Prosecution Insights
Last updated: August 17, 2026
Application No. 19/019,303

SYSTEMS AND METHODS FOR DISTRIBUTED NETWORK ACCESS CONTROL

Non-Final OA §101§103
Filed
Jan 13, 2025
Examiner
GELAGAY, SHEWAYE
Art Unit
2436
Tech Center
2400 — Computer Networks
Assignee
Capital One Services LLC
OA Round
1 (Non-Final)
72%
Grant Probability
Favorable
1-2
OA Rounds
3y 0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 72% — above average
72%
Career Allowance Rate
201 granted / 280 resolved
+13.8% vs TC avg
Strong +45% interview lift
Without
With
+45.3%
Interview Lift
resolved cases with interview
Typical timeline
4y 7m
Avg Prosecution
7 currently pending
Career history
297
Total Applications
across all art units

Statute-Specific Performance

§101
17.8%
-22.2% vs TC avg
§103
51.4%
+11.4% vs TC avg
§102
11.9%
-28.1% vs TC avg
§112
15.3%
-24.7% vs TC avg
Black line = Tech Center average estimate • Based on career data from 280 resolved cases

Office Action

§101 §103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Election/Restrictions Applicant's election with traverse of Group II (claims 2-20) in the reply filed on 07/08/2026 is acknowledged. In response to Applicant's argument on pages 12-13 of Remarks regarding the restriction requirement, Examiner respectfully disagrees for the following reasons. Group I and Group II are independent or distinct for the reasons given in the requirement for restriction office action issued on 06/23/2026. The two groups (Group I and Group II) require a different field of search including employing different search strategies and queries and as pointed out Group I directed to providing feedback while group II has providing access. The requirement is still deemed proper and is therefore made final. Claim Objections Claims 2 and 18 objected to because of the following informalities: claims 2 and 18 recite “one or more actions” in line 4 and “an action” in line 11 but not clear “an action” in line 11 is referring back to the same action recited line 4 or not. The phrase “to be provided” recited in claims 2, 11-13 and 18 are not positively recited limitation. Claim 10 recites “providing, by the edge node and to a user device for which the access is suspended, a form for the justification for the access based on determining to obtain the justification” the limitation is unclear as to how a form for the justification is provided based on determining to obtain the justification. Appropriate correction is required. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 2-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter. Claims 2 and 18 recite limitations generating, determining and performing an action could be all performed in the human mind and/or with the help of paper and pencil. The limitation receiving step is mere data gathering. Other than reciting edge node, cloud computing devices and machine learning model, nothing in the claims preclude the steps for being performed in the human mind. The limitations input and output information to a machine learning model is simply applying machine learning as a tool to improve the abstract idea. This judicial exception is not integrated into a practical application. The computers are recited at a high-level of generality such that it amounts no more than mere instructions to apply the exception using generic computer components. Accordingly, this additional element does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. Simply implementing the abstract idea on a generic computer environment is not a practical application of the abstract idea and does not take the claim out of the mental process and method of organizing a human activity grouping. The claims are directed to an abstract idea. The claims do not include additional elements that even in combination are sufficient to amount to significantly more than the judicial exception. As discussed above, with respect to integration of the abstract idea into a practical application, the additional element of using edge computing devices, cloud computing devices and machine learning model to perform generating, determining and performing an action step amounts to no more than mere instructions to apply the exception using generic computer components. Mere instructions to apply an exception using generic computer components cannot provide an inventive concept. The claims are not patent eligible. Dependent claims 3-17 and 19-20 also rejected under the same rationale set forth above because they also fail to recite any additional elements/steps that might integrates the abstract idea into a practical application. As such, claims 2-20 are not patent eligible. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 2-4, 6-8, 10, 12 and 18 are is/are rejected under 35 U.S.C. 103 as being unpatentable over Muddu et al. (US 2019/0109868), hereinafter Muddu and in view of Mullins et al. (US 2023/0421578), hereinafter Mullins and in view of Jakobsson et al. (US 2023/0385815), hereinafter Jakobsson Regarding claim 2, Muddu discloses a method comprising: receiving, by an edge node and from one or more cloud computing devices, a machine learning model configured to determine a risk of a threat of an access via the edge node; (para. [0005]-[0006], [0321], Network administrators seek to detect such activities, for example, by searching for patterns of behavior that are abnormal or otherwise vary from the expected use pattern of a particular entity, such as an organization or subset thereof, individual user, IP address, node or group of nodes in the network, etc … Security appliances are used in known systems to provide network security … installing security appliances … Once installed, the appliance monitors traffic that traverses the network. Functions provided by the appliance may include malware detection, intrusion detection, unauthorized access or unauthorized use of data, among others. Unfortunately, security appliances cannot easily be scaled to handle temporary or permanent increases in network traffic… an appliance will be unaware of activities occurring on other