Prosecution Insights
Last updated: August 17, 2026
Application No. 19/090,809

SYSTEMS AND METHODS FOR MACHINE LEARNING ASSISTED AUTHORIZATION POLICY RECOMMENDATIONS

Non-Final OA §102§103
Filed
Mar 26, 2025
Priority
May 20, 2024 — provisional 63/649,489
Examiner
HAJIABBASI, AMIR MAHDI
Art Unit
Tech Center
Assignee
CyberArk Software Ltd.
OA Round
1 (Non-Final)
86%
Grant Probability
Favorable
1-2
OA Rounds
1y 2m
Est. Remaining
95%
With Interview

Examiner Intelligence

Grants 86% — above average
86%
Career Allowance Rate
24 granted / 28 resolved
+25.7% vs TC avg
Moderate +9% lift
Without
With
+8.9%
Interview Lift
resolved cases with interview
Typical timeline
2y 6m
Avg Prosecution
9 currently pending
Career history
39
Total Applications
across all art units

Statute-Specific Performance

§101
4.8%
-35.2% vs TC avg
§103
60.3%
+20.3% vs TC avg
§102
13.5%
-26.5% vs TC avg
§112
16.7%
-23.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 28 resolved cases

Office Action

§102 §103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Information Disclosure Statement The information disclosure statement (IDS) submitted on 7/6/2026 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Claim Rejections - 35 USC § 102 The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action: A person shall be entitled to a patent unless – (a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention. Claim(s) 1-3, 5, 9, 11-13, 15, and 16 is/are rejected under 35 U.S.C. 102(a)(2) as being anticipated by Kunchakarra (Kunchakarra et al., US 12541726 B1). Claim 1: Kunchakarra teaches a non-transitory computer readable medium including instructions that, when executed by at least one processor, cause the at least one processor to perform operations for developing machine-learning authorization policy recommendations, comprising: receive input data for an organization; pre-process the input data (4:48-50, 3:59-62; contextual inputs are received from user, contents related to an organization are extracted from data sources according to the contextual inputs); wherein the pre-processing includes a feedback loop to update the input data by providing feedback to the organization (63:54-65, 68:55-59; using feedback, the AI engine is iteratively re-trained (input data is updated for training the ML for more accurate results to give to the organization)); generate, using a machine learning model, at least one authorization policy recommendation based on the input data (3:62-4:6; from the contents, the artificial intelligence engine determines the 'job description', i.e. access levels, roles and responsibilities, etc. (authorization policy). See also 21:29-36), wherein the machine learning model is trained using at least one of: an organizational attribute, an organizational action, an organization policy, or domain information (56:4-8; the model is trained and re-trained based on organizational changes, policies, standards, etc. (organizational attribute/action/policy)); provide the at least one authorization policy recommendation to the organization; identify a status of the at least one authorization policy recommendation, wherein the status comprises at least one organizational feedback (63:66-64:14; the job description is displayed to the users, and the users give approval, refusal, and/or edits/updates (identified status) for the job descriptions (organizational feedback)); and iteratively update the machine learning model based on the identified status (63:54-65, 68:55-59; using the feedback, the AI engine is iteratively re-trained (updated)). Claim 2: Kunchakarra teaches the non-transitory computer-readable medium of claim 1, wherein the at least one authorization policy recommendation is automatically enforced by applying the at least one authorization policy recommendation to a network environment associated with the organization (47:24-37; the roles and policies regarding privileges and access control are automatically enforced. 57:58-61; the access level refers to privileges within a network. See also 44:40-47). Claim 3: Kunchakarra teaches the non-transitory computer-readable medium of claim 1, wherein the at least one authorization policy recommendation is automatically enforced if at least one predetermined condition is met (47:24-37; the roles and policies regarding privileges and access control are automatically enforced by comparing them with a baseline and determining whether they have excessive privileges or not (predetermined condition). See also 44:40-47). Claim 5: Kunchakarra teaches the non-transitory computer-readable medium of claim 1, further comprising using at least one other machine learning model (4:23-24; there are multiple large language models in the artificial intelligence engine). Claim 9: Kunchakarra teaches the non-transitory computer-readable medium of claim 1, wherein the pre- processing further comprises cleaning the input data using predetermined rules (68:37-40, "Data Preprocessing: Clean the dataset by removing duplicates, irrelevant information, or inconsistencies. Normalize text, remove special characters, and perform tokenization to prepare the data for analysis."). Claim 11: Kunchakarra teaches the non-transitory computer-readable medium of