Prosecution Insights
Last updated: August 17, 2026
Application No. 19/012,743

AUTOMATED PROVISIONING OF ADAPTED CYBERSECURITY POLICY SETS

Non-Final OA §103
Filed
Jan 07, 2025
Examiner
RASHID, HARUNUR
Art Unit
2497
Tech Center
2400 — Computer Networks
Assignee
Dell Products L.P.
OA Round
1 (Non-Final)
76%
Grant Probability
Favorable
1-2
OA Rounds
1y 9m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 76% — above average
76%
Career Allowance Rate
476 granted / 626 resolved
+18.0% vs TC avg
Strong +36% interview lift
Without
With
+36.3%
Interview Lift
resolved cases with interview
Typical timeline
3y 4m
Avg Prosecution
25 currently pending
Career history
654
Total Applications
across all art units

Statute-Specific Performance

§101
13.4%
-26.6% vs TC avg
§103
60.8%
+20.8% vs TC avg
§102
5.4%
-34.6% vs TC avg
§112
7.4%
-32.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 626 resolved cases

Office Action

§103
DETAILED ACTION 1. Claims 1-20 are pending in this examination. Notice of Pre-AIA or AIA Status 2. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . 3. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. Claim Objections 4.1. Claim objected to because of the following informalities: 4.2. As to claim 1, Applicant recites, "...operation can be applied;…”The MPEP interprets claim limitations that contain "if, may, might, can, can be, when and could" statement(s), as optional language. As matter of linguistic precision, optional claim elements do not narrow claim limitations, since they can always be omitted. Language that suggests or makes optional but does not require steps to be performed or does not limit a claim to a particular structure does not limit the scope of a claim or claim limitation. Claim 11 contains similar language found in claim 1. Appropriate correction is required. Claim Rejections - 35 USC § 103 5.1. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 5.2. Claims 1-2, 5-6, 8-10, 11-12, 15-16, 18-20 are rejected under 35 U.S.C. 103 as being unpatentable over US Patent Application No. 11895121 issued to Karim et al (“Karim”) in view of US Patent Application No. 20190327271 to Saxena et al (“Saxena”). As per claim 1, Karim discloses a method for implementing a policy hot-start in an environment, comprising: receiving, as input, respective descriptions of reference environments, a respective set of reference operating policies for each of the reference environments, and a description of a target environment (Col. 58, lines 45-67 to col. 59, lines 1-20 (216) FIG. 13A-13B illustrates a process flow of identifying and remediating excessive privileges of Identity and Access Management (IAM) roles and/or policies for a system, according to one or more embodiments. At step 1302, an IAM role validation is initiated on-demand or whenever RPESAL is updated because of changes detected by Job Role or Service Task Monitor System 1007. Updating baselines that do not have excessive privileges whenever job role or service description changes provides the ability to dynamically adopt baselines to changes in the Role Descriptions and Service Task Descriptions. The IAM role validation is performed to provide access to any other functionality or perform permissions management. At step 1304, the system reads and generates a cloud provider service action access reference list. At step 1306, the system retrieves IAM baselines for the IAM role from a compliance solution (e.g., C2VS) repository. At step 1308, the system reads IAM roles and policies from the baselines retrieved. At step 1310, the system analyzes each IAM role. At step 1312, the system retrieves policies for the each IAM role. At step 1314, the system retrieves Machine-Readable Role Definition for each role. At step 1316, the system generates Role Potential Excessive Service Action List (RPESAL) based on the MRRD. At step 1318, the system generates Role Actual Excessive Service Action List (RAESAL) for each policy. In an embodiment, the system may invoke policy simulator/IAM access analyzer to generate RAESAL. (217) At step 1320, the system determines whether the RAESAL is not empty. At step 1322, the system detects no excess permissions. At step 1324, the system persists in placing the results in the compliance solution (e.g., C2VS) repository. At step 1326, the system detects excess permissions and the RAESAL is not empty and proceeds to step 1324. At step 1328, the system generates remediation instructions until empty and proceeds to step 1324. At step 1330, the system determines whether the remediation can be automated. At step 1332, the system automatically remediates the excessive privileges. At step 1334, the system manually remediates the excessive privileges. At step 1336, the system updates IAM role and policy baselines once the remediation is done, also see figs. 13a-12B, 14 and associated texts, col. 56, lines 58-67 to col. 57, lines 1-20); using respective graphs to represent each of the reference environments (col. 9, lines 20-40, 162, The above mentioned features may be helpful in visualizing and analyzing security configuration scan results, lists of components that include environment(s) for an Information System, data flows, security controls, and metadata. Standard KPIs, charts, historical trends, etc., along with the root cause analyses, may help a human analyst narrow down misconfiguration issues of custom applications 210 and associated components thereof. Exemplary