Prosecution Insights
Last updated: October 04, 2026
Application No. 19/081,839

SYSTEMS AND METHODS FOR RANSOMWARE EVENTS

Non-Final OA §101§103§112§DOUBLEPATENT
Filed
Mar 17, 2025
Priority
Mar 19, 2024 — provisional 63/567,385
Examiner
SAVENKOV, VADIM
Art Unit
Tech Center
Assignee
Dymium Inc.
OA Round
1 (Non-Final)
61%
Grant Probability
Moderate
1-2
OA Rounds
1y 10m
Est. Remaining
81%
With Interview

Examiner Intelligence

Grants 61% of resolved cases
61%
Career Allowance Rate
193 granted / 318 resolved
+0.7% vs TC avg
Strong +20% interview lift
Without
With
+20.3%
Interview Lift
resolved cases with interview
Typical timeline
3y 5m
Avg Prosecution
27 currently pending
Career history
374
Total Applications
across all art units

Statute-Specific Performance

§101
10.6%
-29.4% vs TC avg
§103
53.7%
+13.7% vs TC avg
§102
8.9%
-31.1% vs TC avg
§112
17.3%
-22.7% vs TC avg
Black line = Tech Center average estimate • Based on career data from 318 resolved cases

Office Action

§101 §103 §112 §DOUBLEPATENT
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Priority Applicant’s claim to priority to US provisional application 63/567,385 (filed 3/19/2024) has been acknowledged by the examiner. Information Disclosure Statement The 7/31/2025 and 8/24/2026 IDS documents have been considered by the examiner. Specification The title of the invention is not descriptive since the claims drawn to the ransomware detection embodiment(s) have been withdrawn. The currently presented claims do not comprise any subject matter concerning ransomware events. A new title is required that is clearly indicative of the invention to which the claims are directed. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer. Claims 1-6 and 13-20 rejected on the ground of nonstatutory double patenting as being unpatentable over at least claims 1-2, 6, and 9 of U.S. Patent No. 12,393,719 B2 in view of Wang (US 2023/0245651 A1). The patent claims are considered to anticipate the instant claims as per the analysis below, but do not specify: the “artificial intelligence resource comprising at least one named-entity recognition model” and “analyze the request using the at least one named-entity recognition model to identify sensitive information within the request before accessing any data sources.” However, the patent claims in view of at least [0135] and [0141] of Wang are considered to disclose these limitations. Therefore, it would have been obvious to one of ordinary skill in the art to modify the AI of the instant claims to further implement NER because particular known technique was recognized as part of the ordinary capabilities of one skilled in the art for identifying certain portions of data. Independent claim 13 is substantially similar to independent claim 1 and is therefore rejected under the same analysis. The dependent claims are also likewise rejected with their respective parent claims. Instant Application US 12,393,719 B2 1. A data security system for safeguarding private data across databases and file-sharing platforms, the system comprising: at least one data access proxy communicatively coupled to at least one private database and at least one file-sharing service; at least one artificial intelligence resource comprising at least one named-entity recognition model and at least one large language model, the artificial intelligence resource communicatively coupled to the at least one data access proxy; at least one server communicatively coupled to the at least one data access proxy and configured to operate the at least one data access proxy and the artificial intelligence resource to: determine a user identity and a request from a user to access at least one data item stored within the at least one private database or shared via the at least one file-sharing service; analyze the request using the at least one named-entity recognition model to identify sensitive information within the request before accessing any data sources; validate the user and the request by inspecting the user identity, evaluating user activity history of the user, and using the artificial intelligence resource to detect suspicious behavior, and determining permissions and restrictions associated with the user and the at least one data item; retrieve the at least one data item from the at least one private database or the at least one file-sharing service; inspect one or more security attributes of the at least one data item, including data origin and intended confidentiality level; and transform the at least one data item using the at least one large language model based on one or more privacy rules, wherein transformation includes generating synthetic data or redacting personally identifiable information using the large language model, and at least one of redacting sensitive information, substituting information with proxy data, or adding encryption to the at least one data item, and wherein a transformed data item is provided to the user without granting direct access to the at least one private database or the at least one file-sharing service; and wherein the user is prevented from directly accessing the at least one private database or the at least one file-sharing service. 1. A data security system for protecting private data within a database, the data security system comprising: at least one AI-powered assistant configured to analyze available data, create a contextual framework based on a nature of a query, a persona, and a permission of a user and the at least one AI-powered assistant configured to define and analyze a task associated with a role within an organization… at least one data access proxy communicatively coupled with at least one private database, the at least one data access proxy further communicatively coupled with at least one server, the at least one server configured to operate the at least one data access proxy to… … a) identify the user and a request from the user to access at least one data item stored in the at least one private database… … b) validate the user and the request using the behavioral analysis and outlier detection, the validation including inspecting the user's identity, evaluating the user's activity history, evaluating permissions