claim 1, wherein the identifying comprises accepting, ignoring, or rejecting the at least one authorization policy recommendation via a user interface (63:66-64:14; the job description is displayed to the users, and the users give approval, refusal, and/or edits/updates (identified status) for the job descriptions). Claim 12: Kunchakarra teaches the non-transitory computer-readable medium of claim 11, wherein the identifying further comprises providing feedback based on the accepting, ignoring, or rejecting via the user interface (63:66-64:14; the job description is displayed to the users, and the users give approval, refusal, and/or edits/updates for the job descriptions (organizational feedback)). Claim 13: Kunchakarra teaches the non-transitory computer-readable medium of claim 12, wherein the identifying further comprises using the feedback for the machine learning model (63:54-65, 68:55-59; using the feedback, the AI engine is iteratively re-trained (updated)). Claim 15: Kunchakarra teaches the non-transitory computer-readable medium of claim 1, wherein the identifying occurs in real-time (49:65-50:1, "The system adapts continuously to changes to job role or service task changes and/or spatial and temporal information and updates the MRRD in real-time or near real-time."). Claim 16: Kunchakarra teaches the non-transitory computer-readable medium of claim 1, wherein the identifying further comprises reinforcing the at least one authorization policy recommendation if the organization accepts the recommendation (59:7-10, 46-48; approved changes to policies are implemented. See also 65:2-46). Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 4 is/are rejected under 35 U.S.C. 103 as being unpatentable over Kunchakarra as applied to claim 1 above, and further in view of Ren (Ren et al., US 20240146740 A1). Claim 4: Kunchakarra teaches the non-transitory computer-readable medium of claim 1, wherein the identified status further comprises an acceptance rate of the at least one authorization policy recommendation by the organization (64:6-12; the system receives the approval or refusal (status) for the job descriptions (authorization policy recommendation) from one or more users. More than one user indicates that some may approve (accept) and some may refuse, such that the received data indicates the proportion of approvals to refusals (acceptance rate)). However, Kunchakarra does not explicitly teach but, in an analogous art, Ren teaches that the identified status further comprises calculation of an acceptance rate (¶330, ¶335; the proportion of constraint actions in the plurality of access policies are calculated to determine which one restricts the most (acceptance rate)) It would be obvious to one of ordinary skill in the art prior to the effective filing date of the claimed invention to modify Kunchakarra using Ren to calculate the acceptance rate of the authorization policy recommendation because it would improve the invention by letting the invention know how popular an authorization policy is among the various users. Claim(s) 6 and 7, and 14 is/are rejected under 35 U.S.C. 103 as being unpatentable over Kunchakarra as applied to claim 1 and 12 above, and further in view of Baghdadi (Baghdadi et al., US 12652307 B1). Claim 6: Kunchakarra teaches the non-transitory computer-readable medium of claim 1. Kunchakarra does not explicitly teach but, in an analogous art, Baghdadi teaches that the machine learning model uses a ranking system for the training (10:10-19; the CVSS, a ranking system that can be used to determine the level of vulnerability of a system according to possible attacks from access control, is used to prepare the training data). It would be obvious to one of ordinary skill in the art prior to the effective filing date of the claimed invention to modify Kunchakarra using Baghdadi to use a ranking system for the training of a machine learning model because it allows for responders to prioritize vulnerabilities, such as malicious access (Baghdadi, 4:61-63, 10:19-27) Claim 7: Kunchakarra in view of Baghdadi teaches the non-transitory computer-readable medium of claim 6. Baghdadi further teaches that the ranking further comprises using at least one of a maturity level of the organization, best practices for an organization, or an organizational system configuration (Baghdadi, 10:10-19; the CVSS is considered a suitable system out of any suitable industry standard (best practices))(see claim 6 for motivation to combine). Claim 14: Kunchakarra teaches the non-transitory computer-readable medium of claim 12. Kunchakarra does not explicitly teach but, in an analogous art, Baghdadi teaches the use of feedback to train against a machine learning model (17:48-54), where the machine learning model is used to develop recommended countermeasures against vulnerabilities (10:47-53) and obtain the optimal policy (8:4-8, "reinforcement learning algorithms that obtain an optimal policy by choosing the action that produces the highest state-action value. DON is often a best fit for discrete state space, which may be the case in the problem described herein."), such that the feedback is used to mitigate against diversion from best practices. It would be obvious