embodiments may also provide for anomaly detection and root cause analyses of misconfigurations based on historical scan results using machine learning and deep learning models. Summary and analyses of thousands of components along with hundreds of thousands of configurations through normal visualization and dashboards may not be efficient. In addition, in one or more embodiments, incorporation of machine learning and Artificial Intelligence (AI) technologies within the computing system may enable prediction of potential issues to be encountered when a new environment is provisioned, and all applications are deployed and configured therewith, also see col. 33, lines 37-60.); mapping from the reference environments to a target environment by applying a graph alignment technique to the graphs (Col. 60, lines 1-25, also see figs. 13a-12B, 14 and associated texts, col. 51, lines 1-40); and automatically generating a set of policies compatible with the description of the target environment by mapping the reference policies to the target environment (Col. 59, lines 5-45, (218) FIG. 14 illustrates a process flow of monitoring IAM Role Policies for excessive privilege drifts, according to one or more embodiments. At step 1402, the system initiates a scan for excessive privileges of roles/policies in target environment. At step 1404, the system compares target environment IAM role policies with IAM role policies during baseline establishment. At step 1406, the system determines whether any drifts exist in the baselines. At step 1408, the system retrieves roles of a policy if any drifts exist in the IAM roles policies. At step 1410, the system retrieves MRRD for each role. At step 1412, the system then generates RPESAL for each role. At step 1414, the system then generates RPESAL for each role associated with the policy. In an embodiment, the system invokes policy simulator for each drifted policy and for generating RPESAL. At step 1416, the system then generates role and RAESAL (Role Actual Excessive Service Action List) for each drifted policy. (219) FIG. 15 illustrates a logical architecture of a system for identifying excessive privileges, remediating and visualizing the security configurations, according to one or more embodiments. The logical architecture depicts a Role Potential Actual Excessive Service Action List (RPESAL) generator 1502, a security policy hardening advisor 1504, and an advanced IAM role/policy remediation engine 1506. The logical architecture further depicts security configuration remediation engine 234, and analytics and visualization engine 232). Karim does not explicitly disclose however in the same field of endeavor, Saxena discloses normalizing the reference operating policies in a normalized description form in which alignment operations can be applied ([0051]-[0056], also see [0131]-[0133], [0211]) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Karim with the teaching of Saxena by including the feature of normalization, in order for Karim’s system to to determine, maintain, and audit policies for the IT infrastructure using Machine learning and/or Artificial Intelligence techniques. Obtaining one or more normalized access control policies associated with one or more first entities based on a stored access control policy representation governing access to a set of resources in an information technology (IT) infrastructure comprising a plurality of subsystems; determining, based on the one or more normalized access control policies, at least one entity cluster associated with the one or more first entities; determining one or more derived access control policies corresponding to the at least one entity cluster; and determining a set of non-compliant access control policies, wherein the set of non-compliant access control policies comprises: a first subset of the one or more normalized access control policies that are non-compliant with one or more stated access control policies applicable to the at least one entity cluster, or a subset of the one or more derived access control policies that are non-compliant with the one or more stated access control policies, or a combination thereof (Saxena, [0006]). As per claim 2, the combination of Karim and Saxena discloses the method as recited in claim 1, wherein the reference policies mapped to the target environment are subjected to a validation process (Karim, col. 33, lines 5-20, also see col. 34, lines 40-50). As per claim 5, the combination of Karim and Saxena discloses the method as recited in claim 1, wherein the reference policies, and the set of policies that was automatically generated, comprise respective cybersecurity policies (Karim, col. 7, lines 40-55, also see col. 5, lines 15-30). As per claim 6, the combination of Karim and Saxena discloses the method as recited in claim 1, wherein each of the reference policies, and policies in the set of policies, comprises a respective set of one or more rules (Saxena, [0071]-[0072], [0113]-[0132] ). The motivation regarding the obviousness of claim 1 is also applied to claim 6. As per claim 8, the combination of Karim and Saxena discloses the method as recited in claim 1, wherein the mapping comprises determining an extent to which the reference environments are similar to the target environment (Karim, col. 59, lines 20-35, also see col. 58, lines 45-67, figs. 13a-12B, 14 and associated texts.). As per claim 9, the combination of Karim and Saxena discloses the method as recited in claim 1, wherein the target environment is either a new environment, or a modified environment (Karim, col. 59, lines 20-40, col. 12, lines 55-67). As per claim 10, the combination of Karim and Saxena discloses the method as recited in claim 1, wherein the graphs are generated based on the input (Karim, col. 37, lines 18-40). Claim 11, is rejected for similar reasons as stated above. Claim 12, is rejected for similar reasons as stated above. Claim 15, is rejected for similar reasons as stated above. Claim 16, is rejected for similar reasons as stated above. Claim 18, is rejected for similar reasons as stated above. Claim 19, is rejected for similar reasons as stated above. Claim 20, is rejected for similar reasons as stated above. 