network segments monitored by other appliances and thus cannot use the additional context information pertaining to activities occurring on other network segments to detect a cleverly-designed piece of malware that may be difficult to detect from purely localized information) generating, by the edge node, a machine learning output that indicates the risk of the threat by inputting information regarding one or more actions into the machine learning model; (para. [0316]-[0318], execute a model deliberation process thread…a computation worker executes the model deliberation process thread. … the computation worker execute multiple model training process threads associated with a single model type. In some embodiments, the computation worker execute multiple model-specific process threads associated with a single model type. In some embodiments, the computation worker execute multiple model-specific process threads associated with different model types. At step 2102, the model deliberation process thread processes the most recent time slice from the group-specific data stream to compute a score associated with the most recent time slice. The most recent time slice can correspond to an event or a sequence of event observed at the target computer network. In some embodiments, the group-specific data stream used by the model deliberation process thread is also used by a corresponding model training process thread for the same entity. That is, the model training process thread can train a model state of an entity-specific machine learning model by processing a previous time slice of the group-specific data stream. The model execution engine 1808 can initiate the model deliberation process thread based on the model state while the model training process thread continues to create new versions (e.g., new model states). In some embodiments, the model deliberation process thread can reconfigure to an updated model state without pausing or restarting….the model deliberation process thread aggregates the security-related conclusion into the security-related conclusion store 1542. The aggregation of the security-related conclusions can be used in an analytic platform of the ML-based CEP engine 1500. In some embodiments, the security-related conclusion store 1542 is backed up to the distributed file system 1514. Optionally, at step 2108, the model deliberation process thread publishes the security-related conclusion to the messaging platform 1518, such that another model deliberation process thread or model training process thread can utilize the security-related conclusion) determining, by the edge node and based on the machine learning output that indicates the risk of the threat and based on a workflow for the threat, [[to suspend the access and that indications of consent]], for the access, are required from team computing devices; (para. [0319]-[0321], When the security-related conclusion indicates that a potential security breach (e.g., a threat or a threat indicator) has occurred, at step 2110, the model deliberation process thread can generate a user interface element to solicit an action command to activate a threat response. In one example, the user interface element triggers the action command for sending a message to the target-side computer system to demand termination of a problematic application, blocking of specific network traffic, or removal of a user account. In some embodiments, at step 2112, the model deliberation process thread can generate a user interface element to accept feedback from a user to confirm or reject the security-related conclusion. The model execution engine 1808 can provide the feedback to a model training process thread to update the model state used to configure the model deliberation process thread… the model deliberation process thread can compare the computed score or the generated security-related conclusion against that of other model deliberation process threads to determine if there are significant deviations or biases. The model deliberation process thread can also check to see if there is an unusual bias in its production of security-related conclusions. For example, if more than a threshold percentage of its security-related conclusions correspond to anomalies or threats, then the model deliberation process thread sets its own health status to failure. Based on the conclusion in step 2114, the model deliberation process thread can decommission itself at step 2116. In some embodiments, a separate process thread can perform steps 2114 and 2116 by externally monitoring the health status of the model deliberation process thread) Muddu does not explicitly disclose to suspend the access and that indications of consent; causing, by the edge node and based on determining that the indications of consent are required from the team computing devices, requests to be provided to the team computing devices for the indications of consent; and performing, by the edge node, an action based on whether the indications of consent, were received from the team computing devices. Mullins discloses causing, by the edge node and based on determining that the indications of consent are required from the team computing devices, requests to be provided to the team computing devices for the indications of consent; (para. [0005]-[0009], The one or more oracles may be configured to execute or to cause execution of a script, API, or other instructions or programs to generate the threat intelligence data at one or more corresponding nodes. The results from the one or more nodes may be transmitted back to the one or more oracles. The one or more oracles may then validate or invalidate a potential threat included in the threat intelligence request. In embodiments, the decision to validate or invalidate the potential threat of the threat intelligence request can be based on whether or not a consensus is reached by all of the nodes receiving the threat of intelligence request, and if all the nodes do not agree to validate, an error or other notice can be provided back to the oracle