to one of ordinary skill in the art prior to the effective filing date of the claimed invention to modify Kunchakarra using Baghdadi to use feedback to mitigate against diversion from best practices because it would allow for the model to choose the optimal policy for security (Baghdadi, 8:4-8) Claim(s) 8 is/are rejected under 35 U.S.C. 103 as being unpatentable over Kunchakarra as applied to claim 1 above, and further in view of Manuel-Devadoss (US 20230283643 A1, cited in IDS). Claim 8: Kunchakarra teaches the non-transitory computer-readable medium of claim 1. Kunchakarra does not explicitly teach but, in an analogous art, Manuel-Devadoss teaches that a machine learning model implements at least one of unsupervised learning, semi-supervised learning, active learning, or reinforcement learning techniques (¶58; the system performs deep reinforcement learning to identify a security policy (analogous to authorization policy)). It would be obvious to one of ordinary skill in the art prior to the effective filing date of the claimed invention to modify Kunchakarra using Manuel-Devadoss to implement reinforcement learning into the machine learning model because it would allow the neural network to pick options that comply with more data security requirements (Manuel-Devadoss, ¶67) Claim(s) 10 is/are rejected under 35 U.S.C. 103 as being unpatentable over Kunchakarra as applied to claim 1 above, and further in view of Chang (Chang et al., US 20180314573 A1). Claim 10: Kunchakarra teaches the non-transitory computer-readable medium of claim 1. Kunchakarra does not explicitly teach but, in an analogous art, Chang teaches that pre-processing further comprises outlier detection of the input data (¶93, "… the pre-processing includes domain knowledge 607 and machine learning methods to clean data 612, detect outliers 614, impute missing entries 616, and process the data 618 from each data source.… the outlier detection includes identification of outliers for removal and/or normalization via statistical clustering, nearest neighbor, classification, and the like."). It would be obvious to one of ordinary skill in the art prior to the effective filing date of the claimed invention to modify Kunchakarra using Chang to perform outlier detection as part of the pre-processing because it would allow for the outliers to be removed (Chang, ¶119). Claim(s) 17 and 18 is/are rejected under 35 U.S.C. 103 as being unpatentable over Kunchakarra as applied to claim 1 above, and further in view of Hurry (Hurry et al., US 20190122006 A1) . Claim 17: Kunchakarra teaches the non-transitory computer-readable medium of claim 1. Kunchakarra does not explicitly teach but, in an analogous art, Hurry teaches that the at least one authorization policy recommendation comprises a confidence level (¶50; depending on whether the likelihood determine by an authorization engine is greater than or equal to a threshold (confidence level), a recommendation for authorization is given or not. See also ¶16, "If the likelihood is greater than a threshold value (e.g., indicating a confident prediction of the user's intent), the security system may provide a recommendation to the user to provide the authorization for the given entity."). It would be obvious to one of ordinary skill in the art prior to the effective filing date of the claimed invention to modify Kunchakarra using Hurry to have a confidence level be a part of the authorization policy recommendation because it allows for adaptive learning of authorization levels for information (Hurry, ¶15, ¶16) Claim 18: Kunchakarra in view of Hurry teaches the non-transitory computer-readable medium of claim 17. Hurry further teaches that the confidence level comprises a categorical level and a probabilistic level (¶50, "… responsive to the authorization engine 220 determining that the likelihood is greater than a first threshold value, the authorization engine 220 automatically updates the authorization database record to authorize the given entity to access the given data object. … responsive to the authorization engine 220 determining that the likelihood is less than or equal to the first threshold value, and greater than a second threshold value, the authorization engine 220 generates a recommendation for the authorization. The first threshold value may be greater than the second threshold value"; the likelihood (probabilistic level) is calculated, and is categorized as being above the thresholds, below, or between (categorical level)) (see claim 17 for motivation to combine). Claim(s) 19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Kunchakarra in view of Amir-Siddiqi (AMIR-SIDDIQI et al., US 20230199074 A1). Claim 19: Kunchakarra teaches a computer-implemented method for developing machine-learning authorization policy recommendations, the method comprising: receiving input data for an organization; pre-processing the input data (4:48-50, 3:59-62; contextual inputs are received from user, contents related to an organization are extracted from data sources according to the contextual inputs); wherein the pre-processing includes a feedback loop to update the input data by providing feedback to the organization (63:54-65, 68:55-59; using feedback, the AI