Prosecution Insights
Last updated: August 07, 2026
Application No. 19/041,845

Generating and Implementing Organizational Security Policies

Non-Final OA §101§102§103
Filed
Jan 30, 2025
Priority
Mar 03, 2021 — provisional 63/156,282 +1 more
Examiner
TO, BAOTRAN N
Art Unit
Tech Center
Assignee
People Center Inc.
OA Round
1 (Non-Final)
86%
Grant Probability
Favorable
1-2
OA Rounds
10m
Est. Remaining
98%
With Interview

Examiner Intelligence

Grants 86% — above average
86%
Career Allowance Rate
574 granted / 667 resolved
+26.1% vs TC avg
Moderate +12% lift
Without
With
+12.4%
Interview Lift
resolved cases with interview
Typical timeline
2y 5m
Avg Prosecution
17 currently pending
Career history
675
Total Applications
across all art units

Statute-Specific Performance

§101
14.8%
-25.2% vs TC avg
§103
38.6%
-1.4% vs TC avg
§102
15.9%
-24.1% vs TC avg
§112
12.7%
-27.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 667 resolved cases

Office Action

§101 §102 §103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This Office action is responsive to Preliminary Amendment filed on 08/06/2025. Claims 2-20 have been newly added. Claims 1-20 are presented for examination. Information Disclosure Statement The information disclosure statement (IDS) submitted on 01/30/2025. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Regarding independent claims 1, 18, and 20, the claims recite “accessing, by a computing system comprising one or more processors, a security request associated with generating a security policy based at least in part on organizational data comprising one or more organizational records, wherein the security request comprises one or more rules associated with the security policy; determining, by the computing system, based at least in part on the security request, the one or more rules that are in compliance with one or more policies associated with the organizational data; generating, by the computing system, the security policy based at least in part on the one or more rules that are in compliance with the one or more policies; and performing, by the computing system, one or more operations associated with implementing the security policy”. The limitations of accessing a security request associated with generating a security policy based at least in part on organizational data comprising one or more organizational records, wherein the security request comprises one or more rules associated with the security policy; determining, by the computing system, based at least in part on the security request, the one or more rules that are in compliance with one or more policies associated with the organizational data; generating, by the computing system, the security policy based at least in part on the one or more rules that are in compliance with the one or more policies; and performing, by the computing system, one or more operations associated with implementing the security policy, as drafted is a process that, under its broadest reasonable interpretation, covers performance of the limitation in the mind. If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for recitation of generic computer components, then it falls within the “Mental Processes” grouping of abstract ideas. Therefore, the claims recite an abstract idea. This judicial exception is not integrated into a practical application. In particular, the claim only recites one additional element – using a processor to perform the accessing, determining, generating, and performing steps. The processor in the steps is recited at a high-level of generality (i.e., as a generic processor performing a generic computer function of performing one or more operations associated with implementing the security policy) such that it amounts no more than mere instructions to apply the exception using a generic computer component. Accordingly, this additional element does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. The claim is directed to an abstract idea. The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional element of using a processor to perform the accessing, determining, generating, and performing steps that amounts to no more than mere instructions to apply the exception using a generic computer component. Mere instructions to apply an exception using a generic computer component cannot provide an inventive concept. The claims 1-20 are not patent eligible. Claim Rejections - 35 USC § 102 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. Claim(s) 1-2, 4-11, 13-14, 16, 18, and 20 are rejected under 35 U.S.C. 102(a)(1) and/or 102(a)(2) as being anticipated by Kahn (US Patent No. 7,185,192 B1) listed in IDS dated 01/30/2025 hereinafter Kahn. Regarding claim 1, 18, and 20, Kahn discloses a computer-implemented method, system, and medium of implementing security policies, the computer-implemented method comprising: accessing, by a computing system (fig. 2, server 200) comprising one or more processors (fig. 2, processor 220), a security request associated with generating a security policy based at least in part on organizational data comprising one or more organizational records (fig. 1-2, resources 160-1 to 160-N) (col. 30, lines 5-16, processing an access request 301 (query or resource) against the master set of rules 350-4 to select which rules will be applied (i.e., selection of the selected set of rules 318) to make an access control decision 301-1 or to produce query result 301-2.) wherein the security request comprises one or more rules associated with the security policy (col. 10, lines 28-30, a requestor can submit an access request to the system of the invention. Access requests can specify, for example, an identity of a requestor, a type of access requested, and a resource to which this requester requests the access); determining, by the computing system, based at least in part on the security request, the one or more rules that are in compliance with one or more policies (fig. 3 or 5, master rule set 350-4) associated with the organizational data (fig. 7, step 420-421, rule engine 315 determines identity of resource to which access is requested and determines role identity of requestor submitting the access request and col. 30, lines 17-30, for steps 420 and 421, the identity of the resource and the identity of the role requester are equal to the respective values of the RESOURCE and REQUESTOR portions as specified in the access request 301 received in step 400 (FIG. 6). However, the RESOURCE and/or the REQUESTOR information indicated within the access request 301 may specify values indicating a username, a software application, or a specific computer or peripheral device which the rule or query engine 315, 320, in respective steps 420 and 421, can then compare to a resource or role identity table that matches this information to a specific resource or requestor role identity, such as one of the role identities or resource identities in Columns 1 and 2 of Table 1 shown above); generating, by the computing system, the security policy (produce the selected set of rules 318) based at least in part on the one or more rules that are in compliance with the one or more policies (col. 31, lines 31-43, If the access request 301 is a resource access request 301-1, then the rule engine 315 processes step 422 in FIG. 7. In step 422, the rule engine 315 applies at least one filter operation, using the identity of the resource and/or the role identity of the requestor and/or the a type of access being requested, for rules in the master set of rules 350-4 to produce the selected set of rules 318 upon which the access control decision will be based. In other words, the rule engine 315, in step 422, applies filter operations to the access request 301 to determine what rules might apply (i.e., to determine an initial set of applicable rules--the selected set of rules 318) to an access control decision for the access request 301); and performing, by the computing system, one or more operations associated with implementing the security policy (abstract, the processor further performs at least one rule operation based on the subset of rules to produce an access control decision). Regarding claim 2, Kahn discloses the computer-implemented method of claim 1, wherein the one or more rules are based on an application specific query language that is associated with the security policy (col. 23, lines 4-67). Regarding claim 4, Kahn discloses the computer-implemented method of claim 1, wherein the one or more policies comprise one or more access policies that define one or more users that are permitted to access one or more applications associated with the one or more organizational records (fig. 5, col. 14, line 5- col. 15, line 67, table 1). Regarding claim 5, Kahn discloses the computer-implemented method of claim 1, wherein the organizational data