Prosecution Insights
Last updated: October 02, 2026
Application No. 19/095,452

MINIFILTER SQUATTING PROTECTION

Non-Final OA §103
Filed
Mar 31, 2025
Priority
Nov 01, 2024 — provisional 63/715,149
Examiner
RUIZ, ANGELICA
Art Unit
2154
Tech Center
2100 — Computer Architecture & Software
Assignee
SOPHOS Limited
OA Round
1 (Non-Final)
83%
Grant Probability
Favorable
1-2
OA Rounds
1y 7m
Est. Remaining
98%
With Interview

Examiner Intelligence

Grants 83% — above average
83%
Career Allowance Rate
709 granted / 852 resolved
+28.2% vs TC avg
Moderate +14% lift
Without
With
+14.5%
Interview Lift
resolved cases with interview
Typical timeline
3y 1m
Avg Prosecution
7 currently pending
Career history
871
Total Applications
across all art units

Statute-Specific Performance

§101
14.5%
-25.5% vs TC avg
§103
42.7%
+2.7% vs TC avg
§102
22.5%
-17.5% vs TC avg
§112
12.3%
-27.7% vs TC avg
Black line = Tech Center average estimate • Based on career data from 852 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status 1. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . 2. Claims 1-20 are pending. Information Disclosure Statement 3. The information disclosure statements (IDSs) submitted on 3/31/2025 and 5/1/2026 are in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement are being considered by the examiner. Drawings 4. The drawings have been reviewed and are accepted as being in compliance with the provisions of 37 CFR 1.121. Claim Rejections - 35 USC § 103 5. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 6. Claim(s) 1-14 and 17-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Strong et al (US 2018/0316708), in view of Wilson et al (US 2024/0152610), hereinafter “Wilson” and “Strong” respectively As per Claim 1, Strong discloses: A method for protecting against filesystem minifilter driver squatting attacks comprising: installing at least one filesystem minifilter driver on an endpoint device; and appending the at least one filesystem minifilter driver with a randomly generated fractional to an assigned integer altitude at a time of loading the at least one filesystem minifilter driver. (Par [0047], “Device related data can also enumerate loaded drivers and registered services.” And par [0060], “a container can be configured to hold all of the data generated by the endpoint computer system 105 for a given period of time. When a container is full (e.g. when the preset amount of data is reached or if the predetermined period of time has elapsed), a new container is added to the end of the series of containers and forensic data are written to that new container. However, Strong does not specifically describes the filter being a minifilter. Wilson discloses the above claimed feature as follows: (Par [0064], “In some embodiments, the security check is performed by an Input/Output request to a file system MiniFilter driver within a filter driver stack.” And Par [0451], “driver that allows the driver to be notified when a new thread is created or an existing thread terminates. By leveraging this callback it is possible to send simple information such as flag values or integers indicating some known value, from a process to the Kernel.). Therefore, it would have been obvious to a person of ordinary skill in the art at the effective filing date to incorporate the teachings of Wilson specifically providing a minifilter into the method of Strong to take advantage on applying the respective acquired information to create specific profiling. The modification would have been obvious because one of the ordinary skills in the art would implement proving a security check by performing an Input/Output request to a file system MiniFilter driver within a filter driver stack. Instead of a regular filtering criterion according to threats. As per Claim 2, the rejection of Claim 1 is incorporated and Strong further discloses: further comprising: detecting, by the at least one minifilter driver, at least one of a creation of a new file, a modification of an existing file, and a usage of a named pipe. (Par [0029], “(xii) Request to open or to duplicate an operating system handle to a named pipe” and par [0099], “Embodiments of the present invention detect the modification, prevent the driver from loading and alert the user;”) However Strong does not specifically describes the filter being a minifilter Wilson discloses the above claimed feature as follows: (Par [0064], “In some embodiments, the security check is performed by an Input/Output request to a file system MiniFilter driver within a filter driver stack.” And Par [0451], “driver that allows the driver to be notified when a new thread is created or an existing thread terminates. By leveraging this callback it is possible to send simple information such as flag values or integers indicating some known value, from a process to the Kernel.). As per Claim 3, the rejection of Claim 1 is incorporated and Wilson further discloses: further comprising: registering the at least one filesystem minifilter driver with a filter manager of the endpoint device with the assigned integer altitude appended by the randomly generated fractional, wherein the filter manager is configured