Prosecution Insights
Last updated: August 18, 2026
Application No. 19/079,166

OPEN RADIO ACCESS NETWORK (O-RAN) STANDARDIZED LOG MANAGEMENT SERVICES

Non-Final OA §103
Filed
Mar 13, 2025
Priority
Nov 18, 2024 — provisional 63/721,784
Examiner
WON, MICHAEL YOUNG
Art Unit
2443
Tech Center
2400 — Computer Networks
Assignee
Dish Wireless LLC
OA Round
1 (Non-Final)
80%
Grant Probability
Favorable
1-2
OA Rounds
1y 6m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 80% — above average
80%
Career Allowance Rate
676 granted / 847 resolved
+21.8% vs TC avg
Strong +28% interview lift
Without
With
+28.4%
Interview Lift
resolved cases with interview
Typical timeline
2y 11m
Avg Prosecution
31 currently pending
Career history
874
Total Applications
across all art units

Statute-Specific Performance

§101
8.6%
-31.4% vs TC avg
§103
47.7%
+7.7% vs TC avg
§102
31.1%
-8.9% vs TC avg
§112
8.7%
-31.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 847 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION 2. This action is in response to the application filed March 13, 2025. 3. Claims 1-20 have been examined and are pending with this action. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 4. Claims 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Giokas (US 2015/0128274 A1) in view of Singh et al. (US 2022/0287038 A1). INDEPENDENT: As per claim 1, Giokas teaches a method of implementing a network standardized log management services in a cellular network, the method comprising: aggregating, by a processing device, log data associated with a plurality of network elements in the cellular network, wherein the processing device communicates with the plurality of network elements via one or more standardized interfaces (see Giokas, [0091]: “The network security monitor may include an aggregator 220 that obtains threat intelligence information from one or more repositories and a normalizer 235 that normalizes the aggregated threat intelligence.”; [0098]: “The log collector 210 may store all previous logs, aggregate logs based on type, or delete the logs after a time period (e.g., 24 hours, 48 hours, a week, month, year, etc.).”; [0103]: “The aggregator 220 can access one or more threat repositories via the external network 104, such as the security intelligence repositories 202a-n, using protocols such as HTTP, FTP, P2P, etc. To access or establish a connection with a repository 202a-n, the aggregator 220 may obtain configuration details from the database 240 including, e.g., URL of a repository 202a-n, information transfer protocol, and/or authentication credentials specified by repository vendors. Using the connection, the aggregator 220 may periodically ping, receive, or otherwise obtain current or up-to-date information from the security intelligence database or resource 202a-n.”; and [0154]: “The system can also normalize these logs in a unified format as to be easier to correlate them. The system can correlate current and past logs and log sets in real-time continuously, as to identify threats of a type that are now penetrating the protected network or had passed unnoticed in the past.”); storing the log data (see Giokas, [0086]: “In addition to storing the logs, which are generated and delivered to the network security monitor via the protected network, the database can include threat indicator lists.”; and [0154]: “The system can collect, store and index logs from various systems of the protected network such as log repositories, SIEMs, network security elements etc. The system can also normalize these logs in a unified format as to be easier to correlate them.”); analyzing the log data (see Giokas, [0082]: “The APT intelligence platform (or network security monitor) can analyze system logs which may be generated by the protected network. The system logs may be provided to the APT intelligence platform via a secure network connection.”; [0084]: “The network security monitor may include a log correlation engine that takes the logs provided by the protected network and indexed by the log indexer, and compares those logs to the lists of threat indicators stored on the database.”; and [0086]: “Thus, the log correlation engine can identify potential APTs based upon their behavior and the patterns they create within the system; patterns, which may be otherwise undetectable, but can be revealed by the analysis performed by the correlation engine.”); and outputting a notification based on a result of the analyzing (see Giokas, [0008]: “An intrusion detection system detects malicious attacks and then raises an alarm such that an authorized system administrator is notified of the attack and can take the appropriate actions to stymie it.”; and [0115]: “Thus, the network security monitor 120 can identify a match (e.g., when the conditions of the correlation rule are satisfied by an indexed log and a threat indication) and notify an administrator or user of the protected network 204 that there is network activity or a communication between the protected network 204 (e.g., an internal IP address of the protected system) and an IP address that is known to be malicious based on security intelligence.”). Giokas does not explicitly teach that the network is an open radio access network (O-RAN) and the network elements are radio access elements. Singh teaches an open radio access network (O-RAN) and radio access elements (see Singh, [0045]: “Today, there is a push to have the Radio Access Network (RAN) of a telecommunication network (e.g., a cellular network) implemented as O-RAN, a standard for allowing interoperability for RAN elements and interfaces. FIG. 1 illustrates an example of O-RAN architecture 100, according to some embodiments.”; and [0078]: “the set of RAN elements that the RIC SDK connects with the control plane application 615 on its machine 610 include network elements of the RIC. Again, these network elements in some embodiments include RAN elements that are produced and/or developed by different RAN vendors and/or developers.”). