Prosecution Insights
Last updated: October 02, 2026
Application No. 19/096,228

FAST GAP REDUCTION IN POLICY TREE CREATION FOR POLICY SET WITH UNEVEN DENSITY

Non-Final OA §103§DOUBLEPATENT
Filed
Mar 31, 2025
Priority
Mar 24, 2023 — continuation of 12/323,390
Examiner
HOLLISTER, JAMES ROSS
Art Unit
Tech Center
Assignee
Fortinet Inc.
OA Round
1 (Non-Final)
76%
Grant Probability
Favorable
1-2
OA Rounds
1y 1m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 76% — above average
76%
Career Allowance Rate
171 granted / 225 resolved
+16.0% vs TC avg
Strong +24% interview lift
Without
With
+24.3%
Interview Lift
resolved cases with interview
Typical timeline
2y 7m
Avg Prosecution
11 currently pending
Career history
237
Total Applications
across all art units

Statute-Specific Performance

§101
18.3%
-21.7% vs TC avg
§103
54.7%
+14.7% vs TC avg
§102
10.1%
-29.9% vs TC avg
§112
10.8%
-29.2% vs TC avg
Black line = Tech Center average estimate • Based on career data from 225 resolved cases

Office Action

§103 §DOUBLEPATENT
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Summary This action is a responsive to the application filed on 3/31/2025. Claims 1-6 are pending and have been examined. Claims 1-6 are rejected. Information Disclosure Statement The information disclosure statement (IDS) submitted on 3/31/2026. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Claim Interpretation The following is a quotation of 35 U.S.C. 112(f): (f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. The following is a quotation of pre-AIA 35 U.S.C. 112, sixth paragraph: An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. The claims in this application are given their broadest reasonable interpretation using the plain meaning of the claim language in light of the specification as it would be understood by one of ordinary skill in the art. The broadest reasonable interpretation of a claim element (also commonly referred to as a claim limitation) is limited by the description in the specification when 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is invoked. As explained in MPEP § 2181, subsection I, claim limitations that meet the following three-prong test will be interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph: (A) the claim limitation uses the term “means” or “step” or a term used as a substitute for “means” that is a generic placeholder (also called a nonce term or a non-structural term having no specific structural meaning) for performing the claimed function; (B) the term “means” or “step” or the generic placeholder is modified by functional language, typically, but not always linked by the transition word “for” (e.g., “means for”) or another linking word or phrase, such as “configured to” or “so that”; and (C) the term “means” or “step” or the generic placeholder is not modified by sufficient structure, material, or acts for performing the claimed function. Use of the word “means” (or “step”) in a claim with functional language creates a rebuttable presumption that the claim limitation is to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites sufficient structure, material, or acts to entirely perform the recited function. Absence of the word “means” (or “step”) in a claim creates a rebuttable presumption that the claim limitation is not to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is not interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites function without reciting sufficient structure, material or acts to entirely perform the recited function. Claim limitations in this application that use the word “means” (or “step”) are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. Conversely, claim limitations in this application that do not use the word “means” (or “step”) are not being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. This application includes one or more claim limitations that use the word “means” or “step” but are nonetheless not being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph because the claim limitation(s) recite(s) sufficient structure, materials, or acts to entirely perform the recited function. Such claim limitation(s) is/are: “a density zone identification module”; “a density normalizing module”; “a zone boundary module” and “a policy implementation module” in claim 6. Because this/these claim limitation(s) is/are not being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, it/they is/are not being interpreted to cover only the corresponding structure, material, or acts described in the specification as performing the claimed function, and equivalents thereof. If applicant intends to have this/these limitation(s) interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, applicant may: (1) amend the claim limitation(s) to remove the structure, materials, or acts that performs the claimed function; or (2) present a sufficient showing that the claim limitation(s) does/do not recite sufficient structure, materials, or acts to perform the claimed function. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer. Claims 1-6 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-6 of U.S. Patent No. US12323390B2. Although the claims at issue are not identical, they are not patentably distinct from each other because the instant application claims are broader than the U.S. Patent. Each of the instant application claims (claims 1, 5 and 6) is broader than the claims (1, 5 and 6) in said U.S. Patent. For instance, taking claim 1 of the U.S. Patent, the limitation “generating a policy bitmap from a set of network security policies, wherein a partition number is used during bitmap labeling for the policy bitmap is configurable, and wherein a configurable threshold during bitmap labeling is adjustable according to network security policies; identifying a plurality of boundaries between low-density zones and high-density zones utilizing bitmap labeling on the policy bitmap by counting lead zeros and tail zeros; binary splitting the node with a single condition check, into two partitions, on an identified boundary of the plurality of boundaries between a low-density zone and a high-density zone of the policy bitmap...” is missing in claim 1 of the instant application.. Since claim 5 and 6 in the instant application recites similar features as claim 1 of the instant application, same comparison can be made. Therefore, it would have been obvious to one of ordinary skill in the art at the time the invention was mace to omit elements when the remaining elements perform as before. A person of ordinary skill could have arrived at the present claims by omitting the details of said U.S. Patent claims. See In re Karlson (CCPA) 136 USPQ 184, decided January 16, 1963 (“Omission of element and its function in combination is obvious expedient if remaining elements perform same function as before’). An exemplary to show similarity among the conflicting claims (see table below). Instant Application U.S. Patent No. US12323390B2 1. A computer-implemented method in a network device examining data packets on a data communication network, for optimizing policy tree creation by reducing gaps in network security policy sets with uneven density, the method comprising: automatically creating a policy tree of nodes and leaves from a network security policy set, by identifying density zones of policy subsets; responsive to identifying an uneven density zone in a node of the policy tree, generating child nodes with normal density zones from the uneven density zones; responsive to identifying a normal density zone in the policy set, cutting the node of an identified boundary between normal density zones into a number of partitions based on the partition number, into child nodes; storing the policy tree of nodes and leaves comprising normal density zones in the network device; and subsequently serving a request at the network device to search the policy tree for application to a network packet. 