Prosecution Insights
Last updated: September 17, 2026
Application No. 19/073,041

MANAGEMENT OF ACCESS TO EXTERNAL AUTHORIZED SERVICES

Non-Final OA §112§DOUBLEPATENT
Filed
Mar 07, 2025
Priority
Sep 05, 2024 — CIP of 12/255,898
Examiner
LEE, MICHAEL M
Art Unit
2436
Tech Center
2400 — Computer Networks
Assignee
Grip Security Ltd.
OA Round
1 (Non-Final)
84%
Grant Probability
Favorable
1-2
OA Rounds
1y 2m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 84% — above average
84%
Career Allowance Rate
233 granted / 277 resolved
+26.1% vs TC avg
Strong +38% interview lift
Without
With
+38.1%
Interview Lift
resolved cases with interview
Typical timeline
2y 8m
Avg Prosecution
23 currently pending
Career history
298
Total Applications
across all art units

Statute-Specific Performance

§101
9.1%
-30.9% vs TC avg
§103
52.8%
+12.8% vs TC avg
§102
8.1%
-31.9% vs TC avg
§112
20.2%
-19.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 277 resolved cases

Office Action

§112 §DOUBLEPATENT
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This is a non-final office action in response to applicant’s communication filed on 3/7/2025. Claims 1-21 are pending and being considered. Information Disclosure Statement The information disclosure statement (IDS) submitted on 4/28/2025, has been considered. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, initialed and dated copy of Applicant’s IDS form 1449 filed as stated above is attached to the instant Office Action. Priority This application is a CIP of 18/824,988 field 9/5/2024, now US Patent No. 12,255,898 B1. Drawings The drawings are objected to because: Fig. 3 is illegible in print. Corrected drawing sheets in compliance with 37 CFR 1.121(d) are required in reply to the Office action to avoid abandonment of the application. Any amended replacement drawing sheet should include all of the figures appearing on the immediate prior version of the sheet, even if only one figure is being amended. The figure or figure number of an amended drawing should not be labeled as “amended.” If a drawing figure is to be canceled, the appropriate figure must be removed from the replacement sheet, and where necessary, the remaining figures must be renumbered and appropriate changes made to the brief description of the several views of the drawings for consistency. Additional replacement sheets may be necessary to show the renumbering of the remaining figures. Each drawing sheet submitted after the filing date of an application must be labeled in the top margin as either “Replacement Sheet” or “New Sheet” pursuant to 37 CFR 1.121(d). If the changes are not accepted by the examiner, the applicant will be notified and informed of any required corrective action in the next Office action. The objection to the drawings will not be held in abeyance. Claim Objections Claims 1, 4-5, 7, 9, 13, 16 are objected to because of the following informalities: Claim 1 line 9, “… and the plurality of service computing environment” may read “… and the plurality of service computing environments”. Similarly, claim 13 line 8. Claim 1 lines 10-11, “… between first user identities that …” may read “… of first user identities that …”, or more appropriate form. Examiner notes, the use of “between” indicates two objects to follow, i.e., between A and B. Similarly, claim 13 line 10. Claim 4 lines 1-2, “wherein the plurality of publicly accessible data sources are …” may read “wherein the publicly accessible data sources set is …”. Claim 5 line 3, “… for a plurality of service computing environments” may read “… for the plurality of service computing environments”. Claim 7 line 4, “and (ii)” may read “and (iii)”. Claim 9 lines 2-3, “and implementing the automatically blocking …” may read “and implementing the automatically blockings …”, or more appropriate form. Claim 16 line 3, “reach” may be typo. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 2, 13-21 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claim 2 line 2 recites, “the user identity”, lines 3-4 recites, “the service computing environment”. There is insufficient antecedent basis for these limitations in the claim. Similarly, claim 14 line 2, lines 3-4. Claim 13 lines 14-18 recites, “in response to the risk of the security breach of at least one user identity of at least one connection meeting a requirement, automatically instructing access for second user identities meeting the requirement to the authorized service computing environments that they are non-authorized to access, and automatically instructing access of the third user identities meeting the requirement to the non-authorized service computing environments.” It is not clear what the requirement is and what the scope of “connection meeting a requirement” is. Since “instructing access” can be interpreted as allowing access or blocking access, therefore, without definition of “requirement”, it is not clear the “instructing access” should be interpretated as allowing access or blocking access. Claims 14-21 depend on claim 13, therefore are also rejected for the same reason set forth above. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP §§ 706.02(l)(1) - 706.02(l)(3) for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/process/file/efs/guidance/eTD-info-I.jsp. Claims 1, 13 are rejected on the ground of nonstatutory double patenting as being unpatentable over the corresponding claims of US Patent No. 12,255,898 B1 (hereinafter “’898”), in view of Jay et al (US20170206351A1, hereinafter, “Jay”). Claim 1 of ‘898 discloses all of the limitations recited in claim 1 of the instant application, as seen in the table below, except those limitations as emphasized in bold, however Jay in the same field of endeavor teaches: for each respective connection of the plurality of connections, comparing a current security state to a preceding security state; and in response to detecting a change from the preceding security state to the current security state in at least one connection (Jay, discloses method of mobile computing device security client that monitors and detects inconsistencies in device security, see [Abstract]. And [0073] The security client may output the security inconsistency notification 410 in response to detecting a security inconsistency (e.g., state change of a peripheral device, installation of an application, communication messaging state, etc.) associated with the operating conditions of the mobile device 115-c. The security inconsistency notification 410 may provide a visual notification to a user of the mobile device 115-c that a security inconsistency was detected). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have employed the teachings of Jay in the management of access to external authorized services of ‘898 by monitoring and detecting inconsistencies in device security. This would have been obvious because the person having ordinary skill in the art would have been motivated to select an action to take in response to the potential security breach (Jay, [Abstract]). Claim 1 of ‘898 discloses all of the limitations recited in claim 13 of the instant application, as seen in the table below, except those limitations as emphasized in bold, however Jay in the same field of endeavor teaches: assigning for each connection a corresponding indication of risk of a security breach to a respective service computing environment for a respective user identity, in response to the risk of the security breach of at least one user identity of at least one connection meeting a requirement (Jay, discloses method of mobile computing device security client that monitors and detects inconsistencies in device security, see [Abstract]. And The response actions may include notification of the user or a network administrator of the potential security breach. A user notification may provide the user with an opportunity to select an action to take in response to the potential security breach. Additionally or alternatively, the response actions may include an actuation associated with the detected inconsistency. Such actuations include uninstalling an application, setting the operating condition to the secured state, blocking a data transfer, erasing data stored by the mobile device 115, locking the mobile device 115, rebooting the mobile device 115, blocking access to data containers, ... And [0064] The security client 205-a may issue a notification at block 340 indicating a security inconsistency has been detected. For example, the security client 205-a may (e.g., via the mobile OS, etc.) output a visual, audible, and/or physical notification of the security inconsistency event detected at 335. The notification may inform the user of a potential security breach). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have employed the teachings of Jay in the management of access to external authorized services of ‘898 by taking action in response to potential security breach. This would have been obvious because the person having ordinary skill in the art would have been motivated to select an action to take in response to the potential security breach (Jay, [Abstract]). Claim Comparison Instant Application 19/073,041 US Patent No. 12255898B1 Claim 1. A computer implemented method of automatically securing access to a plurality of authorized service computing environments from a target computing environment, comprising: monitoring a plurality of data sources associated with security of a plurality of user identities of the target computing environment accessing a plurality of service computing environments; analyzing the plurality of data sources to compute security states between user identities of the target computing environment and the plurality of service computing environments; according to the analyzing, mapping connections between the user identities of the target computing environment and the plurality of service computing environment, and assigning a corresponding security state to each connection of a plurality of connections between first user identities that are authorized to access authorized service computing environments, second user identities that are non-authorized to access the authorized service computing environments, and third user identities that are non-authorized to access non-authorized service computing environments; for each respective connection of the plurality of connections, comparing a current security state to a preceding security state; and in response to detecting a change from the preceding security state to the current security state in at least one connection, automatically blocking access of the second user identities to the authorized service computing environments that they are non-authorized to access, and automatically blocking access of the third user identities to access non-authorized service computing environments. Claim 1. A computer implemented method of automatically managing access to a plurality of authorized service computing environments from a target computing environment, comprising: monitoring a plurality of data sources generated by a plurality of user identities of the target computing environment accessing a plurality of service computing environments; analyzing the plurality of data sources to identify communication between user identities of the target computing environment and the plurality of service computing environments; according to the analyzing, mapping connections between the user identities of the target computing environment and the plurality of service computing environment, including connections between first user identities that are authorized to access authorized service computing environments, second user identities that are non-authorized to access the authorized service computing environments, and third user identities that are non-authorized to access non-authorized service computing environments; and automatically blocking access of the second user identities to the authorized service computing environments that they are non-authorized to access, and automatically blocking access of the third user identities to access non-authorized service computing environments. Claim 13. A computer implemented method of automatically securing access to a plurality of authorized service computing environments from a target computing environment, comprising: monitoring a plurality of data sources associated with a plurality of user identities of the target computing environment accessing a plurality of service computing environments; analyzing the plurality of data sources to identify communication between user identities of the target computing environment and the plurality of service computing environments; according to the analyzing, mapping connections between the user identities of the target computing environment and the plurality of service computing environment, and assigning for each connection a corresponding