Prosecution Insights
Last updated: August 17, 2026
Application No. 18/970,728

SCANNING DIGITAL APPLICATIONS TO DETECT ACCESS CONTROL SECURITY RISKS

Non-Final OA §102
Filed
Dec 05, 2024
Examiner
MURPHY, JOSEPH B
Art Unit
2435
Tech Center
2400 — Computer Networks
Assignee
OneTrust LLC
OA Round
1 (Non-Final)
90%
Grant Probability
Favorable
1-2
OA Rounds
3m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 90% — above average
90%
Career Allowance Rate
578 granted / 641 resolved
+32.2% vs TC avg
Moderate +13% lift
Without
With
+12.9%
Interview Lift
resolved cases with interview
Fast prosecutor
2y 0m
Avg Prosecution
18 currently pending
Career history
646
Total Applications
across all art units

Statute-Specific Performance

§101
3.7%
-36.3% vs TC avg
§103
42.0%
+2.0% vs TC avg
§102
14.8%
-25.2% vs TC avg
§112
26.5%
-13.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 641 resolved cases

Office Action

§102
DETAILED ACTION This Office Action is in response to an application filed on December 5, 2024, in which claims 1 through 20 are pending, and ready for examination. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Rejections - 35 USC § 102 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale or otherwise available to the public before the effective filing date of the claimed invention. Claims 1-20 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Govindavajhala, et al., U.S. Pub. No. 2009/0271863 (hereinafter referred to as Govindavajhala). With regard to claim 1, Govindavajhala discloses identifying, by processing hardware, a set of potentially insecure data access controls from a library of access controls available to digital applications (Govindavajhala, [0027]; [0040]; [0046]-[0049]; [0379]-[0384]; [0391]; [0418]-[0419]); detecting, by the processing hardware, in response to an application scan of a digital application, a set of utilized access controls within the digital application (Govindavajhala, [0222]; [0381]-[0383]; [0417]-[0419]); generating, by the processing hardware, a set of utilized potentially insecure data access controls corresponding to the digital application by comparing the set of utilized access controls to the set of potentially insecure data access controls (Govindavajhala, [0024]-[0028]; [0113]-[0115]; [0169]-[0171]; [0220]; [0391]; [0408]-[0409]); and providing, by the processing hardware, for display within a graphical user interface of a client device, the set of utilized potentially insecure data access controls in relation to a scan report for the digital application (Govindavajhala, [0027]; [0035]; [0043]-[0044]; [0135]; [0222]; [0391]; [0418]-[0419]). With regard to claim 2, Govindavajhala further discloses parsing, by the processing hardware, a library of access controls available to digital applications to identify the set of potentially insecure data access controls (Govindavajhala, [0050]-[0052]; [0123]-[0128]; [0224]-[0229]; [0417]-[0419]). With regard to claim 3, Govindavajhala further discloses determining, by the processing hardware, purpose type descriptors for the set of potentially insecure data access controls (Govindavajhala, [0025]; [0040]-[0043]; [0250]); and providing, by the processing hardware, for display within the graphical user interface of the client device, a set of purpose type descriptors corresponding to the set of set of utilized potentially insecure data access controls (Govindavajhala, [0025]-[0027]; [0040]-[0043]; [0250]). With regard to claim 4, Govindavajhala further discloses generating, by the processing hardware, the set of utilized potentially insecure data access controls corresponding to the digital application by identifying one or more potentially deprecated or potentially compromised access controls, wherein in the access controls comprise digital application permissions (Govindavajhala, [0024]-[0025]; [0046]-[0048]; [0408]-[0410]). With regard to claim 5, Govindavajhala further discloses generating, by the processing hardware, an access control category from two or more utilized access controls from the set of utilized access controls (Govindavajhala, [0024]-[0025]; [0096]; [0396]-[0402]; [0419]); and providing, by the processing hardware, for display within the graphical user interface of the client device, the access control category and a corresponding potential insecurity for the access control category based on the set of utilized potentially insecure data access controls (Govindavajhala, [0024]-[0027]; [0043]-[0046]; [0096]-[0101]; [0382]-[0387]; [0418]-[0419]). With regard to claim 6, Govindavajhala further discloses identifying, by processing hardware, an additional set of potentially insecure data access controls from the library of access controls available to digital applications based on version updates to the library of access controls (Govindavajhala, [0020]; [0027]; [0040]; [0048]-[0051]; [0221]-[0238]); and generating, by the processing hardware, an additional set of utilized potentially insecure data access controls corresponding to the digital application by comparing the set of utilized access controls to the additional set of potentially insecure data access controls (Govindavajhala, [0024]-[0028]; [0113]-[0115]; [0169]-[0171]; [0220]; [0391]; [0408]-[0409]). With regard to claim 7, Govindavajhala further discloses triggering, by the processing hardware, a digital action within a digital application scanning platform for the digital application based on the set of utilized potentially insecure data access controls (Govindavajhala, [0040]-[0041]; [0046]; [0381]-[0383]; [0388]). With regard to claim 8, Govindavajhala further discloses triggering, by the processing hardware, the digital action to provide, for display within an additional graphical user interface of an additional client device (Govindavajhala, [0025]; [0035]; [0052]; [0200]; [0221]-[0237]; [0387]-[0392]; [0418]-[0419]), a selectable access control grant option to enable or reject a utilized potentially insecure data access control from the set of utilized potentially insecure data access controls within the digital application operated on the additional client device (Govindavajhala, [0025]-[0027]; [0048]-[0049]; [0224]-[0237]; [0382]-[0393]; [0409]; [0418]-[0419]). With regard to claim 9, Govindavajhala further discloses triggering, by the processing hardware, the digital action to block an installation of the digital application corresponding to the set of utilized potentially insecure data access controls within an additional client device communicating with the digital application scanning platform (Govindavajhala, [0419]; [0071]; [0387]-[0393]; [0408]-[0409]; [0418]-[0419]). With regard to claim 10, Govindavajhala discloses a non-transitory computer-readable medium storing executable instructions which, when executed by a processing device, cause the processing device to perform operations (Govindavajhala, [0418]-[0421]) comprising: detecting, in response to an application scan of a digital application, a set of utilized access controls within the digital application (Govindavajhala, [0222]; [0381]-[0383]; [0417]-[0419]); generating a set of utilized potentially insecure data access controls corresponding to the digital application by comparing the set of utilized access controls to a set of potentially insecure data access controls (Govindavajhala, [0024]-[0028]; [0040]-[0049]; [0113]-[0115]; [0169]-[0171]; [0220]; [0391]; [0408]-[0409]) from a library of access controls available to digital applications (Govindavajhala, [0027]; [0040]; [0046]-[0049]; [0379]-[0384]; [0391]; [0418]-[0419]); and based on the set of utilized potentially insecure data access controls, triggering a digital action within a digital application scanning platform for the digital application (Govindavajhala, [0040]-[0041]; [0046]; [0381]-[0383]; [0388]). With regard to claim 11, Govindavajhala further discloses generating the set of potentially insecure data access controls by parsing the library of access controls available to digital applications to identify potentially deprecated or potentially compromised access controls (Govindavajhala, [0024]-[0025]; [0046]-[0052]; [0123]-[0128]; [0224]-[0229]; [0408]-[0410]; [0417]-[0419]). With regard to claim 12, Govindavajhala further discloses detecting, in response to the application scan of the digital application, the set of utilized access controls within the digital application as application permissions enabling the digital application to utilize one or more components of a computing device operating the digital application (Govindavajhala, [0071]-[0072]; [0222]; [0354]-[0355]). With regard to claim 13, Govindavajhala further discloses triggering the digital action to provide, for display within a graphical user interface of a client device (Govindavajhala, [0025]; [0035]; [0052]; [0200]; [0221]-[0237]; [0387]-[0392]; [0418]-[0419]), a selectable access control grant option to enable or reject a utilized potentially insecure data access control from the set of utilized potentially insecure data access controls within the digital application operated on the client device (Govindavajhala, [0025]-[0027]; [0048]-[0049]; [0224]-[0237]; [0382]-[0393]; [0409]; [0418]-[0419]). With regard to claim 14, Govindavajhala further discloses triggering the digital action to block an installation of the digital application corresponding to the set of utilized potentially insecure data access controls within a client device communicating with the digital application scanning platform (Govindavajhala, [0049]; [0071]; [0387]-[0393]; [0408]-[0409]; [0418]-[0419]). With regard to claim 15, Govindavajhala further discloses triggering the digital action to provide, for display within a graphical user interface of a client device, the set of utilized potentially insecure data access controls in relation to a scan report for the digital application (Govindavajhala, [0027]; [0035]; [0043]-[0044]; [0135]; [0222]; [0391]; [0418]-[0419]). With regard to claim 16, Govindavajhala discloses one or more non-transitory computer readable media (Govindavajhala, [0418]-[0421]); and processing hardware configured to cause the system to: parse a library of access controls available to digital applications to generate a set of potentially insecure data access controls comprising purpose type descriptors (Govindavajhala, [0025]; [0040]-[0043]; [0250]); generate a set of utilized potentially insecure data access controls corresponding to a digital application by comparing a set of utilized access controls in the digital application to the set of potentially insecure data access controls (Govindavajhala, [0024]-[0028]; [0113]-[0115]; [0169]-[0171]; [0220]; [0391]; [0408]-[0409]); and provide, for display within a graphical user interface of a client device (Govindavajhala, [0027]; [0089]; [0224]-[0230]), the set of utilized potentially insecure data access controls and a set of purpose type descriptors corresponding to the set of utilized potentially insecure data access controls (Govindavajhala, [0025]-[0027]; [0040]-[0043]; [0250]). With regard to claim 17, Govindavajhala further discloses detect the set of utilized access controls within the digital application as application permissions enabling the digital application to utilize one or more components of a computing device operating the digital application (Govindavajhala, [0071]-[0072]; [0222]; [0354]-[0355]). With regard to claim 18, Govindavajhala further discloses parse the library of access controls available to the digital applications to generate the set of potentially insecure data access controls by identifying one or more potentially deprecated or potentially compromised access controls within the digital application (Govindavajhala, [0024]-[0025]; [0046]-[0052]; [0123]-[0128]; [0224]-[0229]; [0408]-[0410]; [0417]-[0419]). With regard to claim 19, Govindavajhala further discloses generate an access control category from two or more utilized access controls from the set of utilized access controls (Govindavajhala, [0024]-[0025]; [0096]; [0396]-[0402]; [0419]); and providing, for display within the graphical user interface of the client device, the access control category and a corresponding potential insecurity based on the set of utilized potentially insecure data access controls (Govindavajhala, [0024]-[0027]; [0043]-[0046]; [0096]-[0101]; [0382]-[0387]; [0418]-[0419]). With regard to claim 20, Govindavajhala further discloses trigger a digital action within a digital application scanning platform for the digital application based on the set of utilized potentially insecure data access controls (Govindavajhala, [0040]-[0041]; [0046]; [0381]-[0383]; [0388]). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: See PTO-892. Any inquiry concerning this communication or earlier communications from the examiner should be directed to J. Brant Murphy whose telephone number is (571)272-6433. The examiner can normally be reached Monday - Friday, 8am - 4pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Amir Mehrmanesh can be reached at 571-270-3351. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /J. BRANT MURPHY/Primary Examiner, Art Unit 2435 June 13, 2026
Read full office action