to intercept requests destined for the filesystem and pass intercepted requests to loaded filesystem minifilter drivers including the at least one filesystem minifilter driver. (Par [0063], “In some embodiments, the security check is performed by an Input/Output request to a file system MiniFilter driver within a filter driver stack. " and paragraphs [0137-0150], “A callback is a software mechanism whereby interest in an event is registered and a subject function is provided that will be called when the event is triggered. ZEROPERIL registers callbacks to intercept one or more of the following events…” and Figure 18). As per Claim 4, the rejection of Claim 1 is incorporated and Strong further discloses: further comprising: generating the randomly generated fractional using an operating system function at the start of loading the at least one filesystem minifilter driver. (Par [0047], “Device related data can also enumerate loaded drivers and registered services.” And par [0060], “a container can be configured to hold all of the data generated by the endpoint computer system 105 for a given period of time. When a container is full (e.g. when the preset amount of data is reached or if the predetermined period of time has elapsed), a new container is added to the end of the series of containers and forensic data are written to that new container. However, Strong does not specifically describe the filter being a minifilter. Wilson discloses the above claimed feature as follows: (Par [0064], “In some embodiments, the security check is performed by an Input/Output request to a file system MiniFilter driver within a filter driver stack.” And Par [0451], “driver that allows the driver to be notified when a new thread is created or an existing thread terminates. By leveraging this callback it is possible to send simple information such as flag values or integers indicating some known value, from a process to the Kernel.). As per Claim 5, the rejection of Claim 1 is incorporated and Strong further discloses: further comprising: inserting a combination of randomly generated characters into a filesystem minifilter driver instance name of the at least one filesystem minifilter driver at a time of loading. . (Par [0047], “Device related data can also enumerate loaded drivers and registered services.” And par [0060], “a container can be configured to hold all of the data generated by the endpoint computer system 105 for a given period of time. When a container is full (e.g. when the preset amount of data is reached or if the predetermined period of time has elapsed), a new container is added to the end of the series of containers and forensic data are written to that new container. However, Strong does not specifically describe the filter being a minifilter. Wilson discloses the above claimed feature as follows: (Par [0064], “In some embodiments, the security check is performed by an Input/Output request to a file system MiniFilter driver within a filter driver stack.” And Par [0451], “driver that allows the driver to be notified when a new thread is created or an existing thread terminates. By leveraging this callback it is possible to send simple information such as flag values or integers indicating some known value, from a process to the Kernel.). As per Claim 6, the rejection of Claim 5 is incorporated and Strong further discloses: wherein the randomly generated fractional and the combination of randomly generated characters include the same sequence of numbers generated by an operating system function. (Par [0047], including the operating system, installed applications, BIOS, hardware, computer manufacturer, and languages. Device related data can also enumerate loaded drivers and registered services”). However Strong do not specifically generates random characters as sequence by operating system. Wilson discloses the above claimed features see paragraphs [0395]-0396], “…ZEROPERIL user mode hooks reside to determine if they have the correct values or if they have been modified. The checking may be performed by using a hashing algorithm for example a Cyclic Redundancy Check (CRC32) to detect tampering with the hooked memory addresses, but any differencing check can be used. It will then repeat the loop sleeping for a random amount of time before checking again, and so on. See below for an example pseudo code representation of this.”). As per Claim 7, the rejection of Claim 1 is incorporated and Strong further discloses: further comprising: appending the at least one filesystem minifilter driver with a different randomly generated fractional to the assigned integer altitude at a second time of loading the at least one filesystem minifilter driver. (Par [0060], “The most recent forensic data are appended to the current active container 210C.” and see Figures 2-3). However Strong does not specifically describes the filter being a minifilter and assigning random fractional to an assigned integer altitude. Wilson discloses the above claimed feature as follows: (Par [0064], “[0064] In some embodiments, the security check is performed by an Input/Output request to a file system MiniFilter driver within a filter driver