indication of risk of a security breach to a respective service computing environment for a respective user identity, including, between first user identities that are authorized to access authorized service computing environments, second user identities that are non-authorized to access the authorized service computing environments, and third user identities that are non-authorized to access non-authorized service computing environments; and in response to the risk of the security breach of at least one user identity of at least one connection meeting a requirement, automatically instructing access for second user identities meeting the requirement to the authorized service computing environments that they are non-authorized to access, and automatically instructing access of the third user identities meeting the requirement to the non-authorized service computing environments. Claim 1. A computer implemented method of automatically managing access to a plurality of authorized service computing environments from a target computing environment, comprising: monitoring a plurality of data sources generated by a plurality of user identities of the target computing environment accessing a plurality of service computing environments; analyzing the plurality of data sources to identify communication between user identities of the target computing environment and the plurality of service computing environments; according to the analyzing, mapping connections between the user identities of the target computing environment and the plurality of service computing environment, including connections between first user identities that are authorized to access authorized service computing environments, second user identities that are non-authorized to access the authorized service computing environments, and third user identities that are non-authorized to access non-authorized service computing environments; and automatically blocking access of the second user identities to the authorized service computing environments that they are non-authorized to access, and automatically blocking access of the third user identities to access non-authorized service computing environments. Allowable Subject Matter Claims 1-21 are objected to as being allowable subject matter over prior arts but would be allowable if rewritten in form resolving of any informalities, concerns under 35 USC 112(b) and the double patenting rejection presented in this office action. As allowable subject matter has been indicated, applicant's reply must either comply with all formal requirements or specifically traverse each requirement not complied with. See 37 CFR 1.111(b) and MPEP § 707.07(a). The following is a statement of reasons for the indication of allowable subject matter: Claim 1 recites unique features “analyzing data sources to compute security states between user identities of target computing environment and service computing environments; mapping connections between the user identities of the target computing environment and service computing environment, and assigning a corresponding security state to each connection of connections between first user identities that are authorized to access authorized service computing environments, second user identities that are non-authorized to access the authorized service computing environments, and third user identities that are non-authorized to access non-authorized service computing environments; for each respective connection of the connections, comparing a current security state to a preceding security state; and in response to detecting a change from the preceding security state to the current security state in at least one connection, automatically blocking access of the second user identities to the authorized service computing environments that they are non-authorized to access, and automatically blocking access of the third user identities to access non-authorized service computing environments”, in combination with all other limitations in the claims as defined by applicant. Claim 13 recites unique features “analyzing data sources to identify communication between user identities of target computing environment and service computing environments; mapping connections between the user identities of the target computing environment and the service computing environment, and assigning for each connection a corresponding indication of risk of a security breach to a respective service computing environment for a respective user identity, including, between first user identities that are authorized to access authorized service computing environments, second user identities that are non-authorized to access the authorized service computing environments, and third user identities that are non-authorized to access non-authorized service computing environments; and in response to the risk of the security breach of at least one user identity of at least one connection meeting a requirement, automatically instructing access for second user identities meeting the requirement to the authorized service computing environments that they are non-authorized to access, and automatically instructing access of the third user identities meeting the requirement to the non-authorized service computing environments”, in combination with all other limitations in the claims as defined by applicant. The prior art, Waldspurger et al (US20220263851A1) discloses systems and methods for determining data risk and managing permissions of granting to identity to perform action on resource. Resource access data is collected for a resource. Based at least on the resource access data, a data risk index (DRI) score is generated for the resource. The DRI score comprises a value that is indicative of a level of risk that the resource will be compromised. At least one of the DRI score, an alert based at least on the DRI score, or a policy change for the resource based at least on the generated DRI score is reported to an administrator. The prior art, Vaknin et al (US12592928B1) discloses method of managing access for user account by: accessing a graph mapping a plurality of nodes denoting real users to user accounts and resources hosted by service computing environments external to a target computing environment accessed by the user accounts, and defining different permissions for user accounts for accessing the different resources, receiving a query for identifying user accounts for a target