requests) is performed by multiple processors (i.e., a plurality of computing devices) located in the multiple geographic regions (i.e., distributed, e.g., distributed over a network).). Claims 3 and 12 are rejected under 35 U.S.C. 103 as being unpatentable over Beveridge in view of Mack in view of Marcus, as applied above, and further in view of Venkataraman (US 2020/0304477 A1). Regarding Claims 3 and 12: The combination of Beveridge, Mack and Marcus discloses the system of claim 1 and the method of claim 10. Beveridge further discloses the need to select a cryptographic technique for transmitting data that meets one or more conditions ( e.g., having a particular security rating and/or being configured to protect against particular types of threats) in order to comply with relevant laws, regulations, or mandates. Beveridge [0036]. However, Beveridge does not explicitly disclose wherein the at least one processor is configured by the data security application to conceal a first endpoint device of the plurality of endpoint devices as a source of the original data by identifying, in the transfer of the modified data, a second endpoint device of the plurality of endpoint devices as a source of the modified data. Venkataraman, on the other hand, teaches wherein the at least one processor is configured by the data security application to conceal a first endpoint device of the plurality of endpoint devices as a source of the original data by identifying, in the transfer of the modified data, a second endpoint device of the plurality of endpoint devices as a source of the modified data (See at least Venkataraman [0041]; [0073]; [0080-0081]; [0087]. Venkataraman teaches wherein the at least one processor (e.g., the second processor) is configured by the data security application to conceal a first endpoint device (i.e., a source node, e.g., the user computer, a preceding node) of the plurality of endpoint devices (i.e., of the plurality of nodes) as a source of the original data by identifying, in the transfer of the modified data (i.e., in an outer header, which is included with the transferred data), a second endpoint device (i.e., an intermediate node, e.g., the first intermediary node) of the plurality of endpoint devices as a source of the modified data. For example, the second processor discards the first outer header (i.e., the outer header which indicates the user computer as the source) and replaces the first outer header with a second outer header, where the second header indicates the first intermediary node as the source instead of the user computer.). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teachings of Venkataraman into Beveridge’s method of selecting a cryptographic technique for transmitting data that meets one or more conditions. One of ordinary skill in the art would have been motivated to include such features in order to ensure that no receiving node (e.g., an intermediary node) is made aware of the source of the data packet (Venkataraman [0058]). Claims 4-6, 13-15 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Beveridge in view of Mack in view of Marcus, as applied above, and further in view of Grill et al. (US 2020/0244672 A1) (hereinafter “Grill”). Regarding Claims 4, 13 and 20: The combination of Beveridge, Mack and Marcus discloses the system of claim 1, the method of claim 10, and the apparatus of claim 19. Beveridge discloses a need to ensure that the most secure and updated cryptographic techniques that are consistent with device and network constraints are utilized. Beveridge [0025]. Beveridge discloses monitoring items such as network connectivity information (e.g., bandwidth, loss metrics for the channel, congestion, latency, and/or the like) and information about the device's physical exposure to potential side-channel attacks. Beveridge [0038]. Beveridge also discloses adjusting the cryptographic techniques based on the monitored information. Id. However, Beveridge does not explicitly disclose, but Grill teaches wherein the data security application comprises an artificial intelligence model utilized by the at least one processor to (See at least Grill [0031-0034]. Grill teaches wherein the data security application comprises an artificial intelligence model (i.e., machine learning model) utilized by the at least one processor.): monitor, in real time, data traffic in the distributed network (See at least Grill [0025] “network 100 may include one or more mesh networks” (where mesh network = distributed network); [0032-0033]; [0036-0039]. Grill teaches monitoring, with the artificial intelligence model (i.e., with the machine learning model) in real time, data traffic in the distributed network (e.g., telemetry data regarding traffic in the network, behavior in network traffic, traffic flow, etc.).); and evaluate the data traffic to identify a security risk of an unauthorized access to the original data, wherein the plurality of data classification ratings is based on the security risk (See at least Grill [0031-0033]; [0043]; [0053-0054];[ 0057]. Grill teaches evaluating the data traffic (e.g., telemetry data regarding traffic in the network, behavior in network traffic, traffic flow, etc.) with the artificial intelligence model (i.e., with the machine learning model) to identify a security risk of an unauthorized access to the original data (i.e., to identify a ransomware attack on the endpoint client’s files), wherein the plurality of data classification ratings (i.e., identifying the endpoint client as infected or not infected with ransomware) is based on the security risk (i.e., is based on detecting a ransomware attack).). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teachings of Grill into Beveridge’s method of adjusting cryptographic techniques based on monitored information. One of ordinary skill in the art would have been motivated to include such features in order to detect changes on an endpoint client that are indicative of ransomware and to initiate mitigation actions in response to the detected changes (Grill [0011]). Regarding Claims 5 and 14: The combination of Beveridge, Mack, Marcus and Grill discloses the system of claim 4 and the method of claim 13. Beveridge further discloses wherein the at least one processor is configured by the data security application to: determine the plurality of data classification ratings dynamically (See at least Beveridge [0013] “the present disclosure provides an approach for dynamically selecting and configuring ciphers based on network and resource constraints”; [0014] “the cryptographic agility system may dynamically determine which libraries, algorithms, configuration values, and/or the like to select based on factors such as the type of data being encrypted, the type of application requesting encryption, the network environment(s) in which the data is to be sent, […]”; [0022] “cryptographic algorithms and/or configurations of algorithms may be dynamically switched over time based on changing circumstances”; [0056]. Beveridge discloses determining the plurality of data classification (i.e., cryptographic techniques) ratings dynamically.); and cause the plurality of endpoint devices to modify the original data to the modified data based on a change in the plurality of data classification ratings (See at least Beveridge [0014-0015]; [0021-0023]; [0045]; [0050-0056]; [0075-0077]. Beveridge discloses causing the plurality of endpoint devices (e.g., devices 212, 222, 232) to modify the original data (i.e., data, e.g., transaction data) to the modified data (i.e., cryptographically modified data) based on a change in the plurality of data classification ratings (i.e., based on a change in the cryptographic technique(s)).). Regarding Claims 6 and 15: The combination of Beveridge, Mack, Marcus and Grill discloses the system of claim 4 and the method of claim 13. Beveridge does not explicitly disclose, but Mack further teaches wherein the at least one processor is configured by the data security application to: detect a pattern in the data traffic indicative of the unauthorized access occurring via one endpoint device of the plurality of endpoint devices (See at least Mack [0006]; [0038-0039]; [0060]; Fig. 4 step 710. Mack teaches detecting a pattern in the data traffic (i.e., detecting that data records are being released/posted on a website) indicative of the unauthorized access (i.e., indicative of the data breach) occurring via one endpoint device (i.e., the device hosting the website with the postings) of the plurality of endpoint devices.); and based on detecting the pattern, cause the transfer of the modified data to the one endpoint device (See at least Mack [0006]; [0038-0039]; [0060]; [0063]; Fig. 4 step 750. Mack teaches based on detecting the pattern (i.e., based on detecting the data records being released/posted on a website), causing the transfer of the modified data (i.e., causing the transfer/posting of the modified data records (e.g., mock/benign data)) to the one endpoint device (i.e., to the device hosting the website with the postings).). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teachings of Mack into Beveridge’s method of adjusting cryptographic techniques based on monitored information. One of ordinary skill in the art would have been motivated to include such features in order to entice and mislead a would-be acquirer of confidential/private data and, in certain instances, determine the physical or network location and/or identity of a would be acquirer of confidential/private data (Mack [0003]). Claims 7 and 16 are rejected under 35 U.S.C. 103 as being unpatentable over Beveridge in view of Mack in view of Marcus in view of Grill, as applied above, and further in view of Sudia (US 2013/0263226 A1). Regarding Claims 7 and 16: The combination of Beveridge, Mack, Marcus and Grill discloses the system of claim 6 and the method of claim 15. Beveridge discloses a need to ensure that the most secure and updated cryptographic techniques that are consistent with device and network constraints are utilized. Beveridge [0025]. Beveridge discloses monitoring