and restrictions associated with the user and the at least one data item, and analyzing patterns in user activity for suspicious behavior including sudden changes in the scope or the frequency of queries; c) access the at least one private database to retrieve the at least one data item; d) inspect one or more security attributes related to the at least one data item; and e) transform the at least one data item based on one or more privacy rules, the transformation including: redacting information from the at least one data item, deleting information from the at least one data item, substituting information from the at least one data item with other information, adding information to the at least one data item, providing synthetic data as a private data item, and providing proxy data for the at least one data item. 2. The data security system of claim 1, wherein the at least one server is further configured to provide a response to the user, the response comprising a transformed version of the requested at least one data item, the transformed version being accessible to the user by way of the at least one data access proxy. 4. The data security system of claim 1, wherein the one or more security attributes further include data sharing permissions, and wherein the at least one server is configured to enforce the data sharing permissions based on a role of the user. 1. …at least one AI-powered assistant configured to analyze available data, create a contextual framework based on a nature of a query, a persona, and a permission of a user and the at least one AI-powered assistant configured to define and analyze a task associated with a role within an organization… 9. The data security system of claim 1, further comprising the AI-powered assistant configured to: utilize the contextual framework to interpret a natural language query from the user; and provide a context-aware, personalized response and guidance tailored to the user's permission and role. 5. The data security system of claim 1, wherein the transformation of the at least one data item further includes adding synthetic data configured to track the user activity history with the transformed data item. 1. …e) transform the at least one data item based on one or more privacy rules, the transformation including: redacting information from the at least one data item, deleting information from the at least one data item, substituting information from the at least one data item with other information, adding information to the at least one data item, providing synthetic data as a private data item, and providing proxy data for the at least one data item. 16. The method of claim 13, wherein validating the user further comprises detecting suspicious behavior using the artificial intelligence resource, wherein the suspicious behavior includes a sudden increase in frequency of requests for the at least one data item from the user. 1. …the at least one AI-powered assistant configured to perform behavioral analysis based on a history of the user and user's associated benign or malicious behavior, determine suspicious behavior from outliers in user activity by monitoring sudden changes in an amount and type of data sought by the user, apply probabilistic reasoning to classify suspicious behavior when query patterns change in scope or frequency, maintain a complete audit trail of all data access events, and enable zero trust for data use… b) validate the user and the request using the behavioral analysis and outlier detection, the validation including inspecting the user's identity, evaluating the user's activity history, evaluating permissions and restrictions associated with the user and the at least one data item, and analyzing patterns in user activity for suspicious behavior including sudden changes in the scope or the frequency of queries; 19. The method of claim 13, further comprising: combining, via the at least one server, data from a plurality of private databases into a virtual database; and deriving the transformed data item from the virtual database. 6. The data security system of claim 1, the at least one data access proxy further functioning as a single front end between and communicatively coupled with one or more data consumers and one or more data side silos in an organization. Claims 1-6 and 13-20 are rejected on the ground of nonstatutory double patenting as being unpatentable over at least claims 1-3 of U.S. Patent No. 12,694,150 B2. Although the claims at issue are not identical, they are not patentably distinct from each other because the patent claims anticipate the instant claims as per the analysis below. Independent claim 13 is substantially similar to independent claim 1 and is therefore rejected under the same analysis. The dependent claims are also likewise rejected with their respective parent claims. Instant Application US 12,694,150 B2 1. A data security system for safeguarding private data across databases and file-sharing platforms, the system comprising: at least one data access proxy communicatively coupled to at least one private database and at least one file-sharing service; at least one artificial intelligence resource comprising at least one named-entity recognition model and at least one large language model, the artificial intelligence resource communicatively coupled to the at least one data access proxy; at least one server communicatively coupled to the at least one data access proxy and configured to operate the at least one data access proxy and the artificial intelligence resource to: determine a user identity and a request from a user to access at least one data item stored within the at least one private database or shared via the at least one file-sharing service; analyze the request using the at least one named-entity recognition model to identify sensitive information within the request before accessing any data sources; validate the user and the request by inspecting the user identity, evaluating user activity history of the user, and using the artificial intelligence resource to detect suspicious behavior, and determining permissions and restrictions associated with the user and the at least one data item; retrieve the at least one data item from the at least one private database or the at least one file-sharing service; inspect one or more security attributes of the at least one data item, including data origin and intended confidentiality level; and transform the at least one data item using the at least one large language model based on one or more privacy rules, wherein transformation includes generating synthetic data or redacting personally identifiable information using the large language model, and at least one of redacting sensitive information, substituting information with proxy data, or adding encryption to the at least one data item, and wherein a transformed data item is provided to the user without granting direct access to the at least one private database or the at least one file-sharing service; and wherein the user is prevented from directly accessing the at least one private database or the at least one file-sharing service. 