Prosecution Insights
Last updated: August 17, 2026
Application No. 19/092,316

SOFTWARE-AS-A-SERVICE USAGE MONITORING WITH SECURE BROWSER OR BROWSER ENVIRONMENT

Non-Final OA §103§112
Filed
Mar 27, 2025
Priority
Apr 22, 2021 — provisional 63/177,998 +1 more
Examiner
WADE-WRIGHT, SHAQUEAL D
Art Unit
Tech Center
Assignee
Palo Alto Networks Inc.
OA Round
1 (Non-Final)
85%
Grant Probability
Favorable
1-2
OA Rounds
11m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 85% — above average
85%
Career Allowance Rate
386 granted / 454 resolved
+25.0% vs TC avg
Strong +18% interview lift
Without
With
+18.2%
Interview Lift
resolved cases with interview
Typical timeline
2y 4m
Avg Prosecution
20 currently pending
Career history
466
Total Applications
across all art units

Statute-Specific Performance

§101
15.9%
-24.1% vs TC avg
§103
48.7%
+8.7% vs TC avg
§102
7.8%
-32.2% vs TC avg
§112
18.1%
-21.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 454 resolved cases

Office Action

§103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Information Disclosure Statement The information disclosure statement (IDS) submitted on 06/12/2025 was filed after the is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Claim Objections Claims 4, 11 and 18 are objected to because of the following informalities: The claims recite the acronym “OAuth” without spelling out the acronym at its first occurrence. The Examiner suggest the acronym to be spelled out to recite “Open Authorization” at its first occurrence. Appropriate correction is required. Claim Rejections - 35 USC § 112 The following is a quotation of the first paragraph of 35 U.S.C. 112(a): (a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention. The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112: The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention. Claims 8-20 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. The claims 8-14 recite the limitation “a non-transitory, machine-readable medium having stored thereon program code comprising instructions”, and claims 15-20 recite the limitations “processor” and “machine-readable medium having stored thereon program code comprising instructions executable by the processor”, however, the specification is void of any medium or program code and processor with in an apparatus. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer. Claims 1, 8 and 15 are provisionally rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1 and 18 of copending Application No. 19/195,964 in view of Chauhan et al. (US Pub No. 2020/0145425). The claims of the copending application teaches each and every claim limitation of the instant application but does not explicitly teach usage of Software-as-a-Service applications (SaaS). However, Chauhan teaches usage of Software-as-a-Service applications (SaaS) (Chauhan, page 10, paragraphs 0103-0104 & page 13, paragraph 0124; access policies and manage/monitor network applications (SaaS application)). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify the copending application with the teachings of Chauhan to monitor and manage network applications to provide the advantage of preventing potential misuse of resources (Chauhan, page 1, paragraph 0002). This is a provisional nonstatutory double patenting rejection. Independent claims 1 & 18 of the copending application are mapped to independent claims 1, 8 & 15 of the instant application. Co-Pending Application 19/195,964 Instant Application 19/092,316 1. A method comprising: verifying, by a backend of an organization, a web browser on an endpoint that hosts a first environment that comprises the web browser; 1. A method comprising: verifying, by a backend of an organization, a web browser on an endpoint that hosts a first environment that comprises the web browser; communicating, by the backend to at least one of the first environment and the web browser, one or more security policies of the organization after verifying the web browser; and communicating, by the backend to at least one of the first environment and the web browser, one or more security policies of the organization after verifying the web browser; and managing, with the first environment and/or the web browser, at least one of activity in the first environment and activity of the web browser based, at least in part, on the one or more security policies. monitoring and managing, with at least one of the first environment and the web browser, usage of Software-as-a-Service applications (SaaS) based, at least in part, on the one or more security policies. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims (s) 1, 3, 8, 10, 15 and 17 are rejected under 35 U.S.C. 103 as being unpatentable over Chauhan et al. (US Pub No. 2020/0145425) in view of Wilson et al. (US Patent No. 8,347,349). Regarding independent claim 1, Chauhan teaches a method comprising: verifying, by a backend of an organization, a web browser on an endpoint that hosts a first environment that comprises the web browser (Chauhan, page 3, paragraph 0050, page 4, paragraphs 0055-0057, page 10, paragraph 0099 and page 13, paragraphs 0120-0121; client device with managed and unmanaged partitions including a client application with embedded browser; authentication of the user and client application); communicating, by the backend to at least one of the first environment and the web browser, one or more security policies of the organization the web browser (Chauhan, page 10, paragraphs 0103-0104; client application obtain various policies from network devices/gateway to manage network application); and monitoring and managing, with at least one of the first environment and the web browser, usage of Software-as-a-Service applications (SaaS) based, at least in part, on the one or more security policies (Chauhan, page 10, paragraphs 0103-0104; client application access policies and mange/control network application (SaaS applications)). Chauhan teaches the client application obtaining policies from the network and authenticating the client application & providing network applications based on the authentication (Chauhan, page 10, paragraphs 0103-0104 and page 13, paragraphs 0120-0121) but does not explicitly teach communicating, by the backend to at least one of the first environment and the web browser, one or more security policies of the organization after verifying the web browser. Wilson teaches communicating, by the backend to at least one of the first environment and the web browser, one or more security policies of the organization after verifying the web browser (Wilson, column 7, lines 40-column 8, line 35; after verification of the credential transmitting browser policy data). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Chauhan with the teachings of Wilson to obtain browser policies after verification to provide the advantage of secure distribution of enterprise policy data (Wilson, column 1, lines 20-52). Regarding claim 3, Chauhan in view of Wilson teaches the method wherein monitoring usage of SaaS applications further comprises tracking at least one of use of the SaaS applications and resources of the organization involved in use of the SaaS applications (Chauhan, page 10, paragraph 0104 and page 17, paragraph 0161-0162). Regarding independent claim 8, Chauhan teaches a non-transitory, machine-readable medium having stored thereon program code comprising instructions to: authenticate a web browser with a backend of an organization (Chauhan, page 3, paragraph 0050, page 4, paragraphs 0055-0057, page 10, paragraph 0099 and page 13, paragraphs 0120-0121; client device with managed and unmanaged partitions including a client application with embedded browser; authentication of the user and client application); obtain from the backend one or more security policies of the organization the web browser (Chauhan, page 10, paragraphs 0103-0104; client application obtain various policies from network devices/gateway to manage network application); and monitor and manage, with at least the web browser, usage of Software-as-a-Service applications (SaaS) based, at least in part, on the one or more security policies (Chauhan, page 10, paragraphs 0103-0104; client application access policies and mange/control network application). Chauhan teaches the client application obtaining policies from the network and authenticating the client application & providing network applications based on the authentication (Chauhan, page 10, paragraphs 0103-0104 and page 13, paragraphs 0120-0121) but does not explicitly teach obtain from the backend one or more security policies of the organization the web browser after authentication of the web browser. Wilson teaches obtain from the backend one or more security policies of the organization the web browser after authentication of the web browser (Wilson, column 7, lines 40-column 8, line 35; after verification of the credential transmitting browser policy data). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Chauhan with the teachings of Wilson to obtain browser policies after verification to provide the advantage of secure distribution of enterprise policy data (Wilson, column 1, lines 20-52). Regarding claim 10, Chauhan in view of Wilson teaches the non-transitory, machine-readable medium wherein the instructions to monitor usage of SaaS applications further comprise instructions to track at least one of use of the SaaS applications and resources of the organization involved in use of the SaaS applications (Chauhan, page 10, paragraph 0104 and page 17, paragraph 0161-0162). Regarding independent claim 15, Chauhan teaches an apparatus comprising: a processor; and a machine-readable medium having stored thereon instructions executable by the processor to cause the apparatus to: authenticate a web browser with a backend of an organization (Chauhan, page 3, paragraph 0050, page 4, paragraphs 0055-0057, page 10, paragraph 0099 and page 13, paragraphs 0120-0121; client device with managed and unmanaged partitions including a client application with embedded browser; authentication of the user and client application); obtain from the backend one or more security policies of the organization the web browser (Chauhan, page 10, paragraphs 0103-0104; client application obtain various policies from network devices/gateway to manage network application); and monitor and manage, with at least the web browser, usage of Software-as-a-Service applications (SaaS) based, at least in part, on the one or more security policies (Chauhan, page 10, paragraphs 0103-0104; client application access policies and mange/control network application). Chauhan teaches the client application obtaining policies from the network and authenticating the client application & providing network applications based on the authentication (Chauhan, page 10, paragraphs 0103-0104 and page 13, paragraphs 0120-0121) but does not explicitly teach obtain from the backend one or more security policies of the organization the web browser after authentication of the web browser. Wilson teaches obtain from the backend one or more security policies of the organization the web browser after authentication of the web browser (Wilson, column 7, lines 40-column 8, line 35; after verification of the credential transmitting browser policy data). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Chauhan with the teachings of Wilson to obtain browser policies after verification to provide the advantage of secure distribution of enterprise policy data (Wilson, column 1, lines 20-52). Regarding claim 17, Chauhan in view of Wilson teaches the apparatus wherein the instructions to monitor usage of SaaS applications further comprise instructions executable by the processor to cause the apparatus to track at least one of use of the SaaS applications and resources of the organization involved in use of the SaaS applications (Chauhan, page 10, paragraph 0104 and page 17, paragraph 0161-0162). Claim(s) 2, 9 and 16 are rejected under 35 U.S.C. 103 as being unpatentable over Chauhan et al. (US Pub No. 2020/0145425) in view of Wilson et al. (US Patent No. 8,347,349) as applied to claims 1, 3, 8, 10, 15 and 17 above, and further in view of Boyer et al. (US Pub No. 2021/0273957). Regarding claim 2, Chauhan in view of Wilson teaches each and every claim limitation of claim 1. Chauhan in view of Wilson does not explicitly teach the method wherein monitoring usage of SaaS applications comprises tracking which of the SaaS applications are accessed with personal credentials and which of the SaaS applications are accessed with credentials of the organization. Boyer teaches wherein monitoring usage of SaaS applications comprises tracking which of the SaaS applications are accessed with personal credentials and which of the SaaS applications are accessed with credentials of the organization (Boyer, page 10, paragraph 0113, page 12, paragraphs 0131 & 0134, and page 15, paragraph 0163; user login activity). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Chauhan in view of Wilson with the teachings of Boyer to analyzing user & network behavior to provide the advantage of preventing cyber threats (Boyer, page 1, paragraphs 0004-0005). Regarding claim 9, Chauhan in view of Wilson teaches each and every claim limitation of claim 8. Chauhan in view of Wilson does not explicitly teach the non-transitory, machine-readable medium wherein the instructions to monitor usage of SaaS applications comprise instructions to track which of the SaaS applications are accessed with personal credentials and which of the SaaS applications are accessed with credentials of the organization. Boyer teaches wherein the instructions to monitor usage of SaaS applications comprise instructions to track which of the SaaS applications are accessed with personal credentials and which of the SaaS applications are accessed with credentials of the organization (Boyer, page 10, paragraph 0113, page 12, paragraphs 0131 & 0134, and page 15, paragraph 0163; user login activity). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Chauhan in view of Wilson with the teachings of Boyer to analyzing user & network behavior to provide the advantage of preventing cyber threats (Boyer, page 1, paragraphs 0004-0005). Regarding claim 16, Chauhan in view of Wilson teaches each and every claim limitation of claim 15. Chauhan in view of Wilson does not explicitly teach the apparatus wherein the instructions to monitor usage of SaaS applications comprise instructions to track which of the SaaS applications are accessed with personal credentials and which of the SaaS applications are accessed with credentials of the organization. Boyer teaches wherein the instructions to monitor usage of SaaS applications comprise instructions to track which of the SaaS applications are accessed with personal credentials and which of the SaaS applications are accessed with credentials of the organization (Boyer, page 10, paragraph 0113, page 12, paragraphs 0131 & 0134, and page 15, paragraph 0163; user login activity). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Chauhan in view of Wilson with the teachings of Boyer to analyzing user & network behavior to provide the advantage of preventing cyber threats (Boyer, page 1, paragraphs 0004-0005). Claim(s) 4, 11 and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Chauhan et al. (US Pub No. 2020/0145425) in view of Wilson et al. (US Patent No. 8,347,349) as applied to claims 1, 3, 8, 10, 15 and 17 above, and further in view of Cohen et al. (US Pub No. 2015/0135302). Regarding claim 4, Chauhan in view of Wilson teaches each and every claim limitation of claim 1. Chauhan in view of Wilson does not explicitly teach the method wherein monitoring usage of SaaS applications comprises monitoring OAuth requests and connections and identifying third party SaaS applications being used based on monitoring the OAuth requests and connections. Cohen teaches wherein monitoring usage of SaaS applications comprises monitoring OAuth requests and connections and identifying third party SaaS applications being used based on monitoring the OAuth requests and connections (Cohen, page 2, paragraph 0039, page 3, paragraph 0047, and page 4, paragraph 0077; track request for OAuth token to identify SaaS application and enforce redirection or enforcements). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Chauhan in view of Wilson with the teachings of Cohen to monitor request to provide the advantage of ensuring network traffic captivation (Cohen, page 1, paragraph 0003). Regarding claim 11, Chauhan in view of Wilson teaches each and every claim limitation of claim 8. Chauhan in view of Wilson does not explicitly teach the non-transitory, machine-readable medium wherein the instructions to monitor usage of SaaS applications comprises instructions to monitor OAuth requests and connections and identify third party SaaS applications being used based on monitoring the OAuth requests and connections. Cohen teaches wherein the instructions to monitor usage of SaaS applications comprises instructions to monitor OAuth requests and connections and identify third party SaaS applications being used based on monitoring the OAuth requests and (Cohen, page 2, paragraph 0039, page 3, paragraph 0047, and page 4, paragraph 0077; track request for OAuth token to identify SaaS application and enforce redirection or enforcements). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Chauhan in view of Wilson with the teachings of Cohen to monitor request to provide the advantage of ensuring network traffic captivation (Cohen, page 1, paragraph 0003). Regarding claim 18, Chauhan in view of Wilson teaches each and every claim limitation of claim 15. Chauhan in view of Wilson does not explicitly teach the apparatus wherein the instructions to monitor usage of SaaS applications comprises instructions to monitor OAuth requests and connections and identify third party SaaS applications being used based on monitoring the OAuth requests and connections. Cohen teaches wherein the instructions to monitor usage of SaaS applications comprises instructions to monitor OAuth requests and connections and identify third party SaaS applications being used based on monitoring the OAuth requests and (Cohen, page 2, paragraph 0039, page 3, paragraph 0047, and page 4, paragraph 0077; track request for OAuth token to identify SaaS application and enforce redirection or enforcements). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Chauhan in view of Wilson with the teachings of Cohen to monitor request to provide the advantage of ensuring network traffic captivation (Cohen, page 1, paragraph 0003). Claim(s) 5, 12 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Chauhan et al. (US Pub No. 2020/0145425) in view of Wilson et al. (US Patent No. 8,347,349) as applied to claims 1, 3, 8, 10, 15 and 17 above, and further in view of Xu et al. (US Pub No. 2022/0116345). Regarding claim 5, Chauhan in view of Wilson teaches each and every claim limitation of claim 1. Chauhan in view of Wilson does not explicitly teach the method wherein managing usage of SaaS applications comprises at last one of: executing requests to a Software-as-a-Service (SaaS) application on behalf of a user if an application programming interface (API) is unavailable for the SaaS application; and using API keys to administer the SaaS application. Xu teaches wherein managing usage of SaaS applications comprises at last one of: executing requests to a Software-as-a-Service (SaaS) application on behalf of a user if an application programming interface (API) is unavailable for the SaaS application; and using API keys to administer the SaaS application (Xu, page 5, paragraphs 0053; authenticate users to SaaS resources based on API keys). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Chauhan in view of Wilson with the teachings of Xu for authentication using API keys to provide the advantage of improving state sharing plug in for workspace environments (Xu, page 1, paragraph 0003). Regarding claim 12, Chauhan in view of Wilson teaches each and every claim limitation of claim 8. Chauhan in view of Wilson does not explicitly teach the non-transitory, machine-readable medium wherein the instructions to manage usage of SaaS applications comprise at last one of: instructions to execute requests to a Software-as-a-Service (SaaS) application on behalf of a user if an application programming interface (API) is unavailable for the SaaS application; and instructions to use API keys to administer the SaaS application. Xu teaches wherein the instructions to manage usage of SaaS applications comprise at last one of: instructions to execute requests to a Software-as-a-Service (SaaS) application on behalf of a user if an application programming interface (API) is unavailable for the SaaS application; and instructions to use API keys to administer the SaaS application (Xu, page 5, paragraphs 0053; authenticate users to SaaS resources based on API keys). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Chauhan in view of Wilson with the teachings of Xu for authentication using API keys to provide the advantage of improving state sharing plug in for workspace environments (Xu, page 1, paragraph 0003). Regarding claim 19, Chauhan in view of Wilson teaches each and every claim limitation of claim 15. Chauhan in view of Wilson does not explicitly teach the apparatus wherein the instructions to manage usage of SaaS applications comprise at last one of: instructions to execute requests to a Software-as-a-Service (SaaS) application on behalf of a user if an application programming interface (API) is unavailable for the SaaS application; and instructions to use API keys to administer the SaaS application. Xu teaches wherein the instructions to manage usage of SaaS applications comprise at last one of: instructions to execute requests to a Software-as-a-Service (SaaS) application on behalf of a user if an application programming interface (API) is unavailable for the SaaS application; and instructions to use API keys to administer the SaaS application (Xu, page 5, paragraphs 0053; authenticate users to SaaS resources based on API keys). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Chauhan in view of Wilson with the teachings of Xu for authentication using API keys to provide the advantage of improving state sharing plug in for workspace environments (Xu, page 1, paragraph 0003). Claim(s) 6-7, 13-14 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Chauhan et al. (US Pub No. 2020/0145425) in view of Wilson et al. (US Patent No. 8,347,349) and further in view of Xu et al. (US Pub No. 2022/0116345) as applied to claims 5, 12 & 19 above, and further in view of Boyer et al. (US Pub No. 2021/0273957). Regarding claim 6, Chauhan in view of Wilson and in further view of Xu teaches each and every claim limitation of claim 5. Chauhan in view of Wilson and in further view of Xu does not explicitly teach the method wherein managing usage of SaaS applications further comprises at least one of analyzing configurations of the SaaS application and scanning for persistence of exploits of the SaaS application. Boyer teaches wherein managing usage of SaaS applications further comprises at least one of analyzing configurations of the SaaS application and scanning for persistence of exploits of the SaaS application (Boyer, page 17, paragraphs 0179-0183 and page 18, paragraph 0195). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Chauhan in view of Wilson and in further view of Xu with the teachings of Boyer to analyzing user & network behavior to provide the advantage of preventing cyber threats (Boyer, page 1, paragraphs 0004-0005). Regarding claim 7, Chauhan in view of Wilson, in further view of Xu and in further view of Boyer teaches each and every claim limitation of claim 6, however, Boyer teaches the method wherein analyzing configurations comprises analyzing forwarding rules and alias rules of an e-mail SaaS application (Boyer, page 17, paragraphs 0179-0183 and page 18, paragraph 0195). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Chauhan in view of Wilson, in further view of Xu and in further view of Boyer with the teachings of Boyer to analyzing user & network behavior to provide the advantage of preventing cyber threats (Boyer, page 1, paragraphs 0004-0005). Regarding claim 13, Chauhan in view of Wilson and in further view of Xu teaches each and every claim limitation of claim 12. Chauhan in view of Wilson and in further view of Xu does not explicitly teach the non-transitory, machine-readable medium wherein the instructions to manage usage of SaaS applications further comprise instructions to, at least one of, analyze configurations of the SaaS application and scan for persistence of exploits of the SaaS application. Boyer teaches wherein the instructions to manage usage of SaaS applications further comprise instructions to, at least one of, analyze configurations of the SaaS application and scan for persistence of exploits of the SaaS application (Boyer, page 17, paragraphs 0179-0183 and page 18, paragraph 0195). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Chauhan in view of Wilson and in further view of Xu with the teachings of Boyer to analyzing user & network behavior to provide the advantage of preventing cyber threats (Boyer, page 1, paragraphs 0004-0005). Regarding claim 14, Chauhan in view of Wilson, in further view of Xu and in further view of Boyer teaches each and every claim limitation of claim 13, however, Boyer teaches the non-transitory, machine-readable medium wherein instructions to analyze configurations comprises analyzing forwarding rules and alias rules of an e-mail SaaS application (Boyer, page 17, paragraphs 0179-0183 and page 18, paragraph 0195). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Chauhan in view of Wilson, in further view of Xu and in further view of Boyer with the teachings of Boyer to analyzing user & network behavior to provide the advantage of preventing cyber threats (Boyer, page 1, paragraphs 0004-0005). Regarding claim 20, Chauhan in view of Wilson and in further view of Xu teaches each and every claim limitation of claim 19. Chauhan in view of Wilson and in further view of Xu does not explicitly teach the apparatus wherein the instructions to manage usage of SaaS applications further comprise instructions to, at least one of, analyze configurations of the SaaS application and scan for persistence of exploits of the SaaS application. Boyer teaches wherein the instructions to manage usage of SaaS applications further comprise instructions to, at least one of, analyze configurations of the SaaS application and scan for persistence of exploits of the SaaS application (Boyer, page 17, paragraphs 0179-0183 and page 18, paragraph 0195). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Chauhan in view of Wilson and in further view of Xu with the teachings of Boyer to analyzing user & network behavior to provide the advantage of preventing cyber threats (Boyer, page 1, paragraphs 0004-0005). Prior Art The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Magazine et al. (US Pub No. 2020/0334698). Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to SHAQUEAL D WADE whose telephone number is (571)270-0357. The examiner can normally be reached M-F 8:00-5:00. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Catherine Thiaw can be reached at 571-270-1138. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /SHAQUEAL D WADE-WRIGHT/Primary Examiner, Art Unit 2407
Read full office action

Prosecution Timeline

Mar 27, 2025
Application Filed
Jul 29, 2026
Non-Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12705319
METHOD OF INSERTING AUDIO-WATERMARK SPECIALIZED FOR MUSIC USAGE AND NFT AND PROVIDING MUSIC SOURCE
1y 8m to grant Granted Aug 11, 2026
Patent 12695629
AUTHENTICATION METHOD AND APPARATUS
3y 1m to grant Granted Jul 28, 2026
Patent 12695732
BROADCAST AND/OR GROUPCAST SECURITY FOR DEVICE-TO-DEVICE POSITIONING
2y 8m to grant Granted Jul 28, 2026
Patent 12694745
SYSTEMS AND METHODS FOR CONTROL OF ELECTRONIC PARCEL LOCKERS
1y 11m to grant Granted Jul 28, 2026
Patent 12689507
STORAGE DEVICE AND OPERATING METHOD THEREOF
2y 12m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
85%
Grant Probability
99%
With Interview (+18.2%)
2y 4m (~11m remaining)
Median Time to Grant
Low
PTA Risk
Based on 454 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month