Prosecution Insights
Last updated: October 02, 2026
Application No. 18/991,984

RISK-AWARE ACCESS CONTROL SYSTEM AND RELATED METHODS

Non-Final OA §103
Filed
Dec 23, 2024
Priority
Dec 21, 2020 — continuation of 11/888,857 +1 more
Examiner
LEMMA, SAMSON B
Art Unit
Tech Center
Assignee
BlackBerry Limited
OA Round
1 (Non-Final)
88%
Grant Probability
Favorable
1-2
OA Rounds
11m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 88% — above average
88%
Career Allowance Rate
809 granted / 917 resolved
+28.2% vs TC avg
Moderate +11% lift
Without
With
+11.2%
Interview Lift
resolved cases with interview
Typical timeline
2y 9m
Avg Prosecution
24 currently pending
Career history
936
Total Applications
across all art units

Statute-Specific Performance

§101
20.5%
-19.5% vs TC avg
§103
40.8%
+0.8% vs TC avg
§102
19.4%
-20.6% vs TC avg
§112
12.1%
-27.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 917 resolved cases

Office Action

§103
DETAILED ACTION 1. This is in response to application No. 18/991,984 filed on 12/23/2024. Claims 1-20 are canceled and new claims 21-24 are submitted for examination. Claims 21, 31 and 39 are independent. Notice of Pre-AIA or AIA Status 2. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Priority 3. This application filed on 12/23/2024 is a Continuation of 18530793, filed on 12/06/2023, now U.S. Patent # 12218949 and having 1 RCE-type filing therein 18530793 is a Continuation of 17129334, filed 12/21/2020, now U.S. Patent # 11888857 Information Disclosure Statement 4. The information disclosure statements (IDS) submitted on 04/09/2025; 07/18/2025 and 07/20/2026 have been considered. The submission is in-compliance with the provisions of 37 CFR 1.97. Form PTO-1449 is signed and attached hereto. Drawings 5. The drawings filed on December 23, 2024, are accepted. Specification 6. The specification filed on December 23, 2024, is also accepted. Internet Communications 7. Applicant is encouraged to submit a written authorization for Internet communications (PTO/SB/439, http:/www.uspto.gov/sites/default/files/documents/sb0439.pdf) in the instant patent application to authorize the examiner to communicate with the applicant via email. The authorization will allow the examiner to better practice compact prosecution. The written authorization can be submitted via one of the following methods only: (1) Central Fax, which can be found in the Conclusion section of this Office action; (2) regular postal mail; (3) EFS WEB; or (4) the service window on the Alexandria campus. EFS web is the recommended way to submit the form since this allows the form to be entered into the file wrapper within the same day (system dependent). Written authorization submitted via other methods, such as direct fax to the examiner or email, will not be accepted. See MPEP § 502.03. Note: US Patent No. 12/218,949 and 11/888,857 have been considered for DP rejection. However, at this stage of the prosecution the current claims in this application are found to be distinct. Claim Rejections - 35 USC § 103 8. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or non-obviousness. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. 9. Claims 21, 23, 30-31 and 39 are rejected under 35 U.S.C. 103 as being unpatentable over Salil Kumar Jain (Jain) (US Pub. No. 20180219891 A1, Pub. Date: Aug 2, 2018) in view of Abhinav BANSAL et al (Bansal) (US Pub. No. 20170332238A1, Pub. Date: Nov. 16, 2017) As per independent claim 21, Jain discloses a method of risk-aware access control performed by a system comprising a hardware processor [Para. 0034, “ processor-executable instructions and/or installed applications corresponding to software, firmware, and/or computer hardware”], the method comprising: detecting a request to perform an action [Para. 0017, “The log-in attempt may be locally processed by the computing device or communicated to another computing device (e.g., a server) for processing by the other computing device. In another example, the authentication event may be an attempt to connect to a network, such as attempting to connect to a Wi-Fi network through a Wi-Fi access point. This para. identifies an authentication event as including an attempt to log in or establish a network connection. Such an event is a request to perform an access action], the requested action being related to a plurality of factors of different factor types [Para. 0012, “utilize device-specific or user-specific rules that are individualized for a device or user based on “multiple attributes”; Para. 0012 teaches accessing risk using multiple attributes associated with the authentication event. Para. 0018, identifies different attribute types including, device location, an IP address, a network identifier (e.g., a network SSID), presence of other devices in the