Prosecution Insights
Last updated: October 02, 2026
Application No. 19/093,396

MANAGING PERMITTED BROWSER RELATED RISKY ACTIVITY IN A SECURE ENVIRONMENT

Non-Final OA §103§112
Filed
Mar 28, 2025
Priority
Apr 22, 2021 — provisional 63/177,998 +1 more
Examiner
WADE-WRIGHT, SHAQUEAL D
Art Unit
Tech Center
Assignee
Palo Alto Networks Inc.
OA Round
1 (Non-Final)
85%
Grant Probability
Favorable
1-2
OA Rounds
10m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 85% — above average
85%
Career Allowance Rate
389 granted / 457 resolved
+25.1% vs TC avg
Strong +18% interview lift
Without
With
+18.1%
Interview Lift
resolved cases with interview
Typical timeline
2y 4m
Avg Prosecution
19 currently pending
Career history
469
Total Applications
across all art units

Statute-Specific Performance

§101
15.5%
-24.5% vs TC avg
§103
49.1%
+9.1% vs TC avg
§102
7.6%
-32.4% vs TC avg
§112
18.1%
-21.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 457 resolved cases

Office Action

§103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Information Disclosure Statement The information disclosure statement (IDS) submitted on 06/12/2025 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Claim Rejections - 35 USC § 112 The following is a quotation of the first paragraph of 35 U.S.C. 112(a): (a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention. The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112: The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention. Claims 8-20 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. Claims 8-13 recite the limitation “a non-transitory machine-readable medium having stored thereon program code comprising instructions” and claims 14-20 recite the limitations “one or more endpoints, wherein each endpoint comprises a processor and a machine-readable medium having stored thereon instructions executable by the processor,” however, the specification is void and does not discloses any medium, program code, instructions or processor. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Chauhan et al. (US Pub No. 2020/0145425) in view of Pathapati et al. (US Patent No. 11,082,445). Regarding independent claim 1, Chauhan teaches a method comprising: instantiating a web browser in a first environment on an endpoint, wherein the first environment is at least partially isolated from a second environment hosted on the endpoint (Chauhan, page 3, paragraph 0050, page 4, paragraphs 0055-0057, page 10, paragraph 0099 and page 13, paragraphs 0120-0121; client device with managed and unmanaged partitions including a client application with embedded browser;); authenticating the web browser against a backend of an organization (Chauhan, page 13, paragraphs 0120-0121; authentication of the user and client application); and after authentication of the web browser, controlling, managing and monitoring activity, according to one or more security policies loaded into the first environment or the web browser from the backend (Chauhan, page 10, paragraph 0103 and page 13, paragraphs 0120-0124; control, manage and monitor activities based on policies). Chauhan does not explicitly teach after authentication of the web browser, allowing risky activity in the first environment while isolating the risky activity to the first environment on the endpoint and while disallowing access via the web browser to resources of the organization and disallowing access to a network of the organization, according to one or more security policies loaded into the first environment or the web browser from the backend. Pathapati teaches allowing risky activity in the first environment while isolating the risky activity to the first environment on the endpoint and while disallowing access via the web browser to resources of the organization and disallowing access to a network of the organization, according to one or more security policies loaded into the first environment or the web browser from the backend (Pathapati, column 6, lines 20-59, column 8, line 54-column 9, line 25 and column 11, lines 10-67; documents from unknown source undergo analysis while running/executing in sandbox, not allowed in corporate network). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Chauhan with the of Pathapati to execute unknown files in the sandbox to provide the advantage of providing security against phishing attacks (Pathapati, column 2, lines 17-21). Regarding claim 2, Chauhan in view of Pathapati teaches the method wherein authenticating the web browser comprises providing credentials of the web browser to the backend (Chauhan, page 13, paragraphs 0120-012, 0123 and 0126; authentication of the user and client application). Regarding claim 3, Chauhan in view of Pathapati teaches the method further comprising authenticating a user to the organization with at least one of the web browser and an identity service provider (Chauhan, page 13, paragraphs 0120-012, 0123 and 0126; authentication of the user and client application). Regarding claim 4, Chauhan in view of Pathapati teaches the method wherein allowing risky activity in the first environment while isolating the risky activity to the first environment on the endpoint comprises limiting endpoint exposure to user input devices and a display (Chauhan, page 17, paragraph 0162). Regarding claim 5, Chauhan in view of Pathapati teaches the method wherein allowing risky activity in the first environment while isolating the risky activity to the first environment on the endpoint comprises at least one of disconnecting at least one of network access and operating system events from the first environment and preventing installation of any application or extension while allowing the risky activity (Chauhan, page 17, paragraph 0162, page 10, paragraph 0104 and page 20, paragraphs 0181-0182). Regarding claim 6, Chauhan in view of Pathapati teaches the method wherein allowing risky activity in the first environment while isolating the risky activity to the first environment on the