Prosecution Insights
Last updated: October 02, 2026
Application No. 19/064,545

ZERO TRUST NETWORK ACCESS SOLUTION FOR 5G SASE WITH EXPLICIT PROXY

Non-Final OA §101§102§103§112
Filed
Feb 26, 2025
Priority
Apr 15, 2024 — provisional 63/634,210 +2 more
Examiner
PALIWAL, YOGESH
Art Unit
Tech Center
Assignee
Palo Alto Networks Inc.
OA Round
1 (Non-Final)
84%
Grant Probability
Favorable
1-2
OA Rounds
11m
Est. Remaining
94%
With Interview

Examiner Intelligence

Grants 84% — above average
84%
Career Allowance Rate
599 granted / 713 resolved
+24.0% vs TC avg
Moderate +10% lift
Without
With
+10.4%
Interview Lift
resolved cases with interview
Typical timeline
2y 7m
Avg Prosecution
15 currently pending
Career history
727
Total Applications
across all art units

Statute-Specific Performance

§101
10.9%
-29.1% vs TC avg
§103
45.3%
+5.3% vs TC avg
§102
15.8%
-24.2% vs TC avg
§112
16.7%
-23.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 713 resolved cases

Office Action

§101 §102 §103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Objections Claims 3, 4 11-13 are objected to because of the following informalities: Claims 2, 4, 11-13 all recites acronym “SPN”, without having first established its respective ordinary meanings. Appropriate correction is required. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(d): (d) REFERENCE IN DEPENDENT FORMS.—Subject to subsection (e), a claim in dependent form shall contain a reference to a claim previously set forth and then specify a further limitation of the subject matter claimed. A claim in dependent form shall be construed to incorporate by reference all the limitations of the claim to which it refers. The following is a quotation of pre-AIA 35 U.S.C. 112, fourth paragraph: Subject to the following paragraph [i.e., the fifth paragraph of pre-AIA 35 U.S.C. 112], a claim in dependent form shall contain a reference to a claim previously set forth and then specify a further limitation of the subject matter claimed. A claim in dependent form shall be construed to incorporate by reference all the limitations of the claim to which it refers. Claims 3, 4, 7, 8 and 11-14 are rejected under 35 U.S.C. 112(d) or pre-AIA 35 U.S.C. 112, 4th paragraph, as being of improper dependent form for failing to further limit the subject matter of the claim upon which it depends, or for failing to include all the limitations of the claim upon which it depends. Claims 3, 4, 7, 8 and 11-14 all fails to further limit the subject matter of claim 1. Claims 3, 4, 7, 8 and 11-14 do not refer to any element of claim 1. Applicant may cancel the claim(s), amend the claim(s) to place the claim(s) in proper dependent form, rewrite the claim(s) in independent form, or present a sufficient showing that the dependent claim(s) complies with the statutory requirements. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claim(s) 20 is rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter. Claim(s) 20 is directed towards “computer program product being embodied in a tangible computer readable storage medium ” that computer instructions. Specification does not define the term. Thus, it is unclear whether the term is meant to encompass signals or not. The broadest, reasonable interpretation of the term is applied and currently the examiner is assuming that it encompasses signals. Signals do not fall within any of the four statutory categories of invention, thus claim 20 is not statutory. Examiner suggests amending claims to recite, “non-transitory computer-readable recording medium" to exclude non-statutory mediums such as signals. Claim Rejections - 35 USC § 102 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention. Claim(s) 1, 2, 5, 7-10, 14 and 16-20 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Yadav et al. (US 2023/0100395 A1), hereinafter, “Yadav”. Regarding Claims 1, 19 and 20, Yadav discloses a system and corresponding method and a computer program product, wherein the system comprises: a processor (See, Paragraphs 0127) configured to: process a Radius start message (See, Paragraph 0063) and populate 5G synchronized (sync) data with a 5G user identity and IP mapping using a 5G Secure Access Service Edge (SASE) service (See, Paragraphs 0045 and 0063), wherein a service provider (SP) configures IMSI, IMEI, and APN information to identify UEs from each SP 5G network (See, Paragraphs 0062 and 0064), and configures a security policy per user group and/or individual users for a 5G SASE service (See, Paragraph 0067); extract contextual information associated with monitored 5G SP data plane traffic to determine a security policy to apply to the 5G SP data plane traffic (See, Paragraphs 0049 and 0068); enforce the security policy on the 5G SP data plane traffic associated with a UE based on contextual information associated with the UE to provide secured 5G SP data plane traffic (See, Paragraph 0068); and egress the secured 5G SP data plane traffic back to an SP backbone or to an external network (See, Paragraph 0066); and a memory coupled to the processor and configured to provide the processor with instructions (See, Paragraph 0127). Regarding Claim 2, the rejection of claim 1 is incorporated and Yadav further discloses wherein the contextual information is extracted using a Packet Forwarding Control Protocol (PFCP), a Radius protocol, a Diameter protocol, a Syslog message, an Application Programming Interface (API), and/or