1. A data security system comprising: at least one artificial intelligence resource comprising at least one named-entity recognition model, at least one large language model, and at least one artificial intelligence application supported by a neural network; and at least one server communicatively coupled to the artificial intelligence resource and further communicatively coupled to at least one private database, the server configured to operate the artificial intelligence resource to: identify a user and a request from the user to access at least one data item stored in the private database; 3. The data security system of claim 1, wherein the named-entity recognition model is trained to identify at least one of: personally identifiable information (PII), financial data, medical information, and trade secrets within the data item, and wherein the named-entity recognition model outputs confidence scores for identified sensitive information types. validate the user and the request, the validation including inspecting the user's identity, evaluating permissions and restrictions associated with the user and the data item, and evaluating the user's activity history by directing information associated with the user… inspect one or more security attributes related to the data item via the named-entity recognition model; transform the data item based on one or more privacy rules via the large language model using results from both the neural network application analysis and the named-entity recognition model inspection, the transformation comprising: at least one of: redacting information from the data item, deleting information from the data item, substituting information from the data item with other information, and adding information to the data item; and at least one of: substituting synthetic data for the data item, providing the synthetic data as a private data item, and providing proxy data for the data item, the synthetic data or the proxy data being used by the server and the artificial intelligence resource as a tracker to trace data traffic associated with the user; reconstitute the data item in a response to the request; and transmit the response with a transformed version of the data item to the user or a designated recipient. 4. The data security system of claim 1, wherein the one or more security attributes further include data sharing permissions, and wherein the at least one server is configured to enforce the data sharing permissions based on a role of the user. 1. …evaluating permissions and restrictions associated with the user and the data item… 5. The data security system of claim 1, wherein the transformation of the at least one data item further includes adding synthetic data configured to track the user activity history with the transformed data item. 1. … and at least one of: substituting synthetic data for the data item, providing the synthetic data as a private data item, and providing proxy data for the data item, the synthetic data or the proxy data being used by the server and the artificial intelligence resource as a tracker to trace data traffic associated with the user; reconstitute the data item in a response to the request; and transmit the response with a transformed version of the data item to the user or a designated recipient. 2. The data security system of claim 1, wherein the transformed version of the data item includes the synthetic data resembling sensitive information in the data item. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claim 5 is rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claim 5 recites “wherein the transformation of the at least one data item further includes adding synthetic data configured to track the user activity history with the transformed data item,” which renders the claim indefinite because it is not clear how to interpret “the synthetic data configured to track.” It is not clear whether this limitation relates to implementing code or a script in the synthetic data to execute some kind of tracking functionality, or if it relates to the synthetic data being watermarked in some way as to enable tracking. In the latter case, it is unclear whether “to track the user activity history with the transformed data item” is part of the claim scope or an intended use of the configuration. Therefore, a person of ordinary skill in the art could not interpret the metes and bounds of the claim so as to understand how to avoid infringement. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-6 and 13-17 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Note that the courts do not distinguish between mental processes that are performed entirely in the human mind and mental processes that require a human to use a physical aid (e.g., pen and paper or a slide rule) to perform the claim limitation (refer to MPEP 2106.04(a)(2)). Independent claim 1 recites the following abstract idea limitations: A data security system for safeguarding private data across databases (e.g., patient health records stored in medical offices) and file-sharing platforms (e.g., any office or organization sharing the patient health records), the system comprising: at least one data access proxy communicatively coupled to at least one private database and at least one file-sharing service (providing a trusted third party intermediary as part of certain methods of organizing human activity—e.g., a trusted intermediary office to securely provide requested patient health records, where the communicative coupling may be telephonic, mail, or even verbal); at least one resource comprising at least one named-entity recognition model and at least one large language model, the resource communicatively coupled to the at least one data access proxy (observation, evaluation, and judgement as part of a mental process—e.g., the trusted intermediary office having an employee to review patient health records for certain fields such as names); [the trusted intermediary] to: determine a user identity and a request from a user to access at least one data item stored within the at least one private database or shared via the at least one file-sharing service (observation and evaluation as part of a mental process—e.g., an employee at the intermediary office receives a request for patient health records and reviews requestor information, where the request may be telephonic, mail, or verbal); analyze the request using the at least one named-entity recognition model to identify sensitive information within the request before accessing any data sources (observation and evaluation as part of a mental process—e.g., the employee identifies sensitive information such as names, addresses, and other PII); validate the user and the request by inspecting the user identity, evaluating user activity history of the user, and using the resource to detect suspicious behavior, and determining permissions and restrictions associated with the user and the at least one data item (observation, evaluation, and judgement as part of a mental process—e.g., the employee reviews information about the requestor to determine if they’re legitimate and have permission to access the requested patient health records; activity history can include past transactions with the intermediary office); retrieve the at least one data item from the at least one private database or the at least one file-sharing service (record retrieval as part of certain methods of organizing human activity—e.g., an employee retrieves a given patient health record via telephone, mail, or verbally); inspect one or more security attributes of the at least one data item, including data origin and intended confidentiality level (observation and evaluation as part of a mental process—e.g., the employee checks the permissions and regulations for the given patient health record); and transform the at least one data item using the at least one large language model based on one or more privacy rules, wherein transformation includes generating synthetic data or redacting personally identifiable information using the large language model, and at least one of redacting sensitive information, substituting information with proxy data, or adding encryption to the at least one data item (observation and evaluation as part of a mental process—e.g., the employee reviews the given patient health record to redact or otherwise substitute any information deemed too sensitive to share based on owner preferences, regulations, and the requestor’s permissions), and wherein a transformed data item is provided to the user without granting direct access to the at least one private database or the at least one file-sharing service (serving as a trusted third-party intermediary as part of certain methods of organizing human activity—e.g., the intermediary office performs its role on behalf of the patient record holders to securely transfer information); and wherein the user is prevented from directly accessing the at least one private database or the at least one file-sharing service (serving as a trusted third-party intermediary as part of certain methods of organizing human activity—e.g., the requestor is barred from direct unfiltered access because they are not the patient or medical provider). Independent claim 1 recites the following limitations which may comprise additional elements sufficient to amount to significantly more than the judicial exception: the resource further comprising and “artificial intelligence resource;” “at least one server communicatively coupled to the at least one data access proxy and configured to operate the at least one data access proxy and the artificial intelligence resource.” With respect to step 2A, this judicial exception is not integrated into a practical application because adding the words "apply it" (or an equivalent) with the judicial exception, or mere instructions to implement an abstract idea on a computer, or merely using a computer as a tool to perform an abstract idea are not considered to be sufficient-e.g., see MPEP 2106.05(f). In this case, the claim is drawn to serving as an intermediary for data requests, with included request authentication and data redaction/substitution based on permission. This is done at a high level of generality such that it can be analogously performed by human employees at a trusted intermediary office. For example, the trusted intermediary office may receive requests for patient health records stored with medical providers, review the requests and requestors, and redact/substitute data in the requested health records before provision according to user preferences and regulations. While the claim does utilize an “artificial intelligence resource” for performing the claim steps relating to the employees, this is considered to be merely automating the mental process at a high level of generality (i.e., adding the words "apply it" (or an equivalent) with the judicial exception, or mere instructions to implement an abstract idea on a computer, or merely using a computer as a tool to perform an abstract idea). The claim having a server perform as the intermediary is likewise considered to be merely adding the words "apply it" (or an equivalent) with the judicial exception, or mere instructions to implement an abstract idea on a computer, or merely using a computer as a tool to perform an abstract idea. Substantially any AI model and computer can be used to implement the claim steps. As such, the claimed invention is addressing a problem