endpoint comprises detecting a change to risky browsing from standard browsing and, based on detecting the change, hardening the first environment for the risky activity (Chauhan, page 17, paragraph 0162, page 10, paragraph 0104 and page 20, paragraphs 0181-0182). Regarding claim 7, Chauhan in view of Pathapati teaches the method wherein hardening the first environment for risky browsing comprises disallowing at least one of: access to a keyboard of the endpoint; screenshots; file downloads; access to cookies and session variables; access to hypertext markup language (HTML) based local storage mechanisms; access to devices of the endpoint from HTML; script based uniform resource locator (URL) fetching from external resources; and access to domains specified in the one or more security polices when risky browsing is allowed (Chauhan, page 17, paragraph 0162, page 10, paragraph 0104 and page 20, paragraphs 0181-0182). Regarding independent claim 8, Chauhan teaches a non-transitory machine-readable medium having stored thereon program code comprising instructions to: instantiate a web browser in a first environment on an endpoint, wherein the first environment is at least partially isolated from a second environment hosted on the endpoint (Chauhan, page 3, paragraph 0050, page 4, paragraphs 0055-0057, page 10, paragraph 0099 and page 13, paragraphs 0120-0121; client device with managed and unmanaged partitions including a client application with embedded browser;); authenticate the web browser against a backend of an organization (Chauhan, page 13, paragraphs 0120-0121; authentication of the user and client application); and after authentication of the web browser, controlling, managing and monitoring activity, according to one or more security policies loaded into the first environment or the web browser from the backend (Chauhan, page 10, paragraph 0103 and page 13, paragraphs 0120-0124; control, manage and monitor activities based on policies). Chauhan does not explicitly teach allow risky activity in the first environment; isolate the risky activity to the first environment on the endpoint; and disallow access via the web browser to resources of the organization and disallow access to a network of the organization. Pathapati teaches allow risky activity in the first environment; isolate the risky activity to the first environment on the endpoint; and disallow access via the web browser to resources of the organization and disallow access to a network of the organization (Pathapati, column 6, lines 20-59, column 8, line 54-column 9, line 25 and column 11, lines 10-67; documents from unknown source undergo analysis while running/executing in sandbox, not allowed in corporate network). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Chauhan with the of Pathapati to execute unknown files in the sandbox to provide the advantage of providing security against phishing attacks (Pathapati, column 2, lines 17-21). Regarding claim 9, Chauhan in view of Pathapati teaches the non-transitory machine-readable medium wherein the instructions to authenticate the web browser comprises providing credentials of the web browser to the backend (Chauhan, page 13, paragraphs 0120-012, 0123 and 0126; authentication of the user and client application). Regarding claim 10, Chauhan in view of Pathapati teaches the non-transitory machine-readable medium wherein the instructions to allow risky activity in the first environment while isolating the risky activity to the first environment on the endpoint comprises limiting endpoint exposure to user input devices and a display (Chauhan, page 17, paragraph 0162). Regarding claim 11, Chauhan in view of Pathapati teaches the non-transitory machine-readable medium wherein the instructions to allow risky activity in the first environment while isolating the risky activity to the first environment on the endpoint comprises at least one of disconnecting at least one of network access and operating system events from the first environment and preventing installation of any application or extension while allowing the risky activity (Chauhan, page 17, paragraph 0162, page 10, paragraph 0104 and page 20, paragraphs 0181-0182). Regarding claim 12, Chauhan in view of Pathapati teaches the non-transitory machine-readable medium wherein the instructions to allow risky activity in the first environment while isolating the risky activity to the first environment on the endpoint comprises detecting a change to risky browsing from standard browsing and, based on detecting the change, hardening the first environment for the risky activity (Chauhan, page 17, paragraph 0162, page 10, paragraph 0104 and page 20, paragraphs 0181-0182). Regarding claim 13, Chauhan in view of Pathapati teaches the non-transitory machine-readable medium, wherein the instructions to harden the first environment for risky browsing comprises disallow at least one of: access to a keyboard of the endpoint; screenshots; file downloads; access to cookies and session variables; access to hypertext markup language (HTML) based local storage mechanisms; access to devices of the endpoint from HTML; script based uniform resource locator (URL) fetching from external resources; and access to domains specified in the one or more security polices when risky browsing is allowed (Chauhan, page 17, paragraph 0162, page 10, paragraph 0104 and page 20, paragraphs 0181-0182). Regarding independent claim 14, Chauhan teaches a system comprising: a backend of an organization, wherein the backend comprises one or more servers; a set of one or more endpoints, wherein each endpoint comprises a processor and a machine-readable medium having stored thereon instructions executable by the processor to cause the endpoint to, instantiate a web browser in a first environment on an endpoint, wherein the first environment is at least partially isolated from a second environment hosted on the endpoint (Chauhan, page 3, paragraph 0050, page 4, paragraphs 