user, executing the query on the graph, and providing details regarding user accounts of the target users from the execution of the query on the graph, the details including identifiers of the user accounts, resources accessible to the user accounts, or access privileges for accessing the resources. The prior art, Sanda et al (US20060075472A1) discloses system and method for enhanced network client security by receiving a security-related policy associated with a user, determining a security model associated with the security-related policy, and applying the security model to a network connection on a client device, receiving a first measure associated with a usage characteristic, the usage characteristic associated with a user, receiving a second measure associated with the usage characteristic, comparing the first measure and second measure, and determining the likelihood that an unauthorized access has occurred based at least in part on the comparison. The prior art, Jay et al (US20170206351A1) discloses method for mobile computing device security client that monitors and detects inconsistencies in device security. The security client may provide a notification and/or perform an actuation in response to detection of a change in operating conditions of a mobile computing device that is inconsistent with security policies for the mobile computing device. A user notification may provide the user with an opportunity to select an action to take in response to the potential security breach. Actuations include response actions to mitigate the compromise in security based on the operating conditions. The security policies may include security policies associated with hardware peripheral use, an application whitelist, an application blacklist, and/or firewall security settings. The prior art, Kirti et al (US20200153855A1) discloses methods for discovery and management of applications in a computing environment of an organization. A security management system discovers use of applications within a computing environment to manage access to applications for minimizing security threats and risks in a computing environment of the organization, obtain network data about network traffic to identify unique applications, performs analysis and correlation, including using one or more data sources, to determine information about an application, computes a measure of security for an application (“an application risk score”) and a user (“a user risk score”), the score is analyzed to determine a threat of security posed by the application based on use of the application, and performs one or more instructions to configure access permitted by an application, whether access is denied or restricted. The prior art, Nevatia et al (US20200412726A1) discloses device and method of security monitoring platform for managing access rights associated with cloud application. A security monitoring platform may use an unsupervised machine learning technique to cluster historical data related to user access rights associated with multiple cloud applications based on various features that relate to user permissions and attributes within the multiple cloud applications, train an access rights data model based on the clustered historical data and perform one or more actions that relate to current access rights assigned to at least one user within one or more of the multiple cloud applications based on a score representing a probability that an access level assigned to the at least one user within the one or more of the multiple cloud applications is correct. The security monitoring platform may apply a reinforcement learning technique to update the access rights data model based on feedback related to the one or more actions. The prior art, Ryland (US20150163158A1) discloses methods for providing identity and access management-based access control for connections between entities in virtual (overlay) network environments. At the encapsulation layer of the overlay network, an out-of-band connection creation process may be leveraged to enforce access control and thus allow or deny overlay network connections between sources and targets according to policies. For example, resources may be given identities, identified resources may assume roles, and policies may be defined for the roles that include permissions regarding establishing connections to other resources. When a given resource (the source) attempts to establish a connection to another resource (the target), role(s) may be determined, policies for the role(s) may be identified, and permission(s) checked to determine if a connection from the source to the target over the overlay network is to be allowed or denied. Citation of References The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. The following references are cited but not been replied upon for this office action: Barth (US20230164165A1) discloses techniques of identity-based risk evaluation using risk scores for different identities. Mierczuk et al (US20240176893A1) discloses systems and methods for analyzing a web browser extension. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to MICHAEL M LEE whose telephone number is (571)272-1975. The examiner can normally be reached on M-F: 8:30AM - 5:30PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Shewaye Gelagay can be reached on (571) 272-4219. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /MICHAEL M LEE/Primary Examiner, Art Unit 2436
Read full office action

Prosecution Timeline

Mar 07, 2025
Application Filed
Sep 02, 2026
Non-Final Rejection mailed — §112, §DOUBLEPATENT (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12737494
Systems and Methods for Detecting man-in-the-middle cybersecurity threats
2y 5m to grant Granted Sep 15, 2026
Patent 12732532
Method for defending against an attempt to disconnect two entities, and associated system
2y 10m to grant Granted Sep 08, 2026
Patent 12706924
TECHNIQUES FOR DETECTING PERSISTENT DIGITAL ASSETS ON AN EXTERNAL ATTACK SURFACE
2y 9m to grant Granted Aug 11, 2026
Patent 12689611
Prioritization For Time-Deterministic Firewalls
1y 12m to grant Granted Jul 21, 2026
Patent 12676884
Spoofed UDP Packet Detection
2y 2m to grant Granted Jul 07, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
84%
Grant Probability
99%
With Interview (+38.1%)
2y 8m (~1y 2m remaining)
Median Time to Grant
Low
PTA Risk
Based on 277 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month