1. A computer-implemented method in a network device examining data packets on a data communication network, for optimizing policy tree creation by reducing gaps in network security policy sets with uneven density, the method comprising: automatically creating a policy tree of nodes and leaves from a network security policy set, by identifying density zones of policy subsets; responsive to identifying an uneven density zone in a node of the policy tree, generating child nodes with normal density zones from the uneven density zones; responsive to identifying a normal density zone in the policy set, cutting the node of an identified boundary between normal density zones into a number of partitions based on the partition number, into child nodes; storing the policy tree of nodes and leaves comprising normal density zones in the network device; and subsequently serving a request at the network device to search the policy tree for application to a network packet. 2. The method of claim 1, further comprising: recursively identifying density zones until no further uneven density zones are identified. 2. The method of claim 1, further comprising: recursively identifying density zones until no further uneven density zones are identified. 3. The method of claim 1, further comprising: using a threshold to control the width of low-density zones. 3. The method of claim 1, further comprising: using a threshold to control the width of low-density zones. 4. The method of claim 1, wherein the configurable partition number is not limited by hardware. 4. The method of claim 1, wherein the configurable partition number is not limited by hardware. 5. A non-transitory computer-readable medium in a network device examining data packets on a data communication network, for optimizing policy tree creation by reducing gaps in network security policy sets with uneven density, the method comprising: automatically creating a policy tree of nodes and leaves from a network security policy set, by identifying density zones of policy subsets; responsive to identifying an uneven density zone in a node of the policy tree, generating child nodes with normal density zones from the uneven density zones; responsive to identifying a normal density zone in the policy set, cutting the node of an identified boundary between normal density zones into a number of partitions based on a partition number, into child nodes; storing the policy tree of nodes and leaves comprising normal density zones in the network device; and subsequently serving a request at the network device to search the policy tree for application to a network packet. 5. A non-transitory computer-readable medium in a network device examining data packets on a data communication network, for optimizing policy tree creation by reducing gaps in network security policy sets with uneven density, the method comprising: automatically creating a policy tree of nodes and leaves from a network security policy set, by identifying density zones of policy subsets; responsive to identifying an uneven density zone in a node of the policy tree, generating child nodes with normal density zones from the uneven density zones; responsive to identifying a normal density zone in the policy set, cutting the node of an identified boundary between normal density zones into a number of partitions based on a partition number, into child nodes; storing the policy tree of nodes and leaves comprising normal density zones in the network device; and subsequently serving a request at the network device to search the policy tree for application to a network packet. 6. A network device examining data packets on a data communication network, for optimizing policy tree creation by reducing gaps in network security policy sets with uneven density, the network device comprising: a processor; a network interface communicatively coupled to the processor and to the WLAN; and a memory, communicatively coupled to the processor and storing: a density zone identification module to automatically create a policy tree of nodes and leaves from a network security policy set, by identifying density zones of policy subsets; a density normalizing module to, responsive to identifying an uneven density zone in a node of the policy tree, generate child nodes with normal density zones from the uneven density zones; a zone boundary module to, responsive to identifying a normal density zone in the policy set, cut the node of an identified boundary between normal density zones into a number of partitions based on a partition number, into child nodes; and a policy implementation module to store the policy tree of nodes and leaves comprising normal density zones in the network device and subsequently serve a request at the network device to search the policy tree for application to a network packet. 6. A network device examining data packets on a data communication network, for optimizing policy tree creation by reducing gaps in network security policy sets with uneven density, the network device comprising: a processor; a network interface communicatively coupled to the processor and to the WLAN; and a memory, communicatively coupled to the processor and storing: a density zone identification module to automatically create a policy tree of nodes and leaves from a network security policy set, by identifying density zones of policy subsets; a density normalizing module to, responsive to identifying an uneven density zone in a node of the policy tree, generate child nodes with normal density zones from the uneven density zones; a zone boundary module to, responsive to identifying a normal density zone in the policy set, cut the node of an identified boundary between normal density zones into a number of partitions based on a partition number, into child nodes; and a policy implementation module to store the policy tree of nodes and leaves comprising normal density zones in the network device and subsequently serve a request at the network device to search the policy tree for application to a network packet. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claims 1, 4-6 are rejected under 35 U.S.C. 103 as being unpatentable over MONNI et al. (US 20210352107 A1) and further in view of Zhang et al. (US 20170187750 A1). As to claim 1, MONNI et al. teaches A computer-implemented method in a network device examining data packets on a data communication network, for optimizing policy tree creation by reducing gaps in network security policy sets with uneven density, the method comprising: automatically creating a policy tree of nodes and leaves from a network security policy set (See ¶¶ [0172]-[0174], Teaches that The exemplary process 700 may comprise generating two radix trees, a network radix tree, as shown in 720 and a service radix tree as shown in 730. Alternative implementations may use other data structures for analyzing the network and/or service hierarchies. The network radix tree's nodes comprise networks addresses of network nodes and masks. The network radix tree is a hierarchical data structure based on addresses of network nodes, subnet masks, and/or other identifiers and groupings. A dictionary comprising network nodes and subnetworks mentioned in the rules may be used as an auxiliary data structure. An exemplary network radix tree is shown in FIG. 8. The service radix nodes describe a plurality of services using a vector comprising IP and TCP options. The service radix tree is a hierarchical data structure that may be based on different layers and levels of protocols, options, configurations, and/or the like. A dictionary comprising services, options, port ranges, and the likes, form one or more communication layers, and groups thereof mentioned in the rules may be used as an auxiliary data structure. An exemplary service radix tree is shown in FIG. 10.); and subsequently serving a request at the network device to search the policy tree for application to a network packet (See ¶ [0168], Teaches that When the packet is compliant with the network policies, or the associative rule allows the communication, the network component executing the process 600 may permit forwarding the data packet, as shown in 603. Otherwise, when the packet is non-compliant with the network policies, no associative rule allows the communication, or that the associative rule precludes allows the communication, the network component executing the process 600 may block the data packet, as shown in 604. The network component may ignore the non-compliant data packet, or send a negative acknowledgement to the source object. The network element may further communicate with other network elements to indicate a data packet was blocked.). However, it does not expressly teach the details of by identifying density zones of policy subsets; responsive to identifying an uneven density zone in a node of the policy tree, generating child nodes with normal density zones from the uneven density zones; responsive to identifying a normal density zone in the policy set, cutting the node of an identified boundary between normal density zones into a number of partitions based on the partition number, into child nodes; storing the policy tree of nodes and leaves comprising normal density zones in the network device. Zhang et al., from analogous art, teaches by identifying density zones of policy subsets (See ¶¶ [0083]-[0085], Teaches that At block 204, when a policy fragment is found in the intermediate representation by the converter, an optimization recommendation may be displayed to the user of the converter. For example, if repeated policies are found, the 5-tuple and the number of the repeated policies may be displayed and one of the repeated policies may be recommended to be kept and the others may be deleted from the intermediate representation. For conflicting policies, mergeable policies and encompassing policies, the converter may display corresponding policies and recommendations. At block 205, the converter may receive feedback from the user regarding a policy fragment. For example, one of the repeated policies, conflicting policies, encompassing policies may be selected to be retained in the intermediate representation and mergeable policies may be allowed to be merged. In an example, the user may create a particular conversion rule or algorithm for a security policy of the first language to generate a corresponding security policy of the second language without producing policy fragments. At block 206, the converter may optimize the intermediate representation of the network security configuration file. In one example, the converter may optimize the intermediate representation by keeping the security policies that are selected by the user at block 205 and deleting the other security policies of the policy fragments. The converter may also convert a security policy based on one or more conversion rules created by the user. In another example, the intermediate representation may be optimized by resolving policy fragments automatically. The converter may select one security policy of a set of repeated policies and delete others from the intermediate representation and merge the mergeable policies into one security policy. For encompassing policies and conflicting policies, the most secure policy of these security policies may be retained within the intermediate representation. For example, if a security policy blocks network traffic while another conflicting security policy allows the same network traffic. The converter may keep the security policy that blocks the network traffic and delete the conflicting policy. The converter may perform similar optimization for encompassing policies.); responsive to identifying an uneven density zone in a node of the policy tree, generating child nodes with normal density zones from the uneven density zones (See ¶¶ [0083]-[0085], Teaches that At block 204, when a policy fragment is found in the intermediate representation by the converter, an optimization recommendation may be displayed to the user of the converter. For example, if repeated policies are found, the 5-tuple and the number of the repeated policies may be displayed and one of the repeated policies may be recommended to be kept and the others may be deleted from the intermediate representation. For conflicting policies, mergeable policies and encompassing policies, the converter may display corresponding policies and recommendations. At block 205, the converter may receive feedback from the user regarding a policy fragment. For example, one of the repeated policies, conflicting policies, encompassing policies may be selected to be retained in the intermediate representation and mergeable policies may be allowed to be merged. In an example, the user may create a particular conversion rule or algorithm for a security policy of the first language to generate a corresponding security policy of the second language without producing policy fragments. At block 206, the