0055-0057, page 10, paragraph 0099 and page 13, paragraphs 0120-0121; client device with managed and unmanaged partitions including a client application with embedded browser;); authenticate the web browser against a backend of an organization (Chauhan, page 13, paragraphs 0120-0121; authentication of the user and client application); and after authentication of the web browser, controlling, managing and monitoring activity, according to one or more security policies loaded into the first environment or the web browser from the backend (Chauhan, page 10, paragraph 0103 and page 13, paragraphs 0120-0124; control, manage and monitor activities based on policies). Chauhan does not explicitly teach allow risky activity in the first environment and isolate the risky activity to the first environment and disallow access to resources of the organization and disallow access to a network of the organization, according to one or more security policies loaded into the first environment or the web browser from the backend. Pathapati teaches allow risky activity in the first environment and isolate the risky activity to the first environment and disallow access to resources of the organization and disallow access to a network of the organization, according to one or more security policies loaded into the first environment or the web browser from the backend (Pathapati, column 6, lines 20-59, column 8, line 54-column 9, line 25 and column 11, lines 10-67; documents from unknown source undergo analysis while running/executing in sandbox, not allowed in corporate network). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Chauhan with the of Pathapati to execute unknown files in the sandbox to provide the advantage of providing security against phishing attacks (Pathapati, column 2, lines 17-21). Regarding claim 15, Chauhan in view of Pathapati teaches the system wherein the instructions to authenticate the web browser comprises providing credentials of the web browser to the backend (Chauhan, page 13, paragraphs 0120-012, 0123 and 0126; authentication of the user and client application). Regarding claim 16, Chauhan in view of Pathapati teaches the system wherein the machine-readable medium further has stored thereon instructions executable by the processor to cause the endpoint to authenticate a user to the organization with at least one of the web browser and an identity service provider (Chauhan, page 13, paragraphs 0120-012, 0123 and 0126; authentication of the user and client application). Regarding claim 17, Chauhan in view of Pathapati teaches the system wherein the instructions to allow risky activity in the first environment while isolating the risky activity to the first environment on the endpoint comprises limiting endpoint exposure to user input devices and a display of the endpoint (Chauhan, page 17, paragraph 0162). Regarding claim 18, Chauhan in view of Pathapati teaches the system wherein the instructions to allow risky activity in the first environment while isolating the risky activity to the first environment on the endpoint comprises at least one of disconnecting at least one of network access and operating system events from the first environment and preventing installation of any application or extension while allowing the risky activity (Chauhan, page 17, paragraph 0162, page 10, paragraph 0104 and page 20, paragraphs 0181-0182). Regarding claim 19, Chauhan in view of Pathapati teaches the system wherein the instructions to allow risky activity in the first environment while isolating the risky activity to the first environment on the endpoint comprises detecting a change to risky browsing from standard browsing and, based on detecting the change, hardening the first environment for the risky activity (Chauhan, page 17, paragraph 0162, page 10, paragraph 0104 and page 20, paragraphs 0181-0182). Regarding claim 20, Chauhan in view of Pathapati teaches the system, wherein the instructions to harden the first environment for risky browsing comprises disallow at least one of: access to a keyboard of the endpoint; screenshots; file downloads; access to cookies and session variables; access to hypertext markup language (HTML) based local storage mechanisms; access to devices of the endpoint from HTML; script based uniform resource locator (URL) fetching from external resources; and access to domains specified in the one or more security polices when risky browsing is allowed (Chauhan, page 17, paragraph 0162, page 10, paragraph 0104 and page 20, paragraphs 0181-0182). Prior Art The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Mandrychenko (US Pub No. 2020/0287920). Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to SHAQUEAL D WADE whose telephone number is (571)270-0357. The examiner can normally be reached M-F 8:00-5:00. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Catherine Thiaw can be reached at 571-270-1138. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /SHAQUEAL D WADE-WRIGHT/ Primary Examiner, Art Unit 2407
Read full office action

Prosecution Timeline

Mar 28, 2025
Application Filed
Aug 26, 2026
Non-Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12743539
SEARCH EXECUTION DEVICE, SEARCH EXECUTION METHOD, COMPUTER READABLE MEDIUM AND SEARCHABLE ENCRYPTION SYSTEM
2y 9m to grant Granted Sep 22, 2026
Patent 12730895
APPARATUSES AND METHODS FOR VERIFICATION OF UPDATED DATA-SET
3y 2m to grant Granted Sep 08, 2026
Patent 12719838
STATISTICALLY PRIVATE OBLIVIOUS TRANSFER FROM CDH
2y 4m to grant Granted Aug 25, 2026
Patent 12705319
METHOD OF INSERTING AUDIO-WATERMARK SPECIALIZED FOR MUSIC USAGE AND NFT AND PROVIDING MUSIC SOURCE
1y 8m to grant Granted Aug 11, 2026
Patent 12695629
AUTHENTICATION METHOD AND APPARATUS
3y 1m to grant Granted Jul 28, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
85%
Grant Probability
99%
With Interview (+18.1%)
2y 4m (~10m remaining)
Median Time to Grant
Low
PTA Risk
Based on 457 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month