and/or the requestor. If a consensus is reached as to a validation or not, the validation or invalidation determination by the set of nodes may be transmitted back to the smart contract and used to update the smart contract) and performing, by the edge node, an action based on whether the indications of consent, were received from the team computing devices. (para. [0005]-[0009], [0011], … consensus driven threat intelligence utilizing a blockchain network…The threat intelligence request can include a request to gather intelligence related to a potential threat. The method may include broadcasting the threat intelligence request to one or more oracles configured to connect external information regarding potential threats to the blockchain. The method may include broadcasting the threat intelligence request from the one or more oracles to one or more corresponding nodes of the plurality of nodes. The method may include gathering threat intelligence data relating to the threat intelligence request at each of the one or more selected or corresponding nodes. The method may include determining, via a threat intelligence operation conducted at each of the one or more corresponding nodes and based on gathered threat intelligence data, a validation or invalidation of the potential threat. The method may include determining whether a consensus has been reached as to whether the potential threat is valid or invalid as determined by the threat intelligence operations conducted by each of the one or more corresponding nodes. The method may include, if a consensus is reached, submitting a threat entry including the gathered threat intelligence data relating to the determination of whether the potential threat of the threat intelligence request is valid or invalid resulting from the threat intelligence operations conducted by each of the one or more corresponding nodes to the at least one of the one or more smart contracts…the potential threat may be considered valid when each of the one or more corresponding nodes agrees on the validation of the potential threat submitted by the threat intelligence request). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings described by Mullins with the teaching of Muddu, and the motivation for such an implementation would be in order to provide consensus driven threat intelligence determination with increased reliability and readily available to and accessible by users of multiple computing devices (para. [0003], Mullins) Maddu in view of Mullins does not explicitly disclose, however, Jakobsson teaches to suspend the access and indications of consent that was received. (para. [0225]-[0226], quarantine states may facilitate review by third parties including but not limited to the owner(s) and/or creator(s) of the relevant smart contracts, marketplace administrators, and/or pre-determined authorities. For cases where, after review, the third party decides the address is allowed to own and/or receive tokens associated with the smart contract, the address may be added to the allowlist. Additionally or alternatively, when the third party decides the address is not allowed to own the token, the address may be added to the banlist… functionality that allows addresses to be removed from banlists and/or allowlists. .. access to the functionality of smart contracts may be limited to the owners and/or creators of the smart contract. … adding and/or removing addresses to banlists and/or allowlists may involve a requirement for a consensus among a group of pre-determined parties given a conditional level of access to the functionality. For example, consensus may be determined using decentralized autonomous organization (DAO) smart contracts) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings described by Jakobsson with the teaching of Muddu and Mullins, and the motivation for such an implementation would be in order to allow a system enabling and securing access (para. [0002]-[0003], Jakobsson) Regarding claim 3, Muddu in view of Mullins in view of Jakobsson teaches the method of claim 2. Muddu in view of Mullins in view of Jakobsson further discloses wherein generating the machine learning output comprises: generating the machine learning output by inputting the information regarding the one or more actions into an isolation forest machine learning model, wherein the machine learning model is the isolation forest machine learning model. (Muddu, [0543]-[0546], …. detecting similarities between users or devices and/or detecting deviations in an entity's activity from a behavioral baseline. For example, identification of node clusters can facilitate detection of lateral movement by user (e.g., a user accessing a device that he does not normally access) or detection of an account takeover situation … efficient, highly scalable, and parallelizable technique for identifying node clusters in a graph. The technique can be implemented by one or more of the above-mentioned machine learning models, for example, and can be implemented in the real-time path, the batch path, or both; Note the term “isolation forest machine learning model” is interpreted broadly in light of description provided in para. 24 of instant application) Regarding claim 4, Muddu in view of Mullins in view of Jakobsson teaches the method of claim 2. Muddu in view of Mullins in view of Jakobsson further discloses wherein generating the machine learning output comprises: generating the machine learning output by inputting the information regarding the one or more actions, an Internet Protocol (IP) address, information regarding an application programming interface (API) endpoint, and one or more of date information or time information. (Muddu, para. [0638] If an anomaly indicating malware in the computer network is detected, and indication of that anomaly can be outputted for display to a user via a user interface of a computing device … the entity identifier associated with the entity can be any identifier, such as a domain name, a uniform resource locater (URL), uniform resource identifier (URI), an