that transcends computing (serving as a trusted intermediary for securely providing data) rather than improving the functioning of a computer, or an improvement to other technology or a technical field. With respect to step 2B, the claim(s) does/do not include additional elements that are sufficient to amount to significantly more than the judicial exception because adding the words "apply it" (or an equivalent) with the judicial exception, or mere instructions to implement an abstract idea on a computer, or merely using a computer as a tool to perform an abstract idea are not considered to be sufficient-e.g., see MPEP 2106.05(f). In this case the “artificial intelligence resource” and “at least one server communicatively coupled to the at least one data access proxy and configured to operate the at least one data access proxy and the artificial intelligence resource” are base level computer elements such that any computer would be capable of performing the abstract idea. And the “artificial intelligence resource” is not defined beyond the human-performable actions which it is taking in the claim. As such, it may be any software for adding the words "apply it" concerning automation of the abstract idea. Regarding independent claim 13, it is substantially similar to elements of independent claim 1 above, and is therefore rejected under the same analysis. Regarding dependent claim 2, it merely further specifies the abstract idea and is rejected under substantially the same analysis because it may be drawn to “the at least one file-sharing service” further including “a third-party file sharing service.” Regarding dependent claim 3, it recites the following abstract idea limitations: wherein the at least one server is further configured to normalize the request into a standard dialect of Structured Query Language (SQL) before retrieving the at least one data item (evaluation as part of a mental process—e.g., an employee converting request parameters to an SQL query without actually querying any databases; actual use and implementation of SQL is not positively recited in the claim, and it is therefore outside of the claim scope). Regarding dependent claim 4, it merely further specifies the abstract idea (i.e., setting and reviewing permissions) and is rejected under substantially the same analysis as claim 1 above. Regarding dependent claim 5, it recites the following abstract idea limitations: wherein the transformation of the at least one data item further includes adding synthetic data configured to track the user activity history with the transformed data item (evaluation as part of a mental process—e.g., the employee writes, or otherwise adds, synthetic data of a given type in place of sensitive data in the health records). Regarding dependent claim 6, it recites the following abstract idea limitations: wherein the at least one server is further configured to establish a secure tunnel over an encrypted authenticated connection between the at least one data access proxy and the user (evaluation as part of a mental process—e.g., the intermediary office and its partners implementing a cipher for securely transmitting information via telephone, mail, or verbally). Regarding dependent claims 14-17, they merely further specify the abstract idea, and are rejected under substantially the same analysis as claims 1-6 and 13 above. Regarding dependent claims 18-20, they are not considered to be drawn to an abstract idea without significantly more. Claim 18 explicitly implements “establishing the secure connection using Transport Layer Security (TLS) encryption;” claim 19 implements “combining, via the at least one server, data from a plurality of private databases into a virtual database; and deriving the transformed data item from the virtual database;” and claim 20 implements “a kill switch mechanism to disable the at least one data access proxy in response to a detected breach.” These claim limitations are considered to at least recite additional elements that respectively integrate the judicial exception into a practical application. Claims 1-6 are rejected under 35 U.S.C. 101 because the claimed invention is directed to non-statutory subject matter. The claim(s) does/do not fall within at least one of the four categories of patent eligible subject matter because claim 1 is considered to be drawn to software per se, which is not patent eligible subject matter. Claim 1 is drawn to “A data security system for safeguarding private data across databases and file-sharing platforms, the system comprising: at least one data access proxy communicatively coupled to at least one private database and at least one file-sharing service… at least one artificial intelligence resource… at least one server communicatively coupled to the at least one data access proxy and configured to operate the at least one data access proxy and the artificial intelligence resource.” While the instant specification provides examples of hardware implementing these claim elements (e.g., [0048] describing hardware processors and memory), these are merely examples and not the specific definitions. Further, the instant specification considers optionally performing “the functions described herein… in one or more of hardware, software, firmware, digital components, or analog components” as in [0077] and [0005]. As such, the “data security system” may be implemented as software per se. The dependent claims do not rectify this issue and are therefore likewise rejected. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1, 4-6, 13-15, and 18 is/are rejected under 35 U.S.C. 103 as being unpatentable over Rahmat (US 20210/385196 A1) in view of Wang (US 2023/0245651 A1). Regarding claim 1, Rahmat discloses: A data security system for safeguarding private data across databases and file-sharing platforms (e.g., [0002] and [0011] of Rahmat concerning data sharing from operation technology (OT) networks; [0043] of Rahmat concerning data files and databases), the system comprising: at least one data access proxy (DCU 106 in at least FIG. 1 of Rahmat) communicatively coupled to at least one private database (devices of OT network 104 having data storage as in FIG. 1 and [0043] of Rahmat for storing raw data) and at least one file-sharing service (e.g., the central server in FIG. 3 and [0030] of Rahmat); Refer to at least FIG. 1, [0003]-[0004], and [0011] of Rahmat with respect to the DCU being configured to operate as a unidirectional communication connection between the OT and IT networks; forwarding data. at least one artificial intelligence resource, the artificial intelligence resource communicatively coupled to the at least one data access proxy; Refer to at least 236 in FIG. 2 and [0025] of Rahmat with respect to a neural network coupled to the DCU. at least one server communicatively coupled to the at least one data access proxy and configured to operate the at least one data access proxy and the artificial intelligence resource (the DCU hardware—e.g., FIG. 5 and [0040] of Rahmat) to: retrieve the at least one data item from the at least one private database or the at least one file-sharing service; Refer to at least 402-406 in FIG. 4, [0022], [0029], and [0034] of Rahmat with respect to collecting raw data from the OT network devices’ data storage by the DCU and its associated neural network. transform the at least one data item using the at least one large language model based on one or more privacy rules, wherein transformation includes generating synthetic data or redacting personally identifiable information using the large language model, and at least one of redacting sensitive information, substituting information with proxy data, or adding encryption to the at least one data item, and wherein a transformed data item is provided to the user without granting direct access to the at least one private database or the at least one file-sharing service; and Refer to at least the abstract, 408-412 in FIG. 4, [0004], [0015], and [0025]-[0028] of Rahmat with respect to the DCU neural network performing anonymization or generating synthetic data for the purpose of preserving privacy (e.g., [0012] of Rahmat). wherein the user is prevented from directly accessing the at least one private database or the at least one file-sharing service. Refer to at least [0012] and [0023] of Rahmat with respect to the DCU maintaining physical separation between the IT and OT networks to ensure unidirectional communication. Rahmat concerns a data proxy and neural network for preserving data privacy, but does not disclose: the AI further comprising at least one named-entity recognition model and at least one large language model; the AI further comprising to determine a user identity and a request from a user to access at least one data item stored within the at least one private database or shared via the at least one file-sharing service; analyze the request using the at least one named-entity recognition model to identify sensitive information within the request before accessing any data sources; validate the user and the request by inspecting the user identity, evaluating user activity history of the user, and using the artificial intelligence resource to detect suspicious behavior, and determining permissions and restrictions associated with the user and the at least one data item; and inspect one or more security attributes of the at least one data item, including data origin and intended confidentiality level. However, Rahmat in view of Wang discloses: the AI further comprising at least one named-entity recognition model and at least one large language model; Refer to at least [0135] and [0141] of Wang with respect to named entity recognition; at least [0243]-[0244] of Wang with respect to language models. the AI further comprising to determine a user identity and a request from a user to access at least one data item stored within the at least one private database or shared via the at least one file-sharing service; Refer to at least FIG. 8, [0227]-[0228], and [0237] of Wang with respect to an AI performing user authentication for access to data, where the AI verifies the user’s identity. analyze the request using the at least one named-entity recognition model to identify sensitive information within the request before accessing any data sources; Refer to at least FIG. 8, [0239], and [0231] of Wang with respect to the AI protecting sensitive data such as names using a transformation module to remove first-level data. validate the user and the request by inspecting the user identity, evaluating user activity history of the user, and using the artificial intelligence resource to detect suspicious behavior, and determining permissions and restrictions associated with the user and the at least one data item; Refer to at least FIG. 8, [0228]-[0230], and [0237] of Wang with respect to the authentication including verifying the identity, verifying user activities and behavior, and determining the user’s permissions. and inspect one or more security attributes of the at least one data item, including data origin and intended confidentiality level. Refer to at least [0238], [0240], [0228], [0230], and [0236] of Wang with respect to permission and clearance levels for data to be accessed. The cited portions of Wang include associating permissions and clearance levels based on a given data owner and their preferences. The teachings of both Rahmat and Wang concern data privacy by way of artificial intelligence, and are considered to be within the same field of endeavor and combinable as such. Likewise, both are drawn to neural network models. Therefore it would have been obvious to one of ordinary skill in the art before the filing date of Applicant’s invention to modify the teachings of Rahmat to further implement the AI functionalities of Wang including use of a language model and NER for identifying sensitive data, as well as access control and user authentication including identity, activity, behavior, and permission analysis for at least the purpose of further improving data privacy and security (i.e., more particularly and accurately identifying sensitive information to anonymize or replace with synthetic data; including more granular access control to allow for securing data according to roles and need-to-know). Regarding claim 4, it is rejected for substantially the same reasons as claim 1 above (e.g., [0236] of Wang