stack.” And Par [0451], “driver that allows the driver to be notified when a new thread is created or an existing thread terminates. By leveraging this callback it is possible to send simple information such as flag values or integers indicating some known value, from a process to the Kernel. As per Claim 8, the rejection of Claim 1 is incorporated and Strong further discloses: further comprising: providing the assigned integer altitude appended by the randomly generated fractional to a remote threat management system managing an endpoint detection and response system of the endpoint device. (Par [0024], "FIG. 3 shows a diagram illustrating a plurality of endpoint computer systems in communication over one or more networks with a server forming part of an endpoint detection and response system;” and Par [0045], “ Artifact data can also focuses on resolving Remote Thread Creation where existing processes have threads injected into them. The artifact data can identify DLL injection through Remote Thread Creation of kernel32!LoadLibraryA/W. As per Claim 9, the rejection of Claim 8 is incorporated and Strong further discloses: further comprising: maintaining, by the remote threat management system, a list of current assigned integer altitudes appended by randomly generated fractionals from a plurality of endpoint devices managed by the endpoint detection and response system. (Par [0047], including the operating system, installed applications, BIOS, hardware, computer manufacturer, and languages. Device related data can also enumerate loaded drivers and registered services”). However Strong does not specifically generates random characters as sequence by operating system. Wilson discloses the above claimed features see paragraphs [0395]-0396], “…ZEROPERIL user mode hooks reside to determine if they have the correct values or if they have been modified. The checking may be performed by using a hashing algorithm for example a Cyclic Redundancy Check (CRC32) to detect tampering with the hooked memory addresses, but any differencing check can be used. It will then repeat the loop sleeping for a random amount of time before checking again, and so on. See below for an example pseudo code representation of this.”). As per Claim 10, Strong discloses: A computer system, comprising: a threat management computer system including a centralized endpoint detection and response (EDR) system configured to monitor a plurality of endpoints for threats; (Par [0077], “FIG. 8 is a process flow diagram 800 illustrating an EDR system with efficient data transfer between the endpoint computer system and a backend server in which, at 810, an endpoint computer system monitors data relating to a plurality of events occurring within an operating environment of the endpoint computer system.”) and an endpoint device monitored by the centralized threat management computer system, the an endpoint device including a localized EDR system in communication with the centralized EDR system, (Par [0077], “…The endpoint computer stores artifacts used in connection with the plurality of events in a vault maintained on such endpoint computer system. Next, at 830 and in response to the trigger, the endpoint computer system identifies and retrieves metadata characterizing artifacts associated with the trigger from the vault…” and Figures 1-2) the an endpoint device including a filter manager, wherein the localized EDR system includes at least one filesystem minifilter driver managed by the filter manager, (Par [0076], “FIG. 7 is a process flow diagram 700 illustrating event characterization as part of endpoint detection and response. Initially, at 710, each of a plurality of endpoint computer systems monitor data relating to a plurality of events occurring within an operating environment of the corresponding endpoint computer system.” And Figures 7-8) the at least one filesystem minifilter driver including an appended randomly generated fractional to an assigned integer altitude. (Par [0060], “The most recent forensic data are appended to the current active container 210C.” and see Figures 2-3). However Strong does not specifically describes the filter being a minifilter and assigning random fractional to an assigned integer altitude. Wilson discloses the above claimed feature as follows: (Par [0064], “[0064] In some embodiments, the security check is performed by an Input/Output request to a file system MiniFilter driver within a filter driver stack.” And Par [0451], “driver that allows the driver to be notified when a new thread is created or an existing thread terminates. By leveraging this callback it is possible to send simple information such as flag values or integers indicating some known value, from a process to the Kernel. Therefore, it would have been obvious to a person of ordinary skill in the art at the effective filing date to incorporate the teachings of Wilson specifically providing a minifilter into the method of Strong to take advantage on applying the respective acquired information to create specific profiling. The modification would have been obvious because one of the ordinary skills in the art would implement proving a security