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the invention to modify the system of Giokas in view of Singh so that the network is an open radio access network (O-RAN) and the network elements are radio access elements. One would be motivated to do so because Giokas teaches in paragraph [0048], “The network 104 may be connected via wired or wireless links. Wired links may include Digital Subscriber Line (DSL), coaxial cable lines, or optical fiber lines. The wireless links may include BLUETOOTH, Wi-Fi, Worldwide Interoperability for Microwave Access (WiMAX), an infrared channel or satellite band. The wireless links may also include any cellular network standards used to communicate among mobile devices, including standards that qualify as 1G, 2G, 3G, or 4G.”, emphasis added. As per claim 8, Giokas and Singh teach a computing system to facilitate a cellular network, the computing system comprising: one or more processing devices (see Giokas, [0092]: “The network security monitor 120, interface 205, log collector 210, log indexer 215, aggregator 220, log correlation engine 225, report engine 230, normalizer 235 and database 240 may each include one or more processing units or other logic devices such as programmable logic array engines, modules, or circuitry designed and constructed to facilitate managing security on a network infrastructure.”); and memory communicatively coupled with and readable by the one or more processing devices and having stored therein processor-readable instructions which, when executed by the one or more processing devices, cause the one or more processing devices to perform operations (see Giokas, [0060]: “As shown in FIGS. 1C and 1D, each computing device 100 includes a central processing unit 121, and a main memory unit 122.”) comprising: aggregating log data associated with a plurality of radio access network elements in the cellular network, wherein the one or more processing devices communicate with the plurality of radio access network elements via one or more standardized interfaces (see Claim 1 rejection above); storing the log data (see Claim 1 rejection above); analyzing the log data (see Claim 1 rejection above); and outputting a notification based on a result of the analyzing (see Claim 1 rejection above). As per claim 15, Giokas and Singh teach one or more non-transitory, computer-readable storage media having computer-readable instructions thereon which, when executed by one or more processing devices, cause the one or more processing devices to perform operations (see Giokas, [0060]: “As shown in FIGS. 1C and 1D, each computing device 100 includes a central processing unit 121, and a main memory unit 122.”; and [0061]: “The central processing unit 121 is any logic circuitry that responds to and processes instructions fetched from the main memory unit 122.”) comprising: aggregating log data associated with a plurality of radio access network elements in a cellular network, wherein the one or more processing devices communicate with the plurality of radio access network elements via one or more standardized interfaces (see Claim 1 rejection above); storing the log data (see Claim 1 rejection above); analyzing the log data (see Claim 1 rejection above); and outputting a notification based on a result of the analyzing (see Claim 1 rejection above). DEPENDENT: As per claims 2, 9, and 16, which respectively depend on claims 1, 8, and 15, Giokas teaches further comprising: monitoring the log data (see Giokas, [0096]: “The monitoring agent may create one or more types of logs including, e.g., general system logs, network security logs, intrusion prevention system logs, intrusion detection system logs, or an antivirus application log.”; and [0098]: “In some embodiments, the monitoring agent may store log files in a predetermined directory of a server or client of the protected network. The log collector 210 may access the predetermined directory based on a time interval (e.g., periodically, upon request, or some other time interval) to determine whether there are new or updated logs that can be retrieved”); determining that a parameter associated with the log data satisfies a threshold criterion (see Giokas, [0118]: “If the current behavior differs from the baseline behavior (e.g., a threshold amount of different performance usage, different email senders, pings, different URLs, etc.), then the network security monitor 120 may generate an alert or report.”); and outputting an alert regarding the parameter associated with the log data (see Giokas, [0118]: “If… then the network security monitor 120 may generate an alert or report.”). As per claims 3, 10, and 17, which respectively depend on claims 1, 8, and 15, Giokas and Singh further teach wherein analyzing the log data further comprises: identifying a pattern, a trend, or a potential issue in the O-RAN based on the log data (see Giokas, [0086]: “Thus, the log correlation engine can identify potential APTs based upon their behavior and the patterns they create within the system; patterns, which may be otherwise undetectable, but can be revealed by the analysis performed by the correlation engine.”; and Claim 1 rejection above). As per claims 4, 11, and 18, which respectively depend on claims 1, 8, and 15, Giokas teaches further comprising: performing a remedy action responsive to the notification (see Giokas, [0008]: “An