5.3. Claims 3 and 13 are rejected under 35 U.S.C. 103 as being unpatentable over Karim and Saxena as applied to claim above, and in view of US Patent Application No. 20230319115 to Shah et al (“Shah”). As per claim 3, the combination of Karim and Saxena discloses the invention as described above. Karim and Saxena do not explicitly disclose however, In the same field of endeavor, Shah discloses the method as recited in claim 1, wherein one or more of the reference environments, and the target environment, comprise respective ZTAs (zero-trust architectures) ([0018], [0086]-[0087], also see [0094]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Karim with the teaching of Saxena/Shah by including the feature of ZTA, in order for Karim’s system to ensure the successful implementation of the policy. A policy manager may be employed in a network to help establish and maintain a “zero trust” security model for the network (i.e., where, by default, new devices, applications, and users have no permissions and/or access to any part of the network and all access must be specifically whitelisted). That is, a policy manager may proactively identify policies that conflict with the “zero trust” model and provide recommendations to modify the policies and/or otherwise modify those policies automatically (Shah, [0018]). Claim 13, is rejected for similar reasons as stated above. 5.4. Claims 4 and 14 are rejected under 35 U.S.C. 103 as being unpatentable over Karim and Saxena as applied to claim above, and in view of US Patent Application No. 20210173874 to Giddings et al (“Giddings”). As per claim 4, the combination of Karim and Saxena discloses the invention as described above. Karim and Saxena do not explicitly disclose however, In the same field of endeavor, Giddings discloses the method as recited in claim 1, wherein the graphs each comprise a respective KG (knowledge graph) in which network entities in the reference environment to which the KG applies are represented in the KG as respective nodes, and relationships between the nodes in the reference environment are represented in the KG as edges connecting the nodes ([0060], [0015], also see [0033]-[0034]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Karim with the teaching of Saxena/Giddings by including the feature of knowledge, in order for Karim’s system to generating Search results and include search queries related to the selected entity. The search results that are generated as disclosed herein may be include a high accuracy. In some examples, feature and context based search result generation may include identifying, based on analysis of a query feature associated with a query context of a query, and an entity feature associated with an entity context of each entity of a plurality of entities, a reduced number of entities that match the query. Based on analysis of a further query feature and a further entity feature, further matching analysis of the query to the reduced number of entities may be performed. The query may be linked by a linking model to an entity of the reduced number of entities to generate a query and entity pair. Selection of an entity may be received, and a linked plurality of queries and entities may be searched. In this regard, search results may be generated and include a set of queries that is associated with the selected entity (Giddings, abstract). Claim 14, is rejected for similar reasons as stated above. 5.6. Claims 7 and 17 are rejected under 35 U.S.C. 103 as being unpatentable over Karim and Saxena as applied to claim above, and in view of US Patent Application No. 20220318059 to Cook et al (“Cook”). As per claim 7, the combination of Karim and Saxena discloses the invention as described above. Karim and Saxena do not explicitly disclose however, In the same field of endeavor, Cook discloses the method as recited in claim 1, wherein an FOL (first-order logic) approach is used to render each of the reference operating policies into a normalized description form ([0015]). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Karim with the teaching of Saxena/Cook by including the feature of FOL, in order for Karim’s system to enabling efficient computation of SMT queries expressed in first order logic and including theory variables, thereby also helping to improve the security posture of organizations' computing resources provided by cloud provider networks and other operating environments. These challenges, among others, are addressed by techniques described herein for efficiently distributing the analysis of SMT queries expressed in first-order logic and including theory variables among any number of separate computing resources (e.g., among separate processes, compute instances, containers, etc.). According to embodiments described herein, for example, a service of a cloud provider network receives a request to determine whether a formula is satisfiable (e.g., to verify some expected behavior of a users' or organizations' set of policies or other such automated reasoning-based analysis). The service identifies a set of predicates in the formula based on a type of theory associated with the formula, where each predicate is a binary-valued function of at least one theory variable contained in the formula. In some embodiments, a search space associated with the formula is then partitioned into a set of sub-formulas, where each sub-formula is defined by a union of the formula with an assumption that a respective predicate of the set of predicates is either true or false. In some embodiments, a respective sub-formula of the set of sub-formulas is sent to an SMT solver running on each of a plurality of separate computing resources. Once an indication is received from the SMT solver running any of the computing resources that its respective sub-formula is satisfiable, the policy analysis service can cause display of information indicating that the formula is satisfiable; otherwise, the policy analysis service can cause display of or otherwise transmit information indicating the formula is unsatisfiable. Among other benefits, the described analysis techniques enable efficient computation of SMT queries expressed in first order logic and including theory variables, thereby also helping to improve the security posture of organizations' computing resources provided by cloud provider networks and other operating environments (Cook, [0015]). Claim 17, is rejected for similar reasons as stated above. 6.1. The prior art made of record and not relied upon is considered pertinent to applicant's disclosure as the prior art discloses many of the claim features (See PTO-form 892). 6.2. a). US Patent Application No. 20260004204 to Myers et al., discloses systems and methods described herein enable adaptive, threshold-based modification of node maps representing ontologies, knowledge graphs, or code development pipelines using generative artificial intelligence. The disclosed platform can retrieve a node map and generate one or more candidate perturbations that modify nodes or relationships within the node map. The disclosed platform can evaluate the effect of the perturbations by comparing respective outputs against ground-truth data. Perturbations can be automatically determined based on changes in external datasets, compliance policies, or operational requirements. The perturbations can be implemented when a computed perturbation quality value satisfies a threshold quality criterion. As such, the system enables efficient, policy-compliant evolution of relational system architectures in dynamic environments. b). US Patent Application No. 20190014153 to LANG et al., discloses a system and method for managing implementation of policies in an information technologies system receives at least one policy function, at least one refinement template and at least one available policy function from the at least one memory, receives a policy input indicating a high level policy for the IT system where the policy input is compliant with the at least one policy function and is received in a format that is not machine-enforceable at an enforcement entity of the IT system, based on the received policy input, automatically or semi-automatically generates a machine-enforceable rule and/or configuration by filling the at least one refinement template, where the machine-enforceable rule and/or configuration includes the at least one available policy function and being compliant with the received policy input, and distributes the machine-enforceable rule and/or configuration to the at least one memory of the IT system or another at least one memory to thereby enable implementation of the policies. Conclusion 7. Any inquiry concerning this communication or earlier communications from the examiner should be directed to HARUNUR RASHID whose telephone number is (571)270-7195. The examiner can normally be reached 9 AM to 5PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Eleni A. Shiferaw can be reached at (571) 272-3867. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. HARUNUR . RASHID Primary Examiner Art Unit 2497 /HARUNUR RASHID/Primary Examiner, Art Unit 2497
Read full office action

Prosecution Timeline

Jan 07, 2025
Application Filed
Jul 30, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12706945
Network Environment Control Scanning Engine
1y 8m to grant Granted Aug 11, 2026
Patent 12701003
MACHINE LEARNING FOR AUTOMATIC IDENTIFICATION OF POINTS OF INTEREST FOR SIDE CHANNEL LEAKAGE
1y 8m to grant Granted Aug 04, 2026
Patent 12694435
DATA MESH BASED ENVIRONMENTAL AUGMENTATION
2y 8m to grant Granted Jul 28, 2026
Patent 12671466
METHOD AND DEVICE FOR TRANSMITTING AND RECEIVING SIGNAL IN WIRELESS COMMUNICATION SYSTEM
2y 4m to grant Granted Jun 30, 2026
Patent 12632567
MICRO CONTROLLER UNIT AND SECURITY DIAGNOSIS METHOD THEREOF
1y 8m to grant Granted May 19, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
76%
Grant Probability
99%
With Interview (+36.3%)
3y 4m (~1y 9m remaining)
Median Time to Grant
Low
PTA Risk
Based on 626 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month