check by performing an Input/Output request to a file system MiniFilter driver within a filter driver stack. As per Claim 11, the rejection of Claim 10 is incorporated and Strong further discloses: wherein the appended randomly generated fractional assigned to the assigned integer altitude is randomly generated and appended at the time of loading of the at least one filesystem minifilter driver. (Par [0047], “Device related data can also enumerate loaded drivers and registered services.” And par [0060], “a container can be configured to hold all of the data generated by the endpoint computer system 105 for a given period of time. When a container is full (e.g. when the preset amount of data is reached or if the predetermined period of time has elapsed), a new container is added to the end of the series of containers and forensic data are written to that new container. However, Strong does not specifically describe the filter being a minifilter. Wilson discloses the above claimed feature as follows: (Par [0064], “In some embodiments, the security check is performed by an Input/Output request to a file system MiniFilter driver within a filter driver stack.” And Par [0451], “driver that allows the driver to be notified when a new thread is created or an existing thread terminates. By leveraging this callback it is possible to send simple information such as flag values or integers indicating some known value, from a process to the Kernel.). As per Claim 12, the rejection of Claim 10 is incorporated and Strong further discloses: wherein the at least one minifilter driver is configured to detect at least one of a creation of a new file, a modification of an existing file, and a usage of a named pipe. (Par [0029], “(xii) Request to open or to duplicate an operating system handle to a named pipe” and par [0099], “Embodiments of the present invention detect the modification, prevent the driver from loading and alert the user;”) However Strong do not specifically describes the filter being a minifilter Wilson discloses the above claimed feature as follows: (Par [0064], “In some embodiments, the security check is performed by an Input/Output request to a file system MiniFilter driver within a filter driver stack.” And Par [0451], “driver that allows the driver to be notified when a new thread is created or an existing thread terminates. By leveraging this callback it is possible to send simple information such as flag values or integers indicating some known value, from a process to the Kernel.). As per Claim 13, the rejection of Claim 12 is incorporated and Strong further discloses: wherein the at least one filesystem minifilter driver includes an inserted combination of randomly generated characters into a filesystem minifilter driver instance name. (Par [0042], “The artifacts can characterizes files used by one of the endpoint computer systems 105 or otherwise transported across the network in which the endpoint computer system 105 resides including, for example, create, modify, delete, established persistence and renamed artifacts along with metadata and file attributes. Such artifact data can be used to correlate file to process relationships.”). As per Claim 14, the rejection of Claim 13 is incorporated and Strong further discloses: wherein the randomly generated fractional and the combination of randomly generated characters include the same sequence of numbers generated by an operating system function. (Par [0047], including the operating system, installed applications, BIOS, hardware, computer manufacturer, and languages. Device related data can also enumerate loaded drivers and registered services”). However Strong does not specifically generates random characters as sequence by operating system. Wilson discloses the above claimed features see paragraphs [0395]-0396], “…ZEROPERIL user mode hooks reside to determine if they have the correct values or if they have been modified. The checking may be performed by using a hashing algorithm for example a Cyclic Redundancy Check (CRC32) to detect tampering with the hooked memory addresses, but any differencing check can be used. It will then repeat the loop sleeping for a random amount of time before checking again, and so on. See below for an example pseudo code representation of this.”). As per Claim 17, Strong further discloses: A method for protecting against filesystem minifilter driver squatting attacks comprising: installing an endpoint detection and response system on an endpoint device, wherein the endpoint detection and response system includes at least one filesystem minifilter driver; (Par [0047], including the operating system, installed applications, BIOS, hardware, computer manufacturer, and languages. Device related data can also enumerate loaded drivers and registered services”). generating a random fractional using an operating system function at the start of loading the at least one filesystem minifilter driver; (Par [0042], “The artifacts can characterizes files used by one of the endpoint computer systems 105 or otherwise transported across the network in which the endpoint computer system 105 resides including, for example, create, modify, delete, established