vicinity, and available network services. These are factors of different factor types related to the same requested authentication action] determining a risk level for the requested action derived from a plurality of factor pairings comprising factors of the different factor types [Para. 0014, “network SSID” and “device location” para. 0056, “For example, the cybersecurity risk assessment model may be set up such that each type of attribute (e.g., latitude, longitude, network SSID, proximate devices, and available services) are considered” and para. 0024, “risk score”. Para. 0014 discloses a first pairing between a location factor and a network-identifier factor. Para. 0056 discloses another pairing between a network identifier factor and a network-services factor. Thus, these identifies at least two different pairings involving factors of different types. Para. 0056 explains that combinations and dependencies among the attributes are used in determining distance within the risk model. Para. 0020 explains that the model result is evaluated against a predetermined threshold or trusted cluster and para. 0024, identifies the resulting risk score.]and denying, by the system, the requested action based on a determination that the risk level [Para. 0024, “denying the authentication attempt by the user device 201, Para. 0024 teaches that when the risk score is above a predetermined threshold or when the evaluated attributes fail outside a trusted cluster, the server can deny the authentication attempt. The denial therefore results from the system’s determination of the the risk level for the requested action]. Jain doesn’t explicitly disclose the following underlined or bolded claim limitation: “denying, by the system, the requested action based on a determination that the risk level does not satisfy a security policy” However, Bansal discloses the underlined limitation: “denying, by the system, the requested action based on a determination that the risk level does not satisfy a security policy” [Para. 0010, “enterprise policy” and “denying the request is based on the risk score” Para. 0010 teaches that the combination of weighting of risk dimensions may be governed by an enterprise policy and that a request may be denied based on the resulting risk score. Para. 0143, further explains that access is controlled under enterprise policy by evaluating the risk score against the relative level of risk tolerance. An enterprise policy governing cybersecurity access decisions corresponds to the claim limitation “security policy”] Jain and Bansal are analogous/in the same field of endeavor as they both are directed to risk assessment related to access control. It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to modify the threshold based multiple-attribute risk model system of Jain by applying enterprise policy such as “denying, by the system, the requested action based on a determination that the risk level does not satisfy a security policy” as per teachings of Bansal so that an organization could accurately measure the threat profile of the requesting device and govern when a risk access request must be denied and subsequently enhance the security of the system . [See Bansal, para. 0008, “to accurately measure the threat profile of the requesting device] As per independent claim 31, Independent claim 31 is a non-transitory medium version of, a method claim 21, and has the same scope as independent claim 21. Thus, claim 31 is rejected for same reason as claim 21. As per independent claim 39, Independent claim 39 is a device version of, a method claim 21, and has the same scope as independent claim 21. Thus, claim 39 is rejected for same reason as claim 21. As per dependent claim 23, the combination of Jain and Bansal discloses the method as applied to claim 21 above. Furthermore, Jain discloses the method wherein, a first factor pairing of the plurality of factor pairings comprises a first factor of a first factor type and a second factor of a second factor type different from the first factor type [Para. 0014, “combination of Para. 0014, a combination of “device location and network SSID”], and a second factor pairing of the plurality of factor pairings comprises the first factor of the first factor type and a third factor of a third factor type different from each of the first factor type and the second factor type [Para. 0056, “network SSID” and available services attributes may be combined] 10. Claims 22 and 32 are rejected under 35 U.S.C. 103 as being unpatentable over Salil Kumar Jain (Jain) (US Pub. No. 20180219891 A1, Pub. Date: Aug 2, 2018) in view of Abhinav BANSAL et al (Bansal) (US Pub. No. 20170332238A1, Pub. Date: Nov. 16, 2017) and further in view of Keng Lim (Lim) (US Pub. No. 20130086261 A1, Pub. Date: April 