items such as network connectivity information (e.g., bandwidth, loss metrics for the channel, congestion, latency, and/or the like) and information about the device's physical exposure to potential side-channel attacks. Beveridge [0038]. Beveridge also discloses adjusting the cryptographic techniques based on the monitored information. Id. However, Beveridge does not explicitly disclose wherein the original data includes a transactional website adapted to provide access to a secured account, and the modified data includes a modified transactional website adapted to provide access to an emulated account. Sudia, on the other hand, teaches wherein the original data includes a transactional website adapted to provide access to a secured account, and the modified data includes a modified transactional website adapted to provide access to an emulated account (See at least Sudia [0094]; [0097-0098]; [0108]; [0122]; [0149]; [0168-0174]. Sudia teaches wherein the original data includes a transactional website (i.e., a genuine bank website, e.g., http://www2.bank.com) adapted to provide access to a secured account, and the modified data includes a modified transactional website (i.e., a fake bank website, e.g., http://www5.bank.com) adapted to provide access to an emulated account (i.e., a false/fake account).). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teachings of Sudia into Beveridge’s method of adjusting cryptographic techniques based on monitored information. One of ordinary skill in the art would have been motivated to include such features in order to provide a false website that allows for the tracing and tracking down of perpetrators conducting online fraud (Sudia [0002]). Response to Arguments Claim Rejections – 35 U.S.C. § 101 Applicant argues that the claims are not directed to an abstract idea. Amendment, p. 7. Examiner respectfully disagrees. Examiner contends that the claims continue to recite the abstract idea, or combination of abstract ideas, of determining a classification for a device based on attributes associated with one or more items in a network, causing data to be modified based on the classification, and causing the transmission of the modified data. This concept/abstract idea falls within the Certain Methods of Organizing Human Activity grouping because it describes a fundamental economic practice (e.g., risk mitigation of transferred data), and/or a legal interaction (e.g., mitigating risk, processing data based on determined conditions, etc.), and/or managing interactions between people (e.g., between a data requestor and a data provider, etc.). Examiner also notes that, contrary to applicant remarks (Amendment, p. 7), the claimed invention is not “using a large language model to produce a summary of the original data as the modified data (with a different data classification rating), and transferring that modified data in place of the original data.” Rather, the claimed invention is merely causing these actions/steps to occur. Applicant argues that the claims are analogous to USPTO Subject Matter Eligibility Example 1 (Removing Malicious Code from Electronic Messages). Amendment, pp. 7-8. This argument is unpersuasive. Unlike example 1, the claimed invention is not isolating and/or extracting code. Rather the claimed invention is merely causing data to be modified based on a determined classification. Furthermore, unlike example 1, this concept is not inextricably tied to computer technology, as this process has been performed long before the advent of the computer. For example, documents/letters were often redacted and/or coded (i.e., modified) based on the individual receiving the document/letter (i.e., a classification). Applicant argues that the claims integrate any abstract idea into a practical application. Amendment, p. 8. Examiner respectfully disagrees. Examiner again notes that claimed invention is not modifying the original data, rather the claimed invention merely causes the data to be modified. As previously indicated in the claim interpretation section, and reiterated again in this office action, causing a step/action to occur is significantly broader in scope than actually performing the step/action. Furthermore, the mere fact that data is modified using a large language model, by itself, is not indicative of a practical application. In this instance, this feature/element is merely refining the abstract idea by describing the particular algorithm used to modify the data. The claimed invention is not providing an improvement to large language models or their use. At best, the claimed invention is merely applying the LLM at a high level of generality. Applicant argues that the claimed invention recites a specific improvement over prior systems because, rather than encrypting or blocking data transfers entirely, the claims recite a system that monitors transfer requests, determines classification ratings for endpoint devices, and uses an LLM to produce summaries that sanitize the data while still enabling the transfer to proceed. Amendment, p. 