persistence and renamed artifacts along with metadata and file attributes. Such artifact data can be used to correlate file to process relationships.”) appending the at least one filesystem minifilter driver with the randomly generated fractional to an assigned integer altitude at a time of loading the at least one filesystem minifilter driver; (Par [0060], “The most recent forensic data are appended to the current active container 210C.” and see Figures 2-3) registering the at least one filesystem minifilter driver with a filter manager of the endpoint device with the assigned integer altitude appended by the randomly generated fractional; (Par [0047], “Device related data can also enumerate loaded drivers and registered services.” And par [0060], “a container can be configured to hold all of the data generated by the endpoint computer system 105 for a given period of time. When a container is full (e.g. when the preset amount of data is reached or if the predetermined period of time has elapsed), a new container is added to the end of the series of containers and forensic data are written to that new container) at least one of a creation of a new file, a modification of an existing file, and a usage of a named pipe. (Par [0029], “(xii) Request to open or to duplicate an operating system handle to a named pipe” and par [0099], “Embodiments of the present invention detect the modification, prevent the driver from loading and alert the user;”) Strong do not disclose the “intercepting a request, by the filter manager, destined for the filesystem; passing, by the filter manager, the intercepted request to the loaded filesystem minifilter driver; and detecting, by the at least one minifilter driver, and specifically the “minifilter” Wilson discloses the above claimed features as follows: (Par [0377], “a. The SL_FORCE_ACCESS_CHECK flag is set for IRP based file system operations in order to force the operating system to check that the current process has the required access to perform the action” and par [0378] “b. Intercept and execute the action with full security checks in order to force the operating system to check that the current process has the required access to perform the action” and [0382] US 2016/328561 A1 is attempting to detect malware and rootkits whereas ZEROPERIL SCE is not attempting to detect malware, but rather it is attempting to pre-emptively remediate a specific class of Kernel driver bugs which leave a computer system vulnerable to exploitation.”) Therefore, it would have been obvious to a person of ordinary skill in the art at the effective filing date to incorporate the teachings of Wilson specifically providing a minifilter into the method of Strong to take advantage on applying the respective acquired information to create specific profiling. The modification would have been obvious because one of the ordinary skills in the art would implement proving a security check by performing an Input/Output request to a file system MiniFilter driver within a filter driver stack. Instead of a regular filtering criteria according to threats. As per Claim 18, the rejection of Claim 17 is incorporated and Strong further discloses: further comprising: inserting a combination of randomly generated characters into a filesystem minifilter driver instance name of the at least one filesystem minifilter driver at a time of loading. (Par [0047], including the operating system, installed applications, BIOS, hardware, computer manufacturer, and languages. Device related data can also enumerate loaded drivers and registered services”). However Strong does not specifically generate random characters as sequence by operating system. Wilson discloses the above claimed features see paragraphs [0395]-0396], “…ZEROPERIL user mode hooks reside to determine if they have the correct values or if they have been modified. The checking may be performed by using a hashing algorithm for example a Cyclic Redundancy Check (CRC32) to detect tampering with the hooked memory addresses, but any differencing check can be used. It will then repeat the loop sleeping for a random amount of time before checking again, and so on. See below for an example pseudo code representation of this.”). As per Claim 19, the rejection of Claim 18 is incorporated and Strong further discloses: wherein the randomly generated fractional and the combination of randomly generated characters include the same sequence of numbers generated by an operating system function. (Par [0047], including the operating system, installed applications, BIOS, hardware, computer manufacturer, and languages. Device related data can also enumerate loaded drivers and registered services”). However Strong do not specifically generates random characters as sequence by operating system. Wilson discloses the above claimed features see paragraphs [0395]-0396], “…ZEROPERIL user mode hooks reside to determine if they have the correct values or if they have been modified. The checking may be performed by using a hashing algorithm for example a Cyclic Redundancy Check (CRC32) to detect tampering with the hooked memory addresses, but any differencing check