Prosecution Timeline

Dec 05, 2024
Application Filed
Jun 17, 2026
Non-Final Rejection mailed — §102 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12706892
SECURE TRANSFER OF WORKLOADS ACROSS SECURITY REGIONS
2y 1m to grant Granted Aug 11, 2026
Patent 12701580
TRANSPORT BLOCK SIZE AND SOFT BUFFER MANAGEMENT FOR SHARED CHANNEL TRANSMISSIONS
2y 3m to grant Granted Aug 04, 2026
Patent 12699632
BACKUP FROM A KUBERNETES CLUSTER USING LIGHTWEIGHT ON-DEMAND IN-CLUSTER RESOURCES
1y 9m to grant Granted Aug 04, 2026
Patent 12694134
SYSTEM, METHOD AND APPARATUS FOR REDUCING LATENCY OF RECEIVER OPERATIONS DURING A CONTAINMENT MODE OF OPERATION
3y 10m to grant Granted Jul 28, 2026
Patent 12683956
PASSWORD RESET USING AN ASYMMETRIC ENCRYPTION KEY PAIR
1y 10m to grant Granted Jul 14, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
90%
Grant Probability
99%
With Interview (+12.9%)
2y 0m (~3m remaining)
Median Time to Grant
Low
PTA Risk
Based on 641 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month