8. This argument is unpersuasive. Examiner initially notes that the claimed invention fails to describe/define what the summary comprises (e.g., partially encrypted/blocked data). Additionally, Examiner contends that selectively modifying data is not a technical problem or a technical solution. It is well established that communications (e.g., documents, letters, etc.) could be partially encrypted/encoded/redacted/etc. It is also well established that these modified communications could be performed based on a classification level (e.g., top secret clearance). Here, the claimed invention is merely applying these same concepts to a particular environment (e.g., a distributed computing environment). For the above reasons, and for those set forth in the 35 U.S.C. § 101 rejection above, all claims remain rejected under 35 U.S.C. § 101. Claim Rejections – 35 U.S.C. § 103 Applicant indicates that claims 1, 10 and 19 have been amended to recite "wherein the modified data comprises a summary of the original data produced using a large language model." Amendment, p. 9. Applicant alleges that Marcus, who was used to teach a substantially similar feature in canceled claims 8 and 17, does not teach or suggest the amended limitation as now recited in the independent claims. Amendment, p. 9. Examiner respectfully disagrees. Examiner contends that Marcus teaches wherein the modified data comprises a summary (i.e., a summary, e.g., a human-readable summary) of the original data (i.e., of the user’s current and past transactions / of the user’s transaction history) produced using a large language model (i.e., large language model (LLM)). Marcus [0044]; [0071]; [0091]; [0116]; Fig. 14. Applicant’s remarks regarding Marcus appear largely to focus on what the summary comprises. Amendment, p. 9. For example, applicant states the summaries in Marcus summarize a user's behavior (e.g., behavioral deviations to detect fraud), and are not "a summary of the original data" (e.g., a summary of the current and past transactions). Id. This argument is unpersuasive. While the claimed invention indicates that the summary is “of the original data”, Examiner contends that this is a very broad description of the modified data. Marcus provides an example of the generated summary. Marcus [0091]. Specifically, Marcus indicates that an example summary could state "The last transaction was made through the web platform, while previous transactions were made through mobile p2p. The receiver, Noah, is not familiar to the bank or the sender, unlike previous transactions with familiar receivers. The transaction amount of 65.0 is not within the usual range of 25.0, 45.0, or 70.0 seen in previous transactions. The receiver's bank name, 0g5, is different from the usual jpm and wfc seen in previous transactions. The device used for the last transaction is not familiar, while previous transactions were made using familiar devices. The sender IP for the last transaction is different (7) from the IPs used in previous transactions (0-6)." Marcus [0091]. Examiner contends that the example summary provided by Marcus is a summary of the original data (i.e., a summary of the user’s current and past transactions / of the user’s transaction history). Accordingly, Marcus does teach/suggest "wherein the modified data comprises a summary of the original data produced using a large language model," are recited in amended claims 1, 10 and 19. Applicant also argues that Marcus does not teach transferring the summary in place of the original data. Amendment, p. 9. This argument is unpersuasive for at least two reasons. First, neither the prior, nor the current, office action cited/cites Marcus as disclosing this feature. Rather, the primary reference, Beveridge, was/is cited as disclosing “causing a transfer of the modified data (i.e., cryptographically modified data) in place of the original data (i.e., in place of the data, e.g., transaction data) between the plurality of endpoint devices in response to the requests.” See February 20, 2026 Non-Final Office Action at pp. 12-13. Examiner notes that one cannot show nonobviousness by attacking references individually where the rejections are based on combinations of references. See In re Keller, 642 F.2d 413, 208 USPQ 871 (CCPA 1981); In re Merck & Co., 800 F.2d 1091, 231 USPQ 375 (Fed. Cir. 1986). Secondly, even if one were to incorrectly determine that this feature was not taught by Beveridge, Marcus does in fact also teach this feature. Specifically, Marcus discloses where a request is received (i.e., at operation 302) for all transactions associated with a user (i.e., original data), and, in response, the system (i.e., at operation 309) sends the textual summary (i.e., the summary), not the original data. Marcus [0058]; [0071]; Fig. 3 Operations 302 and 309. Applicant argues, with respect to claims 9 and 18, that “the Examiner fails to provide a proper rationale for combining Beveridge with Mack.” Amendment, pp. 10-11. Examiner respectfully disagrees. Contrary to applicant’s remarks, Beveridge and Mack do