can be used. It will then repeat the loop sleeping for a random amount of time before checking again, and so on. See below for an example pseudo code representation of this.”). As per Claim 20, the rejection of Claim 17 is incorporated and Strong further discloses: further comprising: appending the at least one filesystem minifilter driver with a different randomly generated fractional to the assigned integer altitude at a second time of loading the at least one filesystem minifilter driver. (Par [0060], “The most recent forensic data are appended to the current active container 210C.” and see Figures 2-3). However Strong does not specifically describes the filter being a minifilter and assigning random fractional to an assigned integer altitude. Wilson discloses the above claimed feature as follows: (Par [0064], “[0064] In some embodiments, the security check is performed by an Input/Output request to a file system MiniFilter driver within a filter driver stack.” And Par [0451], “driver that allows the driver to be notified when a new thread is created or an existing thread terminates. By leveraging this callback it is possible to send simple information such as flag values or integers indicating some known value, from a process to the Kernel. Allowable Subject Matter 7. Claims 15-16 are objected to as being dependent upon a rejected base claim but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. Strong discloses an EDR system with efficient data transfer between the endpoint computer system and a backend server in which, at 810, an endpoint computer system monitors data relating to a plurality of events occurring within an operating environment of the endpoint computer system. Hower not specifically the “a second endpoint device monitored by the centralized threat management computer system, the second endpoint device including a second localized EDR system in communication with the centralized EDR system, the second endpoint device including a second filter manager,wherein the second localized EDR system includes at least one second endpoint filesystem minifilter driver managed by the second filter manager, the at least one second endpoint filesystem minifilter driver including a different appended randomly generated fractional to the assigned integer altitude, wherein the different appended randomly generated fractional is a different set of numbers than the appended randomly generated fractional of the endpoint device.” Claim 16 is depending on an indicated allowable claim. Conclusion 8. The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure. MacLeod; Stewart P. (US-11082444-B2) relates to an example filter manager and minifilter drivers for real-time detection of and protection from malware, in accordance with an embodiment CASSIDY; John ( US-20220021683-A1), relates to configured to provide access to additional content (e.g., network device information, log data, information from Security Information Event Management (SIEM) platforms, information from Endpoint Detection and Response (EDR), and information from other network security devices and platforms) that can be used in combination with the threat intelligence content. SHADBOLT; Matthew Ronald (US-20210385129-A1), relates to the implementation of a system compromised by modifications to a policy as contrasted to a system in which the policy is locked by tamper protection; Kannan; Karthik (US-11290483-B1), relates to provides access to pre-built, high quality threat identifier and threat scenario use cases, which include rules across multiple categories. In some embodiments, analysts may create, modify, or add their own rules following a specified format. For example, threat scenario rules may be created through a virtual wizard. 9. Any inquiry concerning this communication or earlier communications from the examiner should be directed to ANGELICA RUIZ whose telephone number is (571)270-3158. The examiner can normally be reached M-F 10:00 am to 6:00 pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Boris Gorney can be reached at (571) 270-5626. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /ANGELICA RUIZ/Primary Examiner, Art Unit 2154 August 8, 2026
Read full office action

Prosecution Timeline

Mar 31, 2025
Application Filed
Aug 12, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12748733
EFFICIENT APPEND-ONLY FILE SYSTEM FOR HIGH-PERFORMANCE KEY-VALUE STORES
3y 0m to grant Granted Sep 29, 2026
Patent 12748724
CONVERTING A DATA STREAM INTO FILES
2y 5m to grant Granted Sep 29, 2026
Patent 12724821
METHOD, APPARATUS, ELECTRONIC DEVICE AND READABLE MEDIUM FOR PRESENTING
2y 4m to grant Granted Sep 01, 2026
Patent 12711356
GENERATION AND APPLICATION OF RADIATION DOSAGE BASED ON NEURAL NETWORK ARCHITECTURE
3y 4m to grant Granted Aug 18, 2026
Patent 12688165
METHODS AND APPARATUS FOR SUPPRESSING NETWORK FEED ACTIVITIES USING AN INFORMATION FEED IN AN ON-DEMAND DATABASE SERVICE ENVIRONMENT
2y 0m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
83%
Grant Probability
98%
With Interview (+14.5%)
3y 1m (~1y 7m remaining)
Median Time to Grant
Low
PTA Risk
Based on 852 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month