Internet Protocol (IP) address, a unique identifier (UID), a device identification, or a user identification) Regarding claim 6, Muddu in view of Mullins in view of Jakobsson teaches the method of claim 2. Muddu in view of Mullins in view of Jakobsson further discloses wherein generating the machine learning output comprises: generating the machine learning output by inputting, into the machine learning model, particular information regarding accessing of a particular website during a particular time of day, wherein the information regarding the one or more actions includes the particular information. (Muddu, para. [0638] If an anomaly indicating malware in the computer network is detected, and indication of that anomaly can be outputted for display to a user via a user interface of a computing device … the entity identifier associated with the entity can be any identifier, such as a domain name, a uniform resource locater (URL), uniform resource identifier (URI), an Internet Protocol (IP) address, a unique identifier (UID), a device identification, or a user identification) Regarding claim 7, Muddu in view of Mullins in view of Jakobsson teaches the method of claim 2. Muddu in view of Mullins in view of Jakobsson further discloses generating the machine learning output by inputting, into the machine learning model, particular information regarding requesting access to a cloud computing account or a platform for storing code, wherein the information regarding the one or more actions includes the particular information, and wherein determining to suspend the access and that the indications of consent are required comprises: determining, based on the machine learning output that indicates the risk of the threat and based on the workflow for the threat, to suspend the access to the cloud computing account or the platform for storing code.(Mullins, para. [0005]-[0009], The one or more oracles may then validate or invalidate a potential threat included in the threat intelligence request. In embodiments, the decision to validate or invalidate the potential threat of the threat intelligence request can be based on whether or not a consensus is reached by all of the nodes receiving the threat of intelligence request, and if all the nodes do not agree to validate, an error or other notice can be provided back to the oracle and/or the requestor. If a consensus is reached as to a validation or not, the validation or invalidation determination by the set of nodes may be transmitted back to the smart contract and used to update the smart contract; Jakobsson, para. [0225]-[0226], quarantine states may facilitate review by third parties including but not limited to the owner(s) and/or creator(s) of the relevant smart contracts, marketplace administrators, and/or pre-determined authorities. … functionality that allows addresses to be removed from banlists and/or allowlists. .. access to the functionality of smart contracts may be limited to the owners and/or creators of the smart contract. … adding and/or removing addresses to banlists and/or allowlists), The same rationale as claim 2 above applies. Regarding claim 8, Muddu in view of Mullins in view of Jakobsson teaches the method of claim 2. Muddu in view of Mullins in view of Jakobsson further discloses determining to suspend the access based on comparing the machine learning output that indicates the risk of the threat to a particular numerical value indicated by the workflow for the threat. (Muddu, para. [0117], [0137], [0316]-[0317], the security platform introduced here can perform user behavioral analytics (UBA), or more generally user/entity behavioral analytics (UEBA), to detect the security related anomalies and threats, regardless of whether such anomalies and threats are previously known or unknown. Additionally, by presenting analytical results scored with risk ratings and supporting evidence, the security platform can enable network security administrators or analysts to respond to a detected anomaly or threat, and to take action promptly) Regarding claims 10, Muddu in view of Mullins in view of Jakobsson teaches the method of claim 2. Muddu in view of Mullins in view of Jakobsson further discloses determining to obtain a justification for the access based on determining to suspend the access and based on the workflow for the threat; and providing, by the edge node and to a user device for which the access is suspended, a form for the justification for the access based on determining to obtain the justification. (Muddu, [0117], anomalies, threat indicators and threats may be provided to a user interface (UI) system 350 for review by a human operator 352. …. The output of the analysis module 330 may also automatically trigger actions such as terminating access by a user, terminating file transfer, or any other action that may neutralize the detected threats. In certain embodiments, only notification is provided from the analysis module 330 to the UI system 350 for review by the human operator 352. … If the human operator decides to investigate a particular notification, he or she may access from database 378 the event data (including raw event data and any associated information) that supports the anomalies or threat detection. On the other hand, if the threat detection is a false positive, the human operator 352 may so indicate upon being presented with the anomaly or the threat. The rejection of the analysis result may also be provided to the database 378. The operator feedback information (e.g., whether an alarm is accurate or false) may be employed to update the model to improve future evaluation) Regarding claim 12, Muddu in view of Mullins in view of Jakobsson teaches the method of claim 2. Muddu in view of Mullins in view of Jakobsson further discloses wherein causing the requests to be provided comprises: selecting the team computing devices based on determining that the indications of consent are required from the team computing devices and based on the team computing devices being in one or more of same team or same