intrusion detection system detects malicious attacks and then raises an alarm such that an authorized system administrator is notified of the attack and can take the appropriate actions to stymie it”; and [0146]: “Increasing the frequency of system log creation and the frequency with which the system logs are sent to the APT intelligence platform (or network security monitor) can increase the resolution of the network security monitor, as it may be possible to perform more analysis in a time interval.”). As per claims 5 and 12, which respectively depend on claims 1 and 8, Giokas further teaches wherein the log data comprises at least one of: application data or event data (see Giokas, [0094]: “Each log may have a log identifier and indicate information associated with the network activity such as device identifiers, time stamps, domains, level of severity of the log event, source port of the session, source internet protocol (IP) of the session, destination IP of the session, reference URL, etc.”; and Page 11, TABLE 1: “Logid ID of the event” & “Type (threat) Type of the event”). As per claims 6, 13, and 19, which respectively depend on claims 1, 8, and 15, Giokas does not explicitly teach wherein the plurality of radio access network elements comprise: one or more open radio units (O-RUs), one or more open distributed units (O-DUs), and one or more open centralized units (O-CUs). Singh teaches wherein the plurality of radio access network elements comprise: one or more open radio units (O-RUs), one or more open distributed units (O-DUs), and one or more open centralized units (O-CUs) (see, [0045]: “The O-RAN architecture 100 includes a service management and orchestration framework (SMO) 110 with a non-real-time RIC 105, a near real-time RAN intelligent controller (RIC) 115, open control plane central unit (O-CU-CP) 120, open user plane central unit (O-CU-UP) 125, open distributed unit (O-DU) 130, open radio unit (O-RU) 135, and the O-Cloud 140.”; and [0048]: “The two RICs are each adapted to specific control loop and latency requirements. The near real-time RIC 115 provides programmatic control of open centralized units (O-CUs) and open distributed units (O-DUs) on time cycles of 10 ms to 1 second.”). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the invention to modify the system of Giokas in view of Singh so that the plurality of radio access network elements comprise: one or more open radio units (O-RUs), one or more open distributed units (O-DUs), and one or more open centralized units (O-CUs). One would be motivated to do so because such units are well-known, routine, and conventional in O-RAN. As per claims 7, 14, and 20, which respectively depend on claims 1, 8, and 15, Giokas does not explicitly teach wherein the processing device comprises a service management and orchestration (SMO) or an element management system (EMS), wherein the processing device is specific to a first vendor, and wherein the plurality of radio access network elements are specific to various different vendors. Singh teaches wherein the processing device comprises a service management and orchestration (SMO) or an element management system (EMS), wherein the processing device is specific to a first vendor, and wherein the plurality of radio access network elements are specific to various different vendors (see Singh, [0045]: “The O-RAN architecture 100 includes a service management and orchestration framework (SMO) 110 with a non-real-time RIC 105, a near real-time RAN intelligent controller (RIC) 115, open control plane central unit (O-CU-CP) 120, open user plane central unit (O-CU-UP) 125, open distributed unit (O-DU) 130, open radio unit (O-RU) 135, and the O-Cloud 140.”). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the invention to modify the system of Giokas in view of Singh so the processing device comprises a service management and orchestration (SMO) or an element management system (EMS), wherein the processing device is specific to a first vendor, and wherein the plurality of radio access network elements are specific to various different vendors. One would be motivated to do so because SMO frameworks are well-known, routine, and conventional in O-RAN. Conclusion 5. For the reasons above, claims 1-20 have been rejected and remain pending. 6. Any inquiry concerning this communication or earlier communications from the examiner should be directed to MICHAEL Y WON whose telephone number is (571)272-3993. The examiner can normally be reached on Wk.1: M-F: 8-5 PST & Wk.2: M-Th: 8-7 PST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Nicholas R Taylor can be reached on 571-272-3889. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /Michael Won/Primary Examiner, Art Unit 2443
Read full office action

Prosecution Timeline

Mar 13, 2025
Application Filed
Jun 11, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12689969
TRANSPORT MECHANISM SELECTION FOR MULTI-ACCESS POINT COORDINATION GROUP (CG)
1y 8m to grant Granted Jul 21, 2026
Patent 12689678
DETERMINING PROCESSING WEIGHTS OF RULE VARIABLES FOR RULE PROCESSING OPTIMIZATION
1y 7m to grant Granted Jul 21, 2026
Patent 12676789
SELF-ADAPTIVE HEALTH MONITORING SYSTEMS INCLUDING NETWORKS OF TENSOR NETWORKS
1y 8m to grant Granted Jul 07, 2026
Patent 12676799
METHODS AND SYSTEMS FOR OBJECT-AWARE FUZZY PROCESSING BASED ON ANALOGIES
1y 6m to grant Granted Jul 07, 2026
Patent 12665909
Federated Learning Process
2y 0m to grant Granted Jun 23, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
80%
Grant Probability
99%
With Interview (+28.4%)
2y 11m (~1y 6m remaining)
Median Time to Grant
Low
PTA Risk
Based on 847 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month