4, 2013) As per dependent claim 22, the combination of Jain and Bansal discloses the method as applied to claim 21 above. The combination of Jain and Bansal does not disclose the limitation: “wherein each factor type of the different factor types is one of people, device, document, or location” However, Lim discloses the limitation: “wherein each factor type of the different factor types is one of people, device, document, or location” [Para. 0750, “Activity data may be organized as entries including information on user, application, machine, action, object or document, time, and location.” This establishes that people, devices, documents and location were known factor types for evaluating computer security activity] Jain, Bansal and Lim are analogous/in the same field of endeavor as they all are directed to risk assessment related to access control. It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to modify multiple contextual attributes system of Jain and Bansal by applying categories such as “each factor type of the different factor types is one of people, device, document, or location” as per teachings of Lim thereby providing consistent classification of the factors used in the risk assessment and enhance the security of the system by analyzing and evaluating activity data and detect behavioral patterns and anomalies. [See Lim, para. 0015, “Activity data is analyzed or evaluated to detect behavioral patterns and anomalies. When a particular pattern or anomaly is detected, a system may send a notification or perform a particular task”] As per dependent claim 32, dependent claim 32 is a non-transitory medium version of, a method claim 22, and has the same scope as dependent claim 22. Thus, claim 32 is rejected for same reason as claim 22. 11. Claim 30 is rejected under 35 U.S.C. 103 as being unpatentable over Salil Kumar Jain (Jain) (US Pub. No. 20180219891 A1, Pub. Date: Aug 2, 2018) in view of Abhinav BANSAL et al (Bansal) (US Pub. No. 20170332238A1, Pub. Date: Nov. 16, 2017) and further in view of Cameron Esdaile (Esdaile)(US Pub. No. 20160323265 A1, Pub. Date: Nov. 3, 2016) As per dependent claim 30, the combination of Jain and Bansal discloses the method as applied to claim 21 above. The combination of Jain and Bansal does not disclose the limitation: “issuing a user authentication challenge in response to denying the requested action; and allowing the requested action in response to a successful user authentication challenge” However, Esdaile discloses the limitation: “issuing a user authentication challenge in response to denying the requested action; [Para. 0059, “suspends network resource access” and 0060, “ initiates a multi-factor authentication process”] and allowing the requested action in response to a successful user authentication challenge [Para. 0061, “in response to the workflow being successfully completed, the network device grants network resource access”] Jain, Bansal and Esdaile are analogous/in the same field of endeavor as they all are directed to risk assessment related to access control. It would have been obvious to a person having ordinary skill in the art before the effective filing date of the claimed invention to modify the risk-based denial system of Jain and Bansal by adding the challenge response authentication such as “issuing a user authentication challenge in response to denying the requested action; and allowing the requested action in response to a successful user authentication challenge” as per teachings of Esdaile thereby distinguish legitimate users from unauthorized access attempts while permitting verified users to continue and enhance the security of the system [See Esdaile, para. 0061, “In response to the workflow being successfully completed, the network device grants network resource access to the quarantined client device (operation 590), for example, by placing the client device from the quarantined state to the authenticated state.”] Allowable Subject Matter Claims 24, 33 and 40 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. 13. The following is examiner’s statements of reasons for allowance: The above prior arts of record including the rest of the cited prior arts including the prior arts cited in the IDS either taken alone or in combination neither anticipates nor renders obvious the claimed subject matter of the instant application that is taken as a whole including the following limitation recited in dependent claims 24, 33 and 40, “wherein a first factor pairing of the plurality of factor pairings comprises a first factor of a first factor type and a second factor of a second factor type different from the first factor type, and a second factor pairing of the plurality of factor pairings comprises the first factor of the first factor type and