local network as a user device for which the access is suspended; and causing the requests to be provided to the team computing devices based on selecting the team computing devices. Muddu, [0117], anomalies, threat indicators and threats may be provided to a user interface (UI) system 350 for review by a human operator 352. …. The output of the analysis module 330 may also automatically trigger actions such as terminating access by a user, terminating file transfer, or any other action that may neutralize the detected threats. In certain embodiments, only notification is provided from the analysis module 330 to the UI system 350 for review by the human operator 352. … If the human operator decides to investigate a particular notification, he or she may access from database 378 the event data (including raw event data and any associated information) that supports the anomalies or threat detection. On the other hand, if the threat detection is a false positive, the human operator 352 may so indicate upon being presented with the anomaly or the threat. The rejection of the analysis result may also be provided to the database 378. The operator feedback information (e.g., whether an alarm is accurate or false) may be employed to update the model to improve future evaluation) Regarding claims 18, Claim 18 is a computer program instruction with limitations similar to the method of claim 2, and is rejected under the same rationale. Claim(s) 5, 13-17 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Muddu et al. (US 2019/0109868), hereinafter Muddu and in view of Mullins et al. (US 2023/0421578), hereinafter Mullins and in view of Jakobsson et al. (US 2023/0385815), hereinafter Jakobsson and further in view of Cosman et al. (US 2021/0192078), hereinafter Cosman. Regarding claim 5, Muddu in view of Mullins in view of Jakobsson teaches the method of claim 2. Muddu in view of Mullins in view of Jakobsson does not explicitly discloses, however, Cosman discloses wherein generating the machine learning output comprises: generating the machine learning output by inputting, into the machine learning model, particular information regarding accessing of one or more code repositories a particular quantity of times and within a particular quantity of days, wherein the information regarding the one or more actions includes the particular information. (Cosman. para. [0027]-[0029], [0052]-[0059], [0073], [0085], set of time slots may be ranked based on device usage analysis for the period of time (608). The device usage analysis may provide information on preferences of particular times for a user device activity type (e.g., interacting with content items). The user device activity type may be interactions by the user with rendered content in the application 622, such as interactions with content items in a Photos application. By way of example, user device activity analysis may indicate that a user interacts with content items in a photos application at particular times of a day more often than at other times, such as before work, after work, and during lunch and the time slot may be ranked to indicate this preference. In another example, user device analysis may indicate that a user does not interact with photos of an event immediately following the occurrence event). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings described by Cosman with the teaching of Muddu, Mullins and Jakobsson, and the motivation for such an implementation would be in order to provide federated machine learning using distributed computing systems with building a user behavior model. (para. [0002], Cosman) Regarding claim 13, Muddu in view of Mullins in view of Jakobsson teaches the method of claim 2. Muddu in view of Mullins in view of Jakobsson does not explicitly discloses, however, Cosman discloses wherein causing the requests to be provided comprises: selecting the team computing devices based on determining that the indications of consent are required from the team computing devices and based on users of the team computing devices and a user device for which the access is suspended being grouped as a team by an instant messaging application; and causing the requests to be provided to the team computing devices based on selecting the team computing devices. (Cosman, para. [0009], [0061], the updated machine learning model comprising aggregated privatized model updates from one or more device groups of client devices, analyze local content item data with the received updated machine learning model, the local content item data comprising at least one of an association between the content item and a plurality of content item features or an association between the content item and one or more locally stored usage patterns, receive a set of predicted content item setting items based on analysis performed by the updated machine learning model with the local content item data, and present the set of predicted content item setting items in a user interface on the client device; communication e.g. text messaging; Muddu , [0117] discloses … If the human operator decides to investigate a particular notification, he or she may access from database 378 the event data (including raw event data and any associated information) that supports the anomalies or threat detection. On the other hand, if the threat detection is a false positive, the human operator 352 may so indicate upon being presented with the anomaly or the threat. The rejection of the analysis result may also be provided to the database 378. The operator feedback information (e.g., whether an alarm is accurate or false) may be employed to update the model to improve future evaluation). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings described by Cosman with the teaching of Muddu, Mullins and Jakobsson, and the motivation for such an implementation would be in order to provide federated machine learning using distributed computing systems with building a user behavior model. (para. [0002], Cosman) Regarding claim 14, Muddu in view of Mullins in view of Jakobsson teaches the method of claim 2. Muddu in view of Mullins in view of Jakobsson does not explicitly discloses, however, Cosman discloses generating the machine learning output by inputting, into the machine learning model, particular information regarding attempting to access a portable storage device, wherein the information regarding the one or more actions includes the particular information, and wherein determining to suspend the access and that the indications of consent are required comprises: determining, based on the machine learning output that indicates the risk of the threat and based on the workflow for the threat, to suspend the access to the portable storage device. (Cosman, para. [0009], the updated machine learning model comprising aggregated privatized model updates from one or more device groups of client devices, analyze local content item data with the received updated machine learning model, In addition, Maddu, para. [0117], discloses general security analytics and threat detection from event data, including device/activity-based anomalies). The same motivation as claim 13 applies. Regarding claim 15, Muddu in view of Mullins in view of Jakobsson teaches the method of claim 2. Muddu in view of Mullins in view of Jakobsson does not explicitly discloses, however, Cosman discloses wherein generating the machine learning output comprises: identifying one or more first actions, of the one or more actions, within a first timeseries window; identifying one or more second actions, of the one or more actions, within a second timeseries window that is different from the second timeseries window; identifying one or more third actions, of the one or more actions, within a third timeseries window that is different from the first timeseries window and the second timeseries window; and generating the machine learning output that indicates the risk of the threat by inputting, into the machine learning model, first information regarding the one or more first actions, second information regarding the one or more first actions, and third information regarding the one or more third actions, wherein the information regarding the one or more actions includes the first information, the second information, and the third information. (Cosman, para. [0009], [0027]-[0029], [0061], machine learning model may perform timeline generation. Timeline generation is the prediction of a set of content items (e.g., images, etc.) that the user may want rendered on the device within a user interface of an application (e.g., a photos application) during a period of time. Continuing with the example, the machine learning model may be trained to identify or predict the set of content items (e.g., images, video, audio, etc.) accessible from the user device that have features learned to be associated with content items that are temporally and contextually relevant to the user during that the particular period of time. The content items may have features that are relevant to the particular period of time. By way of example, users may interact with photos related to family during the week at work and interact with photos related to vacations or particular locations during the weekend… the updated machine learning model comprising aggregated privatized model updates from one or more device groups of client devices, analyze local content item data with the received updated machine learning model, the local content item data comprising at least one of an association between the content item and a plurality of content item features or an association between the content item and one or more locally stored usage patterns, receive a set of predicted content item setting items based on analysis performed by the updated machine learning model with the local content item data, and present the set of predicted content item setting items in a user interface on the client device; communication e.g. text messaging; Muddu , [0117] discloses discusses time series, timelines, event sequences, sequence analysis, and windowed behavioral analysis). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings described by Cosman with the teaching of Muddu, Mullins and Jakobsson, and the motivation for such an implementation would be in order to provide federated machine learning using distributed computing systems with building a user behavior model. (para. [0002], Cosman) Regarding claim 16, Muddu in view of Mullins in view of Jakobsson in view of Cosman teaches the method of claim 15. Muddu in view of Mullins in view of Jakobsson and in view of Cosman further does not explicitly discloses, however, Cosman discloses wherein identifying the one or more second actions comprises: identifying the one or more second actions based on a predefined interval that is between a beginning of the first timeseries window and a beginning of the second timeseries window, wherein the beginning of the second timeseries window is before an end of the second timeseries window. (Cosman, para. [0009], [0027]-[0029], [0061], timeline generation … the updated machine learning model comprising aggregated privatized model updates from one or more device groups of client devices, analyze local content item data with the received updated machine learning model, the local content item data comprising at least one of an association between the content item and a plurality of content item features or an association between the content item and one or more locally stored usage patterns, receive a set of predicted content item setting items based on analysis performed by the updated machine learning model with the local content item data, and present the set of predicted content item setting items in a user interface on the client device; communication e.g. text messaging; Muddu , [0117] windowed sequence and timeline analysis). Regarding claim 17, Muddu in view of Mullins in view of Jakobsson in view of Cosman teaches the method of claim 15. Muddu in view of Mullins in view of Jakobsson and in view of Cosman further discloses wherein identifying the one or