converter may optimize the intermediate representation of the network security configuration file. In one example, the converter may optimize the intermediate representation by keeping the security policies that are selected by the user at block 205 and deleting the other security policies of the policy fragments. The converter may also convert a security policy based on one or more conversion rules created by the user. In another example, the intermediate representation may be optimized by resolving policy fragments automatically. The converter may select one security policy of a set of repeated policies and delete others from the intermediate representation and merge the mergeable policies into one security policy. For encompassing policies and conflicting policies, the most secure policy of these security policies may be retained within the intermediate representation. For example, if a security policy blocks network traffic while another conflicting security policy allows the same network traffic. The converter may keep the security policy that blocks the network traffic and delete the conflicting policy. The converter may perform similar optimization for encompassing policies.); responsive to identifying a normal density zone in the policy set, cutting the node of an identified boundary between normal density zones into a number of partitions based on the partition number, into child nodes (See ¶¶ [0083]-[0085], Teaches that At block 204, when a policy fragment is found in the intermediate representation by the converter, an optimization recommendation may be displayed to the user of the converter. For example, if repeated policies are found, the 5-tuple and the number of the repeated policies may be displayed and one of the repeated policies may be recommended to be kept and the others may be deleted from the intermediate representation. For conflicting policies, mergeable policies and encompassing policies, the converter may display corresponding policies and recommendations. At block 205, the converter may receive feedback from the user regarding a policy fragment. For example, one of the repeated policies, conflicting policies, encompassing policies may be selected to be retained in the intermediate representation and mergeable policies may be allowed to be merged. In an example, the user may create a particular conversion rule or algorithm for a security policy of the first language to generate a corresponding security policy of the second language without producing policy fragments. At block 206, the converter may optimize the intermediate representation of the network security configuration file. In one example, the converter may optimize the intermediate representation by keeping the security policies that are selected by the user at block 205 and deleting the other security policies of the policy fragments. The converter may also convert a security policy based on one or more conversion rules created by the user. In another example, the intermediate representation may be optimized by resolving policy fragments automatically. The converter may select one security policy of a set of repeated policies and delete others from the intermediate representation and merge the mergeable policies into one security policy. For encompassing policies and conflicting policies, the most secure policy of these security policies may be retained within the intermediate representation. For example, if a security policy blocks network traffic while another conflicting security policy allows the same network traffic. The converter may keep the security policy that blocks the network traffic and delete the conflicting policy. The converter may perform similar optimization for encompassing policies.); storing the policy tree of nodes and leaves comprising normal density zones in the network device (See ¶ [0086], Teaches that At block 207, the converter may store the optimization of policy fragments and conversion rules created by the user to the converting knowledge database in order that the same or similar policy fragments may be resolved automatically in subsequent conversion processing.). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Zhang et al. into MONNI et al. in order improve the integrity of security policy conversion (See Zhang et al. ¶ [0011]). As to claim 4, the combination of MONNI et al. and Zhang et al. teaches the method according to claim 1 above. However, it does not expressly teach the details of wherein the configurable partition number is not limited by hardware. Zhang et al., from analogous art, teaches wherein the configurable partition number is not limited by hardware (See ¶¶ [0083]-[0085], Teaches that At block 204, when a policy fragment is found in the intermediate representation by the converter, an optimization recommendation may be displayed to the user of the converter. For example, if repeated policies are found, the 5-tuple and the number of the repeated policies may be displayed and one of the repeated policies may be recommended to be kept and the others may be deleted from the intermediate representation. For conflicting policies, mergeable policies and encompassing policies, the converter may display corresponding policies and recommendations. At block 205, the converter may receive feedback from the user regarding a policy fragment. For example, one of the repeated policies, conflicting policies, encompassing policies may be selected to be retained in the intermediate representation and mergeable policies may be allowed to be merged. In an example, the user may create a particular conversion rule or algorithm for a security policy of the first language to generate a corresponding security policy of the second language without producing policy fragments. At block 206, the converter may optimize the intermediate representation of the network security configuration file. In one example, the converter may optimize the intermediate representation by keeping the security policies that are selected by the user at block 205 and deleting the other security policies of the policy fragments. The converter may also convert a security policy based on one or more conversion rules created by the user. In another example, the intermediate representation may be optimized by resolving policy fragments automatically. The converter may select one security policy of a set of repeated policies and delete others from the intermediate representation and merge the mergeable policies into one security policy. For encompassing policies and conflicting policies, the most secure policy of these security policies may be retained within the intermediate representation. For example, if a security policy blocks network traffic while another conflicting security policy allows the same network traffic. The converter may keep the security policy that blocks the network traffic and delete the conflicting policy. The converter may perform similar optimization for encompassing policies). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Zhang et al. into the combination of MONNI et al. and Zhang et al. in order improve the integrity of security policy conversion (See Zhang et al. ¶ [0011]). As to claim 5, MONNI et al. teaches A non-transitory computer-readable medium in a network device examining data packets on a data communication network, for optimizing policy tree creation by reducing gaps in network security policy sets with uneven density, the method comprising: automatically creating a policy tree of nodes and leaves from a network security policy set (See ¶¶ [0172]-[0174], Teaches that The exemplary process 700 may comprise generating two radix trees, a network radix tree, as shown in 720 and a service radix tree as shown in 730. Alternative implementations may use other data structures for analyzing the network and/or service hierarchies. The network radix tree's nodes comprise networks addresses of network nodes and masks. The network radix tree is a hierarchical data structure based on addresses of network nodes, subnet masks, and/or other identifiers and groupings. A dictionary comprising network nodes and subnetworks mentioned in the rules may be used as an auxiliary data structure. An exemplary network radix tree is shown in FIG. 8. The service radix nodes describe a plurality of services using a vector comprising IP and TCP options. The service radix tree is a hierarchical data structure that may be based on different layers and levels of protocols, options, configurations, and/or the like. A dictionary comprising services, options, port ranges, and the likes, form one or more communication layers, and groups thereof mentioned in the rules may be used as an auxiliary data structure. An exemplary service radix tree is shown in FIG. 10.); and subsequently serving a request at the network device to search the policy tree for application to a network packet (See ¶ [0168], Teaches that When the packet is compliant with the network policies, or the associative rule allows the communication, the network component executing the process 600 may permit forwarding the data packet, as shown in 603. Otherwise, when the packet is non-compliant with the network policies, no associative rule allows the communication, or that the associative rule precludes allows the communication, the network component executing the process 600 may block the data packet, as shown in 604. The network component may ignore the non-compliant data packet, or send a negative acknowledgement to the source object. The network element may further communicate with other network elements to indicate a data packet was blocked.). However, it does not expressly teach the details of by identifying density zones of policy subsets; responsive to identifying an uneven density zone in a node of the policy tree, generating child nodes with normal density zones from the uneven density zones; responsive to identifying a normal density zone in the policy set, cutting the node of an identified boundary between normal density zones into a number of partitions based on a partition number, into child nodes; storing the policy tree of nodes and leaves comprising normal density zones in the network device. Zhang et al., from analogous art, teaches by identifying density zones of policy subsets (See ¶¶ [0083]-[0085], Teaches that At block 204, when a policy fragment is found in the intermediate representation by the converter, an optimization recommendation may be displayed to the user of the converter. For example, if repeated policies are found, the 5-tuple and the number of the repeated policies may be displayed and one of the repeated policies may be recommended to be kept and the others may be deleted from the intermediate representation. For conflicting policies, mergeable policies and encompassing policies, the converter may display corresponding policies and recommendations. At block 205, the converter may receive feedback from the user regarding a policy fragment. For example, one of the repeated policies, conflicting policies, encompassing policies may be selected to be retained in the intermediate representation and mergeable policies may be allowed to be merged. In an example, the user may create a particular conversion rule or algorithm for a security policy of the first language to generate a corresponding security policy of the second language without producing policy fragments. At block 206, the converter may optimize the intermediate representation of the network security configuration file. In one example, the converter may optimize the intermediate representation by keeping the security policies that are selected by the user at block 205 and deleting the other security policies of the policy fragments. The converter may also convert a security policy based on one or more conversion rules created by the user. In another example, the intermediate representation may be optimized by resolving policy fragments automatically. The converter may select one security policy of a set of repeated policies and delete others from the intermediate representation and merge the mergeable policies into one security policy. For encompassing policies and conflicting policies, the most secure policy of these security policies may be retained within the intermediate representation. For example, if a security policy blocks network traffic while another conflicting security policy allows the same network traffic. The converter may keep the security policy that blocks the network traffic and delete the conflicting policy. The converter may perform similar optimization for encompassing policies.); responsive to identifying an uneven density zone in a node of the policy tree, generating child nodes with normal density zones from the uneven density zones (See ¶¶ [0083]-[0085], Teaches that At block 204, when a policy fragment is found in the intermediate representation by the converter, an optimization recommendation may be displayed to the user of the converter. For example, if repeated policies are found, the 5-tuple and the number of the repeated policies may be displayed and one of the repeated policies may be recommended to be kept and the others may be deleted from the intermediate representation. For conflicting policies, mergeable policies and encompassing policies, the converter may display corresponding policies and recommendations. At block 205, the converter may receive feedback from the user regarding a policy fragment. For example, one of the repeated policies, conflicting policies, encompassing policies may be selected to be retained in the intermediate representation and mergeable policies may be allowed to be merged. In an example, the user may create a particular conversion rule or algorithm for a security policy of the first language to generate a corresponding security policy of the second language without producing policy fragments. At block 206, the converter may optimize the