a third factor of a third factor type different from each of the first factor type and the second factor type” For this reason, the specific claim limitations recited in dependent claims 24, 33 and 40 taken as whole would be allowed if the current rejection set forth in this office action is overcome. Claims 25-29 and 34-38 depend on the above objected claims 24 and 33 respectively and would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. Conclusion 15. The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. a. US Patent No. 10721239 B2 Koottayi discloses threat detection, and more particularly, to techniques for managing user access to resources in an enterprise environment. Some aspects are directed to the concept of managing access to a target resource based on a threat perception of a user that is calculated using a rule or policy based risk for the user and a behavior based risk for the user. Other aspects are directed to preventing insider attacks in a system based on a threat perception for each user logged into the system that is calculated using a rule or policy based risk for each user and a behavior based risk for each user. Yet other aspects are directed to providing a consolidated view of users, applications being accessed by users, and the threat perception, if any, generated for each of the users. b. US Publication No. 20220417229 A1 Sood et al discloses time constrained electronic request evaluation. A server system receives, from a computing device, a request submitted via an account, including a first set of characteristics associated with the request. The system executes a first machine-learning model to determine a first risk score for the request by inputting the first set of characteristics into the first model. The system generates an initial authentication decision for the request based on the first score and sends the decision to the device. The system executes a second, different machine-learning model to determine a second risk score for the request, by inputting the first set of characteristics and a second, different set of characteristics associated with the account into the second model. Based on the second score, the system determines a final authentication decision. The disclosed techniques may advantageously improve computer security and operations via identification of malicious electronic requests c. US Publication No. 20230132635 A1 Cervantez discloses requests to perform activity with respect to a customer account can be monitored to attempt to detect fraudulent activity due to compromised customer credentials or other unauthorized access. The unauthorized party can request actions such as to create a new account, mount a snapshot of customer data, and exfiltrate the customer data. Various embodiments monitor such requests and permissions granted to accounts not directly owned by a customer, and can apply automatic mitigations for suspicious activity in order to reduce the risk of exposing data to unauthorized accounts. Such an offering determines mitigations to perform, such as to block, alert, rate limit, or terminate the linked or non-linked account based on account reputation. The detection mechanism can use various heuristics to make mitigation decisions, as may consider factors such as account age, geolocation, access history, device fingerprint, network domain, payment type, prior suspicious activity, and the like. d. See the other cited prior arts. Any inquiry concerning this communication or earlier communications from the examiner should be directed to SAMSON B LEMMA whose telephone number is 571-272-3806. The examiner can normally be reached on M-F 8am-10pm. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Shaw Yin Chen can be reached on to 571-272-8878. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /SAMSON B LEMMA/Primary Examiner, Art Unit 2498
Read full office action

Prosecution Timeline

Dec 23, 2024
Application Filed
Apr 09, 2025
Response after Non-Final Action
Sep 10, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12748896
PHYSICAL UNCLONABLE FUNCTION DEVICE AND METHOD
2y 4m to grant Granted Sep 29, 2026
Patent 12732520
GENERATION DEVICE, GENERATION METHOD, AND GENERATION PROGRAM
2y 0m to grant Granted Sep 08, 2026
Patent 12719874
SECURITY MANAGEMENT OF TRUSTED NETWORK FUNCTIONS
1y 8m to grant Granted Aug 25, 2026
Patent 12712643
SYSTEM AND METHOD FOR NETWORK DISTRIBUTION OF QUANTUM ENTANGLEMENT
1y 11m to grant Granted Aug 18, 2026
Patent 12694098
SYSTEMS AND METHODS FOR MANAGING STATE
1y 8m to grant Granted Jul 28, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
88%
Grant Probability
99%
With Interview (+11.2%)
2y 9m (~11m remaining)
Median Time to Grant
Low
PTA Risk
Based on 917 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month