not have “diametrically opposed objectives.” Rather, Beveridge and Mack are both concerned with protecting data. Additionally, Beveridge seemingly understands that encrypted data could be obtained by an unauthorized party (i.e., indicated, at least, by the “if” in Beveridge’s “if the unauthorized party cannot decrypt the encrypted data, then the unauthorized party cannot access the underlying data” statement. See Beveridge [0001]; also see [0003] describing the risks associated with quantum computing and nefarious actors.). Applicant is utilizing an unsupported assumption that encrypted data cannot be decrypted by an unauthorized party and therefore, incorrectly, assumes that there would be no reason to put something like false data into the modified data (i.e., into the encrypted data). Furthermore, there is no indication in Beveridge that the party requesting the data is authorized. Accordingly, Beveridge could, theoretically, receive a request from an unauthorized entity for data, and, based on that unauthorized request, could decide to not only encrypt the data but also include false data (i.e., mock/benign data), or a subset of the original data (e.g., a street number, street name, one or more digits in a social security number, etc.) in the modified data (i.e., in the modified/encrypted data records). As noted in the prior office action (see Non-Final OA at p. 15), and as stated by Mack (see Mack [0045]), performing this additional operation could/would mislead a would-be accessor/acquirer of the modified data records into believing that they have accessed/acquired valid/real data. Beveridge also discloses selecting a cryptographic technique from a plurality of different techniques, where some techniques have a higher level of security (e.g., more layers of security). Beveridge [0002]; [0015]; [0076]. Examiner contends that adding additional features such as watermarks, false data and/or including a subset of the original data are all modifications to enhance the level of security, a feature desired by Beveridge. For the above reasons, and for those set forth in the 35 U.S.C. § 103 rejection above, all claims remain rejected under 35 U.S.C. § 103. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure is cited in the Notice of References Cited (PTO-892). The additional cited art further establishes the state of the art prior to the effective filling date of Applicant’s claimed invention. Crabtree et al. (US 2023/0362142 A1) discloses where a network is monitored in real-time and a machine learning algorithm is used to detect behavioral anomalies as they occur in real-time. Crabtree [0124]; Fig. 19. Kaidi et al (US 2024/0176902 A1) discloses a data control framework that enables storing, sharing, and transferring of data in a secure manner. Data files stored in data repositories are scanned. Content associated with different section of each data file is analyzed, and each section is tagged with a sensitivity level based on the content and a subject matter derived for the data file. Each data file is also assigned to a clearance classification based on an expected viewer of the data file. When sections from a first data file is being transferred to a second data file, a data control mechanism is triggered. If a particular section from the first data file is incompatible with the second data file, the data control mechanism may prevent the particular section from being transferred to the second data file, while allowing the remaining sections being transferred to the second data file. Kaidi Abstract. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to JASON FENSTERMACHER whose telephone number is (571)270-3511. The examiner can normally be reached Monday - Friday 9:00 AM to 5:30 PM ET, Alternate Fridays Off. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Patrick McAtee can be reached at 571-272-7575. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /J.F./Examiner, Art Unit 3698 /PATRICK MCATEE/Supervisory Patent Examiner, Art Unit 3698
Read full office action

Prosecution Timeline

Dec 05, 2024
Application Filed
Feb 20, 2026
Non-Final Rejection mailed — §101, §103
May 11, 2026
Response Filed
Jul 31, 2026
Final Rejection mailed — §101, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12700002
PAYMENT METHOD, TERMINAL DEVICES, SERVERS, SYSTEMS AND MEDIUM
1y 10m to grant Granted Aug 04, 2026
Patent 12693998
SYSTEMS AND METHODS FOR IMPLEMENTING A PROGRAMMING MODEL FOR SMART CONTRACTS WITHIN A DECENTRALIZED COMPUTER NETWORK
7y 9m to grant Granted Jul 28, 2026
Patent 12695635
SYSTEM AND METHOD FOR CONTROLLING ASSET-RELATED ACTIONS VIA A BLOCK CHAIN
3y 5m to grant Granted Jul 28, 2026
Patent 12664549
HYBRID TRANSACTION OPERATIONS
3y 10m to grant Granted Jun 23, 2026
Patent 12651259
MULTI-PARTY BLOCKCHAIN ADDRESS SCHEME
2y 7m to grant Granted Jun 09, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
46%
Grant Probability
86%
With Interview (+39.2%)
3y 11m (~2y 3m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 257 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month