a Geneve protocol (See, Paragraphs 0049, 0063 and 0101). Regarding Claim 5, the rejection of claim 1 is incorporated and Yadav further discloses wherein the external network includes a tenant Data Center (DC) and/or an Internet (See, Paragraph 0064). Regarding Claim 7, the rejection of claim 1 is incorporated and Yadav further discloses wherein the 5G SP data plane traffic is secured from and to 4G, 5G, and/or 6G UE devices (See, Paragraphs 0045). Regarding Claim 8, the rejection of claim 1 is incorporated and Yadav further discloses wherein Internet access is secured from and to 4G, 5G, and/or 6G UE devices (See, Paragraph 0045). Regarding Claim 9, the rejection of claim 1 is incorporated and Yadav further discloses wherein enterprise data center access is secured from and to 4G, 5G, and/or 6G UE devices (See, Paragraph 0045). Regarding Claim 10, the rejection of claim 1 is incorporated and Yadav further discloses wherein selection and the enforcement of the security policy is based on the contextual information associated with a UE (See, Paragraph 0067) and the 5G SP data plane traffic correlated with the UE based on a UE Internet Protocol (IP) address (See, Paragraphs 0063 and 0064). Regarding Claim 14, the rejection of claim 1 is incorporated and Yadav further discloses wherein each of a plurality of security policies is distinctly selected and enforced for each mobile service provider (MSP) enterprise tenant at a SASE cloud network (See, Paragraphs 0044 and 0067), wherein per tenant security policy configuration and enforcement are provided by the SASE cloud network (See, Paragraphs 0067 and 0068). Regarding Claim 16, the rejection of claim 1 is incorporated and Yadav further discloses wherein the processor is further configured to: determine the security policy to apply at a SASE cloud network to the 5G SP data plane traffic based on a subscriber identity and/or a unique device identifier (See, Paragraphs 0044 and 0067). Regarding Claim 17, the rejection of claim 1 is incorporated and Yadav further discloses wherein the processor is further configured to: receive a message over a network protocol from a mobile core network at a SASE cloud network (See, Paragraphs 0044 and 0063), wherein contextual information associated with the message is communicated using a Packet Forwarding Control Protocol (PFCP), a Radius protocol, a Diameter protocol, Syslogmessages, an Application Programming Interface (API), and/or a Geneve protocol (See, Paragraphs 0049, 0063 and 0101). Regarding Claim 18, the rejection of claim 1 is incorporated and Yadav further discloses wherein the processor is further configured to: receive an accounting message from a mobile core network at a SASE cloud network (See, Paragraph 0052 and 0101), wherein contextual information associated with the accounting message is communicated using a DIAMETER protocol, a Radius protocol, and/or via an Application Programming Interface (API) (See, Paragraphs 0049, 0063 and 0101). Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 3-4 and 12-13 are rejected under 35 U.S.C. 103 as being unpatentable over Yadav in view of Starr et al. (US 2022/0261276 A1), hereinafter, “Starr”. Regarding Claim 3, the rejection of claim is incorporated and Yadav further discloses wherein an SPN While Yadav discloses SASE including Firewall-as-a-Service, Yadav fails to discloses wherein an SPN includes a firewall as a service that is configured with a plurality of security policies. Starr discloses a system wherein an SPN includes a firewall as a service that is configured with a plurality of security policies (See, Paragraphs 0038-0039 and 0078). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to include, in the system of Yadav, a firewall as a service that is configured with a plurality of security policies as taught by Starr so that firewall could be configured with tenant specific polices that could be updated any time when the requirements of the tenant changes. Regarding Claim 4, the rejection of claim 1 is incorporated and Yadav further discloses wherein an SPN Subscriber Director Number (MSISDN), and/or another external identifier (See, Paragraph 0062). While Yadav discloses SASE including Firewall-as-a-Service, Yadav fails to discloses wherein an SPN includes a firewall as a service that is configured with a plurality of security policies. Starr discloses a system wherein an SPN includes a firewall as a service that is configured with a plurality of security policies (See, Paragraphs 0038-0039 and 0078). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to include, in the system of Yadav, a firewall as a service that is configured with a plurality of security policies as taught by Starr so that firewall could be configured with tenant specific polices that could be updated any time when the requirements of the tenant changes. Regarding Claim 12, the rejection of claim 1 is incorporated and Yadav further discloses wherein an SPN includes a firewall as a service (FWaaS) associated with a SASE cloud network While Yadav discloses SASE including Firewall-as-a-Service, Yadav fails to discloses a firewall as a service that is configured to perform application Denial of Service (DoS) detection for the 5G SP data plane traffic. Starr discloses a system wherein an SPN includes a firewall as a service that is configured to perform application Denial of Service (DoS) detection for a SP data plane traffic (See, Paragraph 0044). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to include, for the 5G SP data place traffic in the system of Yadav, a firewall as a service that is configured to perform application Denial of Service (DoS) detection as taught by Starr in order to detect and mitigate DOS attacks on enterprise network. Regarding Claim 13, the rejection of claim 1 is incorporated and Yadav further discloses wherein an SPN includes a firewall as a service (FWaaS) associated with a SASE cloud network While Yadav discloses SPN SASE including Firewall-as-a-Service, Yadav fails to discloses firewall as a service that is configured to perform threat prevention, advanced threat prevention, and/or advanced Uniform Resource Link (URL) filtering for the 5G SP data plane traffic. Starr discloses firewall as a service that is configured to perform threat prevention, advanced threat prevention, and/or advanced Uniform Resource Link (URL) filtering for a SP data plane traffic (See, Paragraph 0044). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to include, for the 5G SP data place traffic in the system of Yadav, firewall as a service that is configured to perform threat prevention, advanced threat prevention, and/or advanced Uniform Resource Link (URL) filtering as taught by Starr in order to prevent unwanted traffic into the enterprise networks which protects the enterprise networks. Claim 6 is rejected under 35 U.S.C. 103 as being unpatentable over Yadav in view of Deshmukh et al. (US 2021/0336934 A1), hereinafter, “Deshmukh”. Regarding Claim 6, the rejection of claim 1 is incorporated and Yadav does not explicitly disclose wherein the external network includes a Software as a Service (SaaS) application (app) or a private app. Deshmukh discloses wherein an external network includes a Software as a Service (SaaS) application (app) or a private app (See, Paragraph 0069). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have, in the system of Yadav, external network includes a Software as a Service (SaaS) application (app) or a private app as taught by Deshmukh in order to communicate securely between enterprise nodes and SaaS cloud for data and filed transfer across multiple systems. Claim 11 is rejected under 35 U.S.C. 103 as being unpatentable over Yadav in view of Ganguli et al. (US 2024/0283826 A1), hereinafter, “Ganguli”. Regarding Claim 11, the rejection of claim 1 is incorporated and Yadav further discloses wherein an SPN includes a firewall as a service (FWaaS) associated with a SASE cloud network that is configured to perform Yadav does not explicitly disclose performing URL filtering. Ganguly discloses performing URL filtering (See, Paragraphs 0009, 0065 and 0066). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to perform, for the 5G SP data plane traffic of Yadav, URL filtering as taught by Ganguli in order to provide cloud-based intrusion prevention, protection against advanced threats (malware, spam, Cross-Site Scripting (XSS), phishing, etc.), cloud-based sandbox, antivirus, DNS security (See, Ganguli, Paragraph 0065). Claim 15 is rejected under 35 U.S.C. 103 as being unpatentable over Yadav in view of Padmanabhan et al. (US 2020/0213187 A1), hereinafter, “Padmanabhan”. Regarding Claim 15, the rejection of claim 1 is incorporated and Yadav further does not explicitly disclose wherein the 5G SP data plane traffic is encapsulated with meta information, including a subscriber identity and/or a unique device identifier. Padmanabhan discloses wherein 5G SP data plane traffic is encapsulated with meta information, including a subscriber identity and/or a unique device identifier (See, Paragraphs 0016 and 0039). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to encapsulate, 5G SP data plane traffic in the system of Yadav, with meta information, including a subscriber identity and/or a unique device identifier as taught by Padmanabhan in order to associate traffic with a specific subscriber to uniquely handle individual subscribers. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to YOGESH PALIWAL whose telephone number is (571)270-1807. The examiner can normally be reached M-F 9:00AM-5:00PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Amir Mehrmanesh can be reached at (571)270-3351. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /YOGESH PALIWAL/ Primary Examiner, Art Unit 2435
Read full office action

Prosecution Timeline

Feb 26, 2025
Application Filed
Aug 18, 2026
Non-Final Rejection mailed — §101, §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12744790
Secure Communications Service for Intercepting Suspicious Messages and Performing Backchannel Verification Thereon
1y 7m to grant Granted Sep 22, 2026
Patent 12737605
SUPERCONDUCTING NEUROMORPHIC COMPUTING DEVICES AND CIRCUITS
3y 0m to grant Granted Sep 15, 2026
Patent 12739104
DATA PROCESSING METHOD AND APPARATUS, ELECTRONIC DEVICE, AND STORAGE MEDIUM
2y 2m to grant Granted Sep 15, 2026
Patent 12726368
Validating Certificate Bundles With Asymmetric Keys
2y 11m to grant Granted Sep 01, 2026
Patent 12712880
SYSTEM AND METHOD FOR PROVIDING A WEB SERVICE USING A MOBILE DEVICE CAPTURING DUAL IMAGES
3y 0m to grant Granted Aug 18, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
84%
Grant Probability
94%
With Interview (+10.4%)
2y 7m (~11m remaining)
Median Time to Grant
Low
PTA Risk
Based on 713 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month