concerning assigning permissions based on roles). Regarding claim 5, it is rejected for substantially the same reasons as claim 1 above (i.e., the citations to Rahmat concerning generating synthetic data; the citations to Wang concerning tracking user activity). Regarding claim 6, Rahmat-Wang discloses: The data security system of claim 1, wherein the at least one server is further configured to establish a secure tunnel over an encrypted authenticated connection between the at least one data access proxy and the user. Refer to at least [0233] of Wang with respect to providing security for data in transit using, e.g., SSL or TLS. Therefore it would have been obvious to one of ordinary skill in the art before the filing date of Applicant’s invention to modify the teachings of Rahmat-Wang to further implement securing data in transit using protocols such as SSL and TLS for at least the reasons discussed in the cited portion of Wang (i.e., to “ensure that any data transmitted between the two parties is protected from eavesdropping, tampering, or interception by unauthorized individuals”). Independent claim 13 is substantially similar to elements of independent claim 1 above, and is therefore likewise rejected under the same citations and obviousness rationale. Regarding claim 14, it is rejected for substantially the same reasons as claim 13 above (e.g., at least [0135], [0141], and [0239] of Wang). Regarding claim 15, Rahmat-Wang discloses: The method of claim 13, wherein transforming the at least one data item further comprises generating the synthetic data using the at least one large language model, wherein the at least one large language model is trained on a corpus of organizational legacy resources including files, emails, and documents. Refer to at least [0026] and [0032]-[0033] of Rahmat with respect to training for generating the synthetic data based off of raw data examples. Regarding claim 18, it is rejected for substantially the same reasons as claim 6 above. Claim(s) 2 is/are rejected under 35 U.S.C. 103 as being unpatentable over Rahmat-Wang as applied to claims 1, 4-6, 13-15, and 18 above, and further in view of Ngo (US 2025/0061011 A1). Regarding claim 2, Rahmat-Wang discloses file systems as in [0043] of Rahmat but does not specify: wherein the at least one file-sharing service includes at least one of a Network File System (NFS), a Server Message Block (SMB) system, and/or a third-party file sharing service. However, Rahmat-Wang in view of Ngo discloses: wherein the at least one file-sharing service includes at least one of a Network File System (NFS), a Server Message Block (SMB) system, and/or a third-party file sharing service. Refer to at least [0208] of Ngo with respect to implementing NFS or any other appropriate file system protocol. The teachings of Ngo likewise concern data storage and privacy, and are considered to be within the same field of endeavor and combinable as such. Therefore it would have been obvious to one of ordinary skill in the art before the filing date of Applicant’s invention to modify the teachings of Rahmat-Wang to further implement NFS because he substitution of one known element for another would have yielded predictable results to one of ordinary skill in the art at the time as per the cited portion of Ngo. Claim(s) 3 is/are rejected under 35 U.S.C. 103 as being unpatentable over Rahmat-Wang as applied to claims 1, 4-6, 13-15, and 18 above, and further in view of Garrison (US 2003/0204752 A1). Regarding claim 3, Rahmat-Wang does not disclose: wherein the at least one server is further configured to normalize the request into a standard dialect of Structured Query Language (SQL) before retrieving the at least one data item. However, Rahmat-Wang in view of Garrison discloses: wherein the at least one server is further configured to normalize the request into a standard dialect of Structured Query Language (SQL) before retrieving the at least one data item. Refer to at least the abstract and [0069] of Garrison with respect to translating a client request for data into an appropriate SQL query (or other type of query compatible with the database system). The teachings of Garrison likewise concern access control for data requests and are considered to be within the same field of endeavor and combinable as such. Therefore it would have been obvious to one of ordinary skill in the art before the filing date of Applicant’s invention to modify the teachings of Rahmat-Wang to further implement converting requests into queries compatible with the target database (e.g., SQL queries) for at least the purpose of improving interoperability and user experience (i.e., the user does not need to translate and resubmit queries for every database). Claim(s) 16-17 is/are rejected under 35 U.S.C. 103 as being unpatentable over Rahmat-Wang as applied to claims 1, 4-6, 13-15, and 18 above, and further in view of Jeffords (US 2022/0345457 A1). Regarding claim 16, Rahmat-Wang does not disclose: wherein validating the user further comprises detecting suspicious behavior using the artificial intelligence resource, wherein the suspicious behavior includes a sudden increase in frequency of requests for the at least one data item from the user. However, Rahmat-Wang in view of Jeffords discloses: wherein validating the user further comprises detecting suspicious behavior using the artificial intelligence resource, wherein the suspicious behavior includes a sudden increase in frequency of requests for the at least one data item from the user. Refer to at least FIG. 6-7, [0084], and [0120] of Jeffords with respect to detecting a spike in requests as part of risk scoring and deciding whether to grant access. The teachings of Jeffords likewise concern request access control and are considered to be within the same field of endeavor and combinable as such. Therefore it would have been obvious to one of ordinary skill in the art before the filing date of Applicant’s invention to modify the teachings of Rahmat-Wang to further implement counting requests as part of user activity to be verified for at least the purpose of improving security (i.e., preventing denial of service attacks, replay attacks, and guessing