intermediate representation of the network security configuration file. In one example, the converter may optimize the intermediate representation by keeping the security policies that are selected by the user at block 205 and deleting the other security policies of the policy fragments. The converter may also convert a security policy based on one or more conversion rules created by the user. In another example, the intermediate representation may be optimized by resolving policy fragments automatically. The converter may select one security policy of a set of repeated policies and delete others from the intermediate representation and merge the mergeable policies into one security policy. For encompassing policies and conflicting policies, the most secure policy of these security policies may be retained within the intermediate representation. For example, if a security policy blocks network traffic while another conflicting security policy allows the same network traffic. The converter may keep the security policy that blocks the network traffic and delete the conflicting policy. The converter may perform similar optimization for encompassing policies.); responsive to identifying a normal density zone in the policy set, cutting the node of an identified boundary between normal density zones into a number of partitions based on a partition number, into child nodes (See ¶¶ [0083]-[0085], Teaches that At block 204, when a policy fragment is found in the intermediate representation by the converter, an optimization recommendation may be displayed to the user of the converter. For example, if repeated policies are found, the 5-tuple and the number of the repeated policies may be displayed and one of the repeated policies may be recommended to be kept and the others may be deleted from the intermediate representation. For conflicting policies, mergeable policies and encompassing policies, the converter may display corresponding policies and recommendations. At block 205, the converter may receive feedback from the user regarding a policy fragment. For example, one of the repeated policies, conflicting policies, encompassing policies may be selected to be retained in the intermediate representation and mergeable policies may be allowed to be merged. In an example, the user may create a particular conversion rule or algorithm for a security policy of the first language to generate a corresponding security policy of the second language without producing policy fragments. At block 206, the converter may optimize the intermediate representation of the network security configuration file. In one example, the converter may optimize the intermediate representation by keeping the security policies that are selected by the user at block 205 and deleting the other security policies of the policy fragments. The converter may also convert a security policy based on one or more conversion rules created by the user. In another example, the intermediate representation may be optimized by resolving policy fragments automatically. The converter may select one security policy of a set of repeated policies and delete others from the intermediate representation and merge the mergeable policies into one security policy. For encompassing policies and conflicting policies, the most secure policy of these security policies may be retained within the intermediate representation. For example, if a security policy blocks network traffic while another conflicting security policy allows the same network traffic. The converter may keep the security policy that blocks the network traffic and delete the conflicting policy. The converter may perform similar optimization for encompassing policies.); storing the policy tree of nodes and leaves comprising normal density zones in the network device (See ¶ [0086], Teaches that At block 207, the converter may store the optimization of policy fragments and conversion rules created by the user to the converting knowledge database in order that the same or similar policy fragments may be resolved automatically in subsequent conversion processing.). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Zhang et al. into MONNI et al. in order improve the integrity of security policy conversion (See Zhang et al. ¶ [0011]). As to claim 6, MONNI et al. teaches A network device examining data packets on a data communication network, for optimizing policy tree creation by reducing gaps in network security policy sets with uneven density, the network device comprising: a processor; a network interface communicatively coupled to the processor and to the WLAN; and a memory, communicatively coupled to the processor and storing: a density zone identification module to automatically create a policy tree of nodes and leaves from a network security policy set (See ¶¶ [0172]-[0174], Teaches that The exemplary process 700 may comprise generating two radix trees, a network radix tree, as shown in 720 and a service radix tree as shown in 730. Alternative implementations may use other data structures for analyzing the network and/or service hierarchies. The network radix tree's nodes comprise networks addresses of network nodes and masks. The network radix tree is a hierarchical data structure based on addresses of network nodes, subnet masks, and/or other identifiers and groupings. A dictionary comprising network nodes and subnetworks mentioned in the rules may be used as an auxiliary data structure. An exemplary network radix tree is shown in FIG. 8. The service radix nodes describe a plurality of services using a vector comprising IP and TCP options. The service radix tree is a hierarchical data structure that may be based on different layers and levels of protocols, options, configurations, and/or the like. A dictionary comprising services, options, port ranges, and the likes, form one or more communication layers, and groups thereof mentioned in the rules may be used as an auxiliary data structure. An exemplary service radix tree is shown in FIG. 10.); and subsequently serve a request at the network device to search the policy tree for application to a network packet (See ¶ [0168], Teaches that When the packet is compliant with the network policies, or the associative rule allows the communication, the network component executing the process 600 may permit forwarding the data packet, as shown in 603. Otherwise, when the packet is non-compliant with the network policies, no associative rule allows the communication, or that the associative rule precludes allows the communication, the network component executing the process 600 may block the data packet, as shown in 604. The network component may ignore the non-compliant data packet, or send a negative acknowledgement to the source object. The network element may further communicate with other network elements to indicate a data packet was blocked.). However, it does not expressly teach the details of by identifying density zones of policy