more third actions comprises: identifying the one or more third actions based on the one or more third actions being related to one or more of same user, internet protocol (IP) address, or single sign-on (SSO) as the one or more first actions and the one or more second actions. (Muddu, [0166], para. correlation permits the security platform to make certain assumptions about the relationship between an IP address and a user so that, if any event data arrives from that IP address in the future, an assumption regarding which user is associated with that IP address may be made. In some implementations, the event data pertaining to that IP address may be annotated with the identity of the user). Regarding claim 20, Muddu in view of Mullins in view of Jakobsson in view of Cosman teaches the method of claim 18. Muddu in view of Mullins in view of Jakobsson and in view of Cosman further does not explicitly discloses, however, Cosman discloses wherein performing the action comprises: determining that the indications of consent were not received from the team computing devices; and providing, from an edge node that includes the one or more processors, via a network, and based on determining that the indications of consent were not received from the team computing devices, a request for consent, for the access, to a device of a risk manager of an entity where the one or more actions occurred, a device of a cyber security operations center (CSOC) that maintains cyber security for the entity, or a device of an application owner of an application for which the access was suspended. (Cosman, para. [0009], [0027]-[0029], [0061], machine learning model may perform timeline generation. Timeline generation is the prediction of a set of content items (e.g., images, etc.) that the user may want rendered on the device within a user interface of an application (e.g., a photos application) during a period of time. Continuing with the example, the machine learning model may be trained to identify or predict the set of content items (e.g., images, video, audio, etc.) accessible from the user device that have features learned to be associated with content items that are temporally and contextually relevant to the user during that the particular period of time. The content items may have features that are relevant to the particular period of time. By way of example, users may interact with photos related to family during the week at work and interact with photos related to vacations or particular locations during the weekend… the updated machine learning model comprising aggregated privatized model updates from one or more device groups of client devices, analyze local content item data with the received updated machine learning model, the local content item data comprising at least one of an association between the content item and a plurality of content item features or an association between the content item and one or more locally stored usage patterns, receive a set of predicted content item setting items based on analysis performed by the updated machine learning model with the local content item data, and present the set of predicted content item setting items in a user interface on the client device; Muddu , [0117] discloses discusses time series, timelines, event sequences, sequence analysis, and windowed behavioral analysis). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings described by Cosman with the teaching of Muddu, Mullins and Jakobsson, and the motivation for such an implementation would be in order to provide federated machine learning using distributed computing systems with building a user behavior model. (para. [0002], Cosman) Claim(s) 9 is rejected under 35 U.S.C. 103 as being unpatentable over Muddu et al. (US 2019/0109868), hereinafter Muddu and in view of Mullins et al. (US 2023/0421578), hereinafter Mullins and in view of Jakobsson et al. (US 2023/0385815), hereinafter Jakobsson and further in view of Buck et al. (US 2020/0285761), hereinafter Buck. Regarding claim 9: Muddu in view of Mullins in view of Jakobsson teaches the method of claim 2. Muddu in view of Mullins in view of Jakobsson does not explicitly discloses, however, Buck discloses wherein determining to suspend the access comprises: determining to suspend single sign-on (SSO) based on comparing the machine learning output that indicates the risk of the threat to a particular numerical value indicated by the workflow for the threat. ([0326] suspend single sign on access requests, match as a result from a machine learning model) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings described by Buck with the teaching of Muddu, Mullins and Jakobsson, and the motivation for such an implementation would be in order to provide a system to configure permissions for computing devices associated with a change of context for a computing device and/or a permission request for software on a computing device. (para. [0001], Buck) Claim(s) 11 is rejected under 35 U.S.C. 103 as being unpatentable over Muddu et al. (US 2019/0109868), hereinafter Muddu and in view of Mullins et al. (US 2023/0421578), hereinafter Mullins and in view of Jakobsson et al. (US 2023/0385815), hereinafter Jakobsson and further in view of Cambric et al. (US 2023/0315840), hereinafter Cambric. Regarding claim 11: Muddu in view of Mullins in view of Jakobsson teaches the method of claim 10. Muddu in view of Mullins in view of Jakobsson does not explicitly discloses, however, Cambric discloses wherein causing the requests to be provided comprises: generating forms, for the requests, that include information identifying the justification; and causing the forms to be provided to the team computing devices. (Cambric, [0041], [0066] Monitor 132 is configured to monitor actions performed on workload identities by other workload identities and/or by user identities with respect to identity service 128 after the user identities have been authenticated by and remain authenticated with identity service 128, as well as actions subsequently taken by workload identities… in