attacks). Regarding claim 17, Rahmat-Wang-Jeffords discloses: The method of claim 13, further comprising generating, via at least one server, a risk score for the user based on the activity history and the suspicious behavior detected by the artificial intelligence resource. Refer to at least FIG. 7, [0006], and [0074] of Jeffords with respect to anomaly-based risk scoring with use of machine learning. Therefore it would have been obvious to one of ordinary skill in the art before the filing date of Applicant’s invention to modify the teachings of Rahmat-Wang to further implement risk scoring because the particular known technique was recognized as part of the ordinary capabilities of one skilled in the art. Claim(s) 19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Rahmat-Wang as applied to claims 1, 4-6, 13-15, and 18 above, and further in view of Diamant (US 2022/0414245 A1). Regarding claim 19, Rahmat-Wang discloses: The method of claim 13, further comprising: combining, via the at least one server, data from a plurality of private databases into [a DCU database]; and deriving the transformed data item from the [DCU database]. Refer to at least FIG. 1 and [0043] of Rahmat with respect to the DCU gathering raw data from plural data sources (e.g., devices 108); data storage in databases. Rahmat-Wang does not specify: the DCU database further comprising a virtual database. However, Rahmat-Wang in view of Diamant discloses: the DCU database further comprising a virtual database. Refer to at least FIG. 1 and [0004]-[0005] of Diamant with respect to a virtual database associated with a database protection solution including redaction. The teachings of Diamant likewise concern request access control and protecting sensitive data, and are considered to be within the same field of endeavor and combinable as such. Therefore it would have been obvious to one of ordinary skill in the art before the filing date of Applicant’s invention to modify the teachings of Rahmat-Wang to further implement a virtual database associated with the DCU because the particular known technique was recognized as part of the ordinary capabilities of one skilled in the art. Claim(s) 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Rahmat-Wang as applied to claims 1, 4-6, 13-15, and 18 above, and further in view of Sislow (US 2022/0019682 A1). Regarding claim 20, Rahmat-Wang does not disclose: implementing, via the at least one server, a kill switch mechanism to disable the at least one data access proxy in response to a detected breach; and allowing an authorized administrator to override the disablement of the at least one data access proxy. However, Rahmat-Wang in view of Sislow discloses: implementing, via the at least one server, a kill switch mechanism to disable the at least one data access proxy in response to a detected breach; Refer to at least FIG. 5J and [0069] of Sislow with respect to a vault teardown at a data proxy responsive to detecting a malicious action. The teachings of Sislow likewise concern data request access control and privacy, and are considered to be within the same field of endeavor and combinable as such. Therefore it would have been obvious to one of ordinary skill in the art before the filing date of Applicant’s invention to modify the teachings of Rahmat-Wang to further implement triggering a teardown procedure for the DCU container in the case of detecting malicious actions for at least the purpose of preventing malicious code or actors from continuing to compromise sensitive data (e.g., in response to detecting code for exfiltrating data or a user attempting to exfiltrate data). Rahmat-Wang does not specify: allowing an authorized administrator to override the disablement of the at least one data access proxy. However, Rahmat-Wang-Sislow in view of Goodson discloses: allowing an authorized administrator to override the disablement of the at least one data access proxy. Refer to at least [0040] of Goodson with respect to a system administrator overriding disabling a device (where it was disabled responsive to security risk as in the abstract or Goodson). The teachings of Goodson likewise concern protecting data centers and terminating devices responsive to security risk, and are considered to be reasonably pertinent to the particular problem with which the inventor was concerned. Therefore it would have been obvious to one of ordinary skill in the art before the filing date of Applicant’s invention to modify the teachings of Rahmat-Wang-Sislow to further include allowing an administrator to override security actions because the particular known technique was recognized as part of the ordinary capabilities of one skilled in the art (administrators being able to override settings and actions). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Any inquiry concerning this communication or earlier communications from the examiner should be directed to VADIM SAVENKOV whose telephone number is (571)270-5751. The examiner can normally be reached 12PM-8PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey L Nickerson can be reached at (469) 295-9235. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /Jeffrey Nickerson/Supervisory Patent Examiner, Art Unit 2432 /V.S/ Examiner, Art Unit 2432
Read full office action

Prosecution Timeline

Mar 17, 2025
Application Filed
Sep 25, 2025
Response after Non-Final Action
Sep 22, 2026
Non-Final Rejection mailed — §101, §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12639449
SYSTEM AND METHOD FOR SCANNING CONTAINERS FOR VULNERABILITIES
2y 4m to grant Granted May 26, 2026
Patent 12632534
ACCESSING SECURE SYSTEM RESOURCES BY LOW PRIVILEGE PROCESSES
7y 12m to grant Granted May 19, 2026
Patent 12613999
DETECTING ELECTRONIC SYSTEM MODIFICATION
6y 10m to grant Granted Apr 28, 2026
Patent 12608482
DETERMINING A SECURITY SCORE IN BINARY SOFTWARE CODE
6y 5m to grant Granted Apr 21, 2026
Patent 12608501
Privacy-Preserving Log Analysis
5y 11m to grant Granted Apr 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
61%
Grant Probability
81%
With Interview (+20.3%)
3y 5m (~1y 10m remaining)
Median Time to Grant
Low
PTA Risk
Based on 318 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month