engine is iteratively re-trained (input data is updated for training the ML for more accurate results to give to the organization)); generating, using a machine learning model, at least one authorization policy recommendation based on the input data (3:62-4:6; from the contents, the artificial intelligence engine determines the 'job description', i.e. access levels, roles and responsibilities, etc. (authorization policy). See also 21:29-36), wherein the machine learning model is trained using at least one of: an organizational attribute, an organizational action, an organization policy, or domain information (56:4-8; the model is trained and re-trained based on organizational changes, policies, standards, etc. (organizational attribute/action/policy)); providing the at least one authorization policy recommendation to the organization; identifying a status of the at least one authorization policy recommendation, wherein the status comprises at least one organizational feedback (63:66-64:14; the job description is displayed to the users, and the users give approval, refusal, and/or edits/updates (identified status) for the job descriptions (organizational feedback)); iteratively updating the machine learning model based on the identified status on a predetermined basis (63:54-65, 68:55-59; using the feedback, the AI engine is iteratively re-trained (updated) to improve it (on a predetermined basis)); and providing an updated at least one authorization policy (63:61-65; the job descriptions are refined (updating the authorization policy)). Kunchakarra does not explicitly teach but, in an analogous art, Amir-Siddiqi teaches providing an updated at least one authorization policy to a user interface based on the iterative update (¶39, "This enables the system 100 to determine, at a given point-in-time, what entitlements should be extended or removed from a user profile. The use of these models can enable the system 100 to evolve over time, using a “feedback loop” of user activities and system decisions, to ensure that access controls are appropriately assigned, maintained, and governed."; the model and access controls are improved with a feedback loop (iterative update). ¶20, "In some implementations, results and statuses related to the system 100 and operations thereof may be displayed to the user via the display 113. For example, in some instances, an administrator can input new user profile to the system 100, and in response, the system 100 can identify and display entitlements associated with the usage of the computer network for the new user."; the new entitlements (updated authorization policies) are presented via user display to a user). It would be obvious to one of ordinary skill in the art prior to the effective filing date of the claimed invention to modify Kunchakarra using Amir-Siddiqi to display an updated authorization policy because it would enhance the user's ability to understand the new policies. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Yuan (YUAN, US 20190190959 A1) teaches predicting a reasonableness value of an authorization policy using an authorization policy optimization value (¶40, ¶52) Sethi (Sethi et al., US 20250123915 A1) teaches adapting access control policies using a reinforcement learning process (¶44), implementing a feedback loop to perform additional training for the machine learning algorithms (¶45, ¶87) Ford (Ford et al., US 20250343796 A1) teaches determining recommended access permissions of a target user, such as obtaining administrative review of the access permissions (Abstract, ¶31) by using machine learning algorithms and an iterative feedback loop (¶37, ¶38). Kliger (KLIGER et al., US 20200053090 A1) teaches automatically generating access control rules for user accesses to a computer resource, implementing a training data set (¶7). Any inquiry concerning this communication or earlier communications from the examiner should be directed to AMIR MAHDI HAJIABBASI whose telephone number is (703)756-5511. The examiner can normally be reached M-F 7:30-5 EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Catherine Thiaw can be reached at (571) 270-1138. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /A.M.H./ Amir Mahdi HajiabbasiExaminer, Art Unit 2407 /Catherine Thiaw/Supervisory Patent Examiner, Art Unit 2407 7/21/2026
Read full office action

Prosecution Timeline

Mar 26, 2025
Application Filed
Jul 23, 2026
Non-Final Rejection mailed — §102, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12705340
DETECTION OF MALICIOUS DIRECT MEMORY ACCESS DEVICE USED FOR DIRECT DEVICE ASSIGNMENT
2y 9m to grant Granted Aug 11, 2026
Patent 12682071
Software Security Defect Prediction Methods and Devices
2y 5m to grant Granted Jul 14, 2026
Patent 12682045
FAULT-ATTACK ANALYSIS DEVICE AND METHOD
2y 7m to grant Granted Jul 14, 2026
Patent 12670266
SECURE MULTI-PARTY COMPUTATION
2y 9m to grant Granted Jun 30, 2026
Patent 12664270
CONNECTED ASSET RISK MANAGEMENT
2y 3m to grant Granted Jun 23, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
86%
Grant Probability
95%
With Interview (+8.9%)
2y 6m (~1y 2m remaining)
Median Time to Grant
Low
PTA Risk
Based on 28 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month