the context of user identities, detection may include whether certain users (e.g., privileged users) changed federation settings or domains, whether an administrator consented to permissions on behalf of a tenant of a cloud-based platform, whether an administrator consented to certain permission grants, whether a scope (e.g., a regional scope) of an administrative unit of identity service 128 of FIG. 1 (that restricts permissions in a role to a certain portion of an organization) is changed, whether a user identity is viewing other user or group attributes (such as permission grants) or updating credentials, whether a user identity is viewing sensitive documents or downloading certain files or a large number of files, whether a user identity is viewing downloading, exporting identity related information, whether a user identity is creating new user accounts, groups, or cloud-based subscriptions, whether a user identity is changing user or group attributes or permissions, whether a previously-dormant account performs mass downloads, reads configuration settings, etc., whether a previously-dormant account is assigned new attributes or provided access to certain resources, whether the same user identity is enabling dormant users, whether an administrator resets a user account) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings described by Cambric with the teaching of Muddu, Mullins and Jakobsson, and the motivation for such an implementation would be in order to provide a system to detect anomalous behavior/state changes with a mitigation action to mitigate the anomalous behavior. (Abstract, Cambric) Claim(s) 19 are rejected under 35 U.S.C. 103 as being unpatentable over Muddu et al. (US 2019/0109868), hereinafter Muddu and in view of Mullins et al. (US 2023/0421578), hereinafter Mullins and in view of Jakobsson et al. (US 2023/0385815), hereinafter Jakobsson and further in view of Gennetten et al. (US 2023/0153191), hereinafter Gennetten. Regarding claim 19: Muddu in view of Mullins in view of Jakobsson teaches the method of claim 10. Muddu in view of Mullins in view of Jakobsson does not explicitly discloses, however, Cambric discloses performing the action comprises: providing, from an edge node that includes the one or more processors and to one or more cloud computing devices, feedback information that is based on whether the indications of consent were received from the team computing devices ([0034]-[0038], historical data may include one or more of batch objects data, incidents data, change order data, and so on… critical data may be identified via feedback, e.g. from the underlying event based process automation system(s), such as log data, datapoints, build data, workflow data, survey results, information or insights obtained from entities such as developers, users and/or customers associated with the batch processes, problems and issues encountered in the past, changes made to batch process or system in the past, and the like. In some examples, based on various data or inputs associated with successful, complete, and/or timely availability of files, identifiable intra-dependency and/or inter-dependence information associated or involved with workflows, dynamic thresholds configured to trigger alerts, etc., various relevant data can be identified as critical data to train a future failure prediction model to forecast on the corresponding aspects with regard to the execution of the batch process; Muddu, [0117], anomalies, threat indicators and threats may be provided to a user interface (UI) system 350 for review by a human operator 352). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings described by Genetten with the teaching of Muddu, Mullins and Jakobsson, and the motivation for such an implementation would be in order to provide a system for predicting a future failure and/or future flag in execution of the batch processes using the trained machine learning model and/or the descriptive analytics (Abstract, Gennetten) Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Klish et al. (US 2026/0119475) directed to consent preference data to consent preference categories is mapped. Consent preference data and mappings are stored in user profiles. Consent preference data is transmitted to destinations based on the results of the mapping. Sankar et al. (US 2021/0192412) directed to improve machine learning-based bots for exception handling. Cabtree et al. (US 2024/0022546) directed to network security, and more particularly detection and mitigation of cyberattacks involving forged authentications. Any inquiry concerning this communication or earlier communications from the examiner should be directed to Shewaye Gelagay whose telephone number is (571)272-4219. The examiner can normally be reached Monday to Friday 8 A.M. - 4 P.M.. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Amy C. Johnson can be reached at (571) 272-2238. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /SHEWAYE GELAGAY/ Supervisory Patent Examiner, Art Unit 2436
Read full office action

Prosecution Timeline

Jan 13, 2025
Application Filed
Jul 23, 2026
Examiner Interview (Telephonic)
Aug 05, 2026
Non-Final Rejection mailed — §101, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12566858
Computer System for Failing a Secure Boot in a Case Tampering Event
4y 2m to grant Granted Mar 03, 2026
Patent 12563030
PER-SERVER CUSTOMIZED ACCESS CREDENTIALS
3y 3m to grant Granted Feb 24, 2026
Patent 8943581
CONTROLLED ACCESS TO FUNCTIONALITY OF A WIRELESS DEVICE
2y 6m to grant Granted Jan 27, 2015
Patent 8924716
COMMUNICATION DEVICE AND COMMUNICATION METHOD
1y 11m to grant Granted Dec 30, 2014
Patent 8918895
PREVENTION OF INFORMATION LEAKAGE FROM A DOCUMENT BASED ON DYNAMIC DATABASE LABEL BASED ACCESS CONTROL (LBAC) POLICIES
1y 7m to grant Granted Dec 23, 2014
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
72%
Grant Probability
99%
With Interview (+45.3%)
4y 7m (~3y 0m remaining)
Median Time to Grant
Low
PTA Risk
Based on 280 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month