comprises information associated with one or more organizational divisions, and wherein each of the one or more organizational divisions is associated with a portion of the one or more organizational records (col. 13, lines 15-52). Regarding claim 6, Kahn discloses the computer-implemented method of claim 5, wherein the security policy is implemented on the one or more organizational divisions (col. 13, lines 15-52). Regarding claim 7, Kahn discloses the computer-implemented method of claim 5, wherein the portion of the one or more organizational records in the one or more organizational divisions is organized in accordance with a hierarchical ranking in which the one or more organizational records are respectively associated with one or more statuses, and wherein the security policy is implemented on the one or more organizational records that are associated with the one or more organizational divisions that are the same and have an equal status or lower status (col. 13, lines 15-52). Regarding claim 8, Kahn discloses the computer-implemented method of claim 1, further comprising: receiving, by the computing system, one or more inputs via a graphical user interface configured to display one or more interface elements associated with the one or more rules; and generating, by the computing system, the security request based on the one or more inputs (col. 16, lines 36-44). Regarding claim 9, Kahn discloses the computer-implemented method of claim 1, wherein the security request is associated with one or more constraints on authentication, access, or authorization of one or more applications or one or more devices associated with the organizational data ((col. 18, lines 20-35). Regarding claim 10, Kahn discloses the computer-implemented method of claim 1, wherein the one or more rules comprise one or more session time-out rules to limit a duration of an authentication session of one or more applications associated with the one or more organizational records (col. 11, lines 24-54). Regarding claim 11, Kahn discloses the computer-implemented method of claim 1, wherein the organizational data comprises historical data associated with one or more events in which one or more applications associated with the organizational data were accessed, wherein the one or more organizational records respectively comprise one or more user attributes, and wherein the security policy is based on one or more rules associated with the historical data and the one or more user attributes records (fig. 5, col. 14, line 5- col. 15, line 67, table 1). Regarding claim 13, Kahn discloses the computer-implemented method of claim 1, wherein the security request is associated with a request authorization level, and wherein the one or more policies are respectively associated with one or more policy authorization levels (col. 6, lines 4-31 and col. 19, lines 32). Regarding claim 14, Kahn discloses the computer-implemented method of claim 13, wherein the determining, by the computing system, based on the security request, the one or more rules that are in compliance with one or more policies associated with the organizational data comprises: comparing, by the computing system, the request authorization level associated with the one or more rules to the one or more policy authorization levels associated with the one or more policies (col. 6, lines 4-31 and col. 19, lines 32). Regarding claim 16, Kahn discloses the computer-implemented method of claim 1, wherein the one or more organizational records comprise one or more employee records respectively associated with one or more employees of an organization (fig. 1, col. 11, lines 24-54). Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 3, 12, and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Kahn as applied to claim 1 above, and further in view of Barton et al. (US Patent Application Publication No. 2014/0109175 A1) hereinafter Barton. Regarding claim 3, Kahn discloses the computer-implemented method of claim 1, wherein the one or more rules comprise an application associated with the one or more organizational records can be accessed within a predetermined time period (col. 11, lines 24-44), but does not explicitly disclose, however, Barton discloses access rules limit a number of times an application can be accessed within a predetermined time period (para 0130, the policy for the application may include an indication describing a condition as to when the ticket expires (e.g., a time-period such as two-weeks, one day, forever, etc.; a number of accesses to the enterprise resource such as one access, ten accesses, infinite accesses, etc.). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filling date of claimed invention to modify the teachings of Kahn to include limit a number of times an application can be accessed within a predetermined time period as taught by Barton in order to provide access to highly protected resource (Barton para 0123). Regarding claim 12, Kahn discloses the computer-implemented method of claim 1 above, but does not explicitly disclose, however, Barton discloses wherein the organizational data comprises information associated with one or more geographic areas, and wherein the one or more rules are associated with constraining access to one or more applications or one or more devices based on the one or more geographic areas (para 0120, These application-specific policies may further restrict access to the enterprise resource only during certain times, from certain networks, from certain geo-locations, and only from devices that are in compliance with all organizations security policies). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filling date of claimed invention to modify the teachings of Kahn to include the one or more rules are associated with constraining access to one or more applications or one or more devices based on the one or more geographic areas as taught by Barton in order to provide access to highly protected resource (Barton para 0123). Regarding claim 19, Kahn discloses the computer-implemented method of claim 1, wherein the one or more rules are based on an application specific query language that is associated with the security policy (col. 23, lines 4-67) and wherein the one or more rules comprise an application associated with the one or more organizational records can be accessed within a predetermined time period (col. 11, lines 24-44), but does not explicitly disclose, however, Barton discloses access rules limit a number of times an application can be accessed within a predetermined time period (para 0130, the policy for the application may include an indication describing a condition as to when the ticket expires (e.g., a time-period such as two-weeks, one day, forever, etc.; a number of accesses to the enterprise resource such as one access, ten accesses, infinite accesses, etc.). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filling date of claimed invention to modify the teachings of Kahn to include limit a number of times an application can be accessed within a predetermined time period as taught by Barton in order to provide access to highly protected resource (Barton para 0123). Claim 17 is rejected under 35 U.S.C. 103 as being unpatentable over Kahn as applied to claim 1 above, and further in view of Burns et al. (US Patent Application Publication No. 2018/0018154 A1) hereinafter Burns. Regarding claim 17, Kahn discloses the computer-implemented method of claim 1, wherein the one or more rules comprise one or more passcode complexity criteria associated with the one or more organizational records (col. 18, lines 20-35, password), but does not explicitly disclose, however, Burns discloses wherein the one or more passcode complexity criteria comprise a minimum passcode length (Fig. 5B, para 0061). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filling date of claimed invention to modify the teachings of Kahn to include the one or more passcode complexity criteria comprise a minimum passcode length as taught by Burns in order to enforce policies specified by the administrator (Burns para 0060). Allowable Subject Matter Claim 15 would be allowable if rewritten to overcome the rejection under 35 U.S.C. 101, set forth in this Office action and to include all of the limitations of the base claim and any intervening claims. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure (see PTO-892). Any inquiry concerning this communication or earlier communications from the examiner should be directed to BAOTRAN N TO whose telephone number is (571)272-8156. The examiner can normally be reached M-F: 8-5. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Amir Mehrmanesh can be reached at 571-270-3351. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /BAOTRAN N TO/Primary Examiner, Art Unit 2435
Read full office action