subsets; a density normalizing module to, responsive to identifying an uneven density zone in a node of the policy tree, generate child nodes with normal density zones from the uneven density zones; a zone boundary module to, responsive to identifying a normal density zone in the policy set, cut the node of an identified boundary between normal density zones into a number of partitions based on a partition number, into child nodes; and a policy implementation module to store the policy tree of nodes and leaves comprising normal density zones in the network device. Zhang et al., from analogous art, teaches by identifying density zones of policy subsets (See ¶¶ [0083]-[0085], Teaches that At block 204, when a policy fragment is found in the intermediate representation by the converter, an optimization recommendation may be displayed to the user of the converter. For example, if repeated policies are found, the 5-tuple and the number of the repeated policies may be displayed and one of the repeated policies may be recommended to be kept and the others may be deleted from the intermediate representation. For conflicting policies, mergeable policies and encompassing policies, the converter may display corresponding policies and recommendations. At block 205, the converter may receive feedback from the user regarding a policy fragment. For example, one of the repeated policies, conflicting policies, encompassing policies may be selected to be retained in the intermediate representation and mergeable policies may be allowed to be merged. In an example, the user may create a particular conversion rule or algorithm for a security policy of the first language to generate a corresponding security policy of the second language without producing policy fragments. At block 206, the converter may optimize the intermediate representation of the network security configuration file. In one example, the converter may optimize the intermediate representation by keeping the security policies that are selected by the user at block 205 and deleting the other security policies of the policy fragments. The converter may also convert a security policy based on one or more conversion rules created by the user. In another example, the intermediate representation may be optimized by resolving policy fragments automatically. The converter may select one security policy of a set of repeated policies and delete others from the intermediate representation and merge the mergeable policies into one security policy. For encompassing policies and conflicting policies, the most secure policy of these security policies may be retained within the intermediate representation. For example, if a security policy blocks network traffic while another conflicting security policy allows the same network traffic. The converter may keep the security policy that blocks the network traffic and delete the conflicting policy. The converter may perform similar optimization for encompassing policies.); a density normalizing module to, responsive to identifying an uneven density zone in a node of the policy tree, generate child nodes with normal density zones from the uneven density zones (See ¶¶ [0083]-[0085], Teaches that At block 204, when a policy fragment is found in the intermediate representation by the converter, an optimization recommendation may be displayed to the user of the converter. For example, if repeated policies are found, the 5-tuple and the number of the repeated policies may be displayed and one of the repeated policies may be recommended to be kept and the others may be deleted from the intermediate representation. For conflicting policies, mergeable policies and encompassing policies, the converter may display corresponding policies and recommendations. At block 205, the converter may receive feedback from the user regarding a policy fragment. For example, one of the repeated policies, conflicting policies, encompassing policies may be selected to be retained in the intermediate representation and mergeable policies may be allowed to be merged. In an example, the user may create a particular conversion rule or algorithm for a security policy of the first language to generate a corresponding security policy of the second language without producing policy fragments. At block 206, the converter may optimize the intermediate representation of the network security configuration file. In one example, the converter may optimize the intermediate representation by keeping the security policies that are selected by the user at block 205 and deleting the other security policies of the policy fragments. The converter may also convert a security policy based on one or more conversion rules created by the user. In another example, the intermediate representation may be optimized by resolving policy fragments automatically. The converter may select one security policy of a set of repeated policies and delete others from the intermediate representation and merge the mergeable policies into one security policy. For encompassing policies and conflicting policies, the most secure policy of these security policies may be retained within the intermediate representation. For example, if a security policy blocks network traffic while another conflicting security policy allows the same network traffic. The converter may keep the security policy that blocks the network traffic and delete the conflicting policy. The converter may perform similar optimization for encompassing policies.); a zone boundary module to, responsive to identifying a normal density zone in the policy set, cut the node of an identified boundary between normal density zones into a number of partitions based on a partition number, into child nodes (See ¶¶ [0083]-[0085], Teaches that At block 204, when a policy fragment is found in the intermediate representation by the converter, an optimization recommendation may be displayed to the user of the converter. For example, if repeated policies are found, the 5-tuple and the number of the repeated policies may be displayed and one of the repeated policies may be recommended to be kept and the others may be deleted from the intermediate representation. For conflicting policies, mergeable policies and encompassing policies, the converter may display corresponding policies and recommendations. At block 205, the converter may receive feedback from the user regarding a policy fragment. For example, one of the repeated policies, conflicting policies, encompassing policies may be selected to be retained in the intermediate representation and mergeable policies may be allowed to be merged. In an example, the user may create a particular conversion rule or algorithm for a security policy of the first language to generate a corresponding security policy of the second language without producing policy fragments. At block 206, the converter may optimize the intermediate representation of the network security configuration file. In one example, the converter may optimize the intermediate representation by keeping the security policies that are selected by the user at block 205 and deleting the other security policies of the policy fragments. The converter may also convert a security policy based on one or more conversion rules created by the user. In another example, the intermediate representation may be optimized by resolving policy fragments automatically. The converter may select one security policy of a set of repeated policies and delete others from the intermediate representation and merge the mergeable policies into one security policy. For encompassing policies and conflicting policies, the most secure policy of these security policies may be retained within the intermediate representation. For example, if a security policy blocks network traffic while another conflicting security policy allows the same network traffic. The converter may keep the security policy that blocks the network traffic and delete the conflicting policy. The converter may perform similar optimization for encompassing policies.); and a policy implementation module to store the policy tree of nodes and leaves comprising normal density zones in the network device (See ¶ [0086], Teaches that At block 207, the converter may store the optimization of policy fragments and conversion rules created by the user to the converting knowledge database in order that the same or similar policy fragments may be resolved automatically in subsequent conversion processing.). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Zhang et al. into MONNI et al. in order improve the integrity of security policy conversion (See Zhang et al. ¶ [0011]). Claims 2-3 are rejected under 35 U.S.C. 103 as being unpatentable over MONNI et al. (US 20210352107 A1) and Zhang et al. (US 20170187750 A1) and further in view of Crawford et al. (US 8984022 B1). As to claim 2, the combination of MONNI et al. and Zhang et al. teaches the method according to claim 1 above. However, it does not expressly teach the details of further comprising: recursively identifying density zones until no further uneven density zones are identified. Crawford et al., from analogous art, teaches further comprising: recursively identifying density zones until no further uneven density zones are identified (See Col 8 Ln 12, Teaches that At 314, for each input tree, the trees resulting from using the N splits (where N can be a user-defined parameter) that result in the maximum increase in divergence can be retained. At 316, for each of the retained candidate trees, the leaf node with the greatest number of records can be recursively grown (as discussed above and as shown in FIG. 4). At 318, when any of the predetermined stopping criteria are met, the process for recursively growing trees is terminated.). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Crawford et al. into the combination of MONNI et al. and Zhang et al. in order to discover a segmentation that can result in the most predictive scoring system for a complete population (See Crawford et al. Col 1 Ln 8). As to claim 3, the combination of MONNI et al. and Zhang et al. teaches the method according to claim 1 above. However, it does not expressly teach the details of further comprising: using a threshold to control the width of low-density zones. Crawford et al., from analogous art, teaches further comprising: using a threshold to control the width of low-density zones (See Col 8 Ln 20, Teaches that An example of the stopping criteria includes a situation where no split being found to increase overall system performance. Another example of the stopping criteria includes a situation where a number of total records or a record per outcome class falls below a predetermined threshold. A further example includes a situation when trees can no longer be grown while satisfying the maximum number of leaf node criteria. Alternatively, when a maximum execution time has been reached, the method can terminate as well). Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Crawford et al. into the combination of MONNI et al. and Zhang et al. in order to discover a segmentation that can result in the most predictive scoring system for a complete population (See Crawford et al. Col 1 Ln 8). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Parekh et al. (US 7203744 B1) teaches An integrated policy enforcement system for a computer network implements several policies on the network traffic. A rule compiler compiles these policies and converts them into a rule tree-graph, which is then used to provide desired behavior to the network traffic comprising data packets. The rule compiler comprises three sub-modules namely--a rule input module, a rule tree generator module and a rule output module. The rule input module receives the input for the rule compiler and prepares the input for the rule tree generator module. The rule tree generator module generates the rule tree-graph. The rule tree-graph is a data structure comprising tree data structure and graph data structure. Such a data structure combines the properties of tree data structure and graph data structure, and enhances the performance of the policy enforcement systems by striking a balance between the memory requirement for storing the data structure and the processing capabilities of the system required to process the network traffic. The Output module converts the rule tree-graph to policy files, which can be downloaded to various modules of the policy enforcement systems. Any inquiry concerning this communication or earlier communications from the examiner should be directed to James R Hollister whose telephone number is (571)270-3152. The examiner can normally be reached Mon - Fri 7:30 am - 4:00 pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Philip Chea can be reached at (571) 272-3951. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. James Hollister /J.R.H./Examiner, Art Unit 2499 8/15/26 /PHILIP J CHEA/Supervisory Patent Examiner, Art Unit 2499
Read full office action

Prosecution Timeline

Mar 31, 2025
Application Filed
Aug 24, 2026
Non-Final Rejection mailed — §103, §DOUBLEPATENT (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12744776
AUTHENTICATION OF MEDICAL DEVICES
3y 0m to grant Granted Sep 22, 2026
Patent 12732486
OBFUSCATION IN PRIVACY BEACON
3y 1m to grant Granted Sep 08, 2026
Patent 12719680
VIRTUAL ACCESS CREDENTIAL INTERACTION SYSTEM AND METHOD
2y 9m to grant Granted Aug 25, 2026
Patent 12701007
System, Method, and Computer Program Product for Third-Party Authorization
1y 9m to grant Granted Aug 04, 2026
Patent 12688276
SHARING CONTAINER DATA INSIDE A TENANT'S POD UNDER DIFFERENT TRUSTED EXECUTION ENVIRONMENTS (TEES)
3y 11m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
76%
Grant Probability
99%
With Interview (+24.3%)
2y 7m (~1y 1m remaining)
Median Time to Grant
Low
PTA Risk
Based on 225 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month