Prosecution Timeline

Jan 30, 2025
Application Filed
Aug 06, 2025
Response after Non-Final Action
Jul 30, 2026
Non-Final Rejection mailed — §101, §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12700995
MULTI-USER QUANTUM KEY DISTRIBUTION APPARATUS
2y 9m to grant Granted Aug 04, 2026
Patent 12683693
AN OPTICAL TRANSMITTER, A QUANTUM COMMUNICATION SYSTEM AND A METHOD OF OPERATING AN OPTICAL TRANSMITTER
2y 5m to grant Granted Jul 14, 2026
Patent 12676865
PLATFORM ACCESS REQUEST MANAGEMENT
2y 2m to grant Granted Jul 07, 2026
Patent 12664323
TAMPER DETECTOR BASED ON POWER NETWORK ELECTRICAL CHARACTERISTIC
2y 7m to grant Granted Jun 23, 2026
Patent 12659142
INFORMATION PROCESSING DEVICE, QUANTUM CRYPTOGRAPHIC COMMUNICATION SYSTEM, KEY MANAGEMENT DEVICE, INFORMATION PROCESSING METHOD, AND COMPUTER PROGRAM PRODUCT
1y 11m to grant Granted Jun 16, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
86%
Grant Probability
98%
With Interview (+12.4%)
2y 5m (~10m remaining)
Median Time to Grant
Low
PTA Risk
Based on 667 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month