Prosecution Insights
Last updated: October 02, 2026
Application No. 19/098,713

COMPUTER-BASED SYSTEMS FOR DYNAMIC PERSONA-BASED ACCESS TO COMPUTER NETWORK RESOURCES BASED ON MACHINE LEARNING TECHNIQUES AND METHODS OF USE THEREOF

Non-Final OA §103§112
Filed
Apr 02, 2025
Priority
May 29, 2020 — continuation of 11/516,299 +1 more
Examiner
DAILEY, THOMAS J
Art Unit
Tech Center
Assignee
American Express Travel Related Services Company, Inc.
OA Round
1 (Non-Final)
81%
Grant Probability
Favorable
1-2
OA Rounds
1y 8m
Est. Remaining
96%
With Interview

Examiner Intelligence

Grants 81% — above average
81%
Career Allowance Rate
711 granted / 878 resolved
+21.0% vs TC avg
Moderate +15% lift
Without
With
+14.9%
Interview Lift
resolved cases with interview
Typical timeline
3y 2m
Avg Prosecution
19 currently pending
Career history
901
Total Applications
across all art units

Statute-Specific Performance

§101
11.6%
-28.4% vs TC avg
§103
51.9%
+11.9% vs TC avg
§102
18.6%
-21.4% vs TC avg
§112
11.7%
-28.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 878 resolved cases

Office Action

§103 §112
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION Claims 1-20 are pending. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. Information Disclosure Statement The information disclosure statement (IDS) submitted on 4/2/2025 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(a) and (b): (a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention. (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. Claims 1-20 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. Claim 1 recites, “determine, within the computer network, a change between the first activity and the second activity.” The examiner could not find support for determining a change between one activity and another. Fig. 4, for example, contains various determinations (i.e. branches) with only label 421 coming closest to such a limitation and is more simply labeled “Scan user Activity.” Following that label to the written description, [46]-[47] recites, “In some instances, when the system 100 determines at 405 that the user role and/ or business unit has not changed, the system 100 can scan the user activity as shown at 421. Thereafter, the system 100 determines if there are any entitlements that the user is not using at 425. In some instances when there are entitlements that the user is not using, the system 100 can suspend access to inactive entitlements and/or trigger a manual review process as shown at 427. In some instances when the system 100 determines at 425 that there are no entitlements the user is not using, the system 100 can determine if there are any changes in the system platform as shown at 429. In some instances, when there are changes in the system platform, for example, incoming data, changes of services, removing data, as shown at 431, the system 100 can suggest new entitlements to the user or automatically extend the new entitlements to the user if there is no policy indicating the opposite as shown at 433.” In sum and to reiterate, it is unclear to the examiner where a change between a first and second activity is determined. This issue flows into the last limitation “generate, based on the change, a second electronic resource to the computer network,” as it is dependent on “the change.” In the examiner’s opinion, this is the more clear and glaring lack of written description. Where is a resource ever “generated” in the specification? And, more pointedly, generated based on a previously determined change? It seems to the examiner the specification supports determining when a new electronic resource is added to the network (see [5], [76], and [79] among others), but this and the other recitations are wholly different than “generate, based on the change, a second electronic resource to the computer network.” Perhaps those portions of the specification loop back to simply a poor wording of the prior “determine” limitation, in that, essentially that limitation is attempting to claim something akin to determining a change to the computer network at a time between the first and second activities which is something the specification appears to support (i.e. the system will be looking for changes (e.g. an added resource) and such an event can occur between activities). But the final limitation still poses significant issues in scope and structure even with such a rewording because the examiner fails to see how, after determining, for example, a resource was added, it would lead to generating another resource (the same resource?). Claims 8 and 15 recite similar limitations and are similarly rejected. With regard to claims 2-7,9-14, and 16-20, they are rejected due to their dependency on the above rejected claims and the examiner advises their review as some rely/further narrow the above limitations that necessitated the rejections. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention. Claims 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Choi et al (US Pub. No. 2016/0057150), hereafter, “Choi,” in view of Pulier et al (US Pat. 8,725,886), hereafter, “Pulier.” As to claim Choi discloses an apparatus, comprising: a processor; and a non-transitory memory storing instructions which, when executed by the processor (Abstract), cause the processor to: determine a first user entitlement associated with a user profile of a user to a computer network (Figs. 2, 3, labels 208, 308, and [0027], particularly, “In step 208, event analytics access provision 200 obtains user roles and attributes.” See also, [0045], particularly, “Steps 302 through 308 of event analytics access de-provision 300 operate similarly or in tandem to embodiments described above in FIG. 2 with regard to respective steps 202 through 210 (following decision 204, no branch) of event analytics access provision 200.”); identify a first activity of the user within the computer network, wherein, in the first activity, the user has accessed a first electronic resource of the computer network based on the first user entitlement (Figs. 2, 3, labels 210, 310, and [0028], particularly, “In step 210, event analytics access provision 200 updates an audit event log and historical reference 122. The audit event log collects and saves security log entries across an organization and may contain information about actions that take place on a computer, computers, and/or network which can be correlated to a user id.” See also, [0026], particularly, “For example, an existing user id requests access to managed system 126. Upon entering a valid user id and password, access to the system is granted (i.e., user id exists, authentication and authorization criteria are met, and assigned role grants access to restricted resource).”); analyze at least one of the user profile, the first user entitlement, or an entitlement authorization condition associated with the computer network to determine a second user entitlement (Fig. 2, label 224 and [0037], particularly, “In step 224, event analytics access provision 200 determines a recommended role for the failed user id from previous successful user id roles. In an embodiment, event analytics access provision 200 determines new roles for the failed user id through a comparison of the roles determined in step 214 above and the roles associated with the user with the successful user ids and shared attributes.” and Fig. 3, label 312 and [0048], particularly, “Additionally, event analytics access de-provision 300 queries historical reference 122 for audit event information associated with other user ids accessing managed system 126 as a reference for additional typical user id activity. Event analytics access de-provision 300 sorts the received audit event information based on similar roles and attributes as the user id associated with the audit event. In one embodiment, event analytics access de-provision 300 identifies a match within the received audit event information. In another embodiment, event analytics access de-provision 300 identifies audit events associated with similar roles and attributes. In an embodiment, event analytics access de-provision 300 organizes audit event information based on similar roles and attributes starting with the most to least similar attribute and/or role matches.”); identify a second activity of the user within the computer network, wherein, in the second activity, the user has accessed the first electronic resource of the computer network based on the second user entitlement (Fig. 2, label 224 and [0037], particularly, “In step 224, event analytics access provision 200 determines a recommended role for the failed user id from previous successful user id roles. In an embodiment, event analytics access provision 200 determines new roles for the failed user id through a comparison of the roles determined in step 214 above and the roles associated with the user with the successful user ids and shared attributes.” And Fig. 3, label 308-312, see [0054]); determine, within the computer network, a change between the first activity and the second activity (Fig. 2, label 224 and [0037], particularly, “In step 224, event analytics access provision 200 determines a recommended role for the failed user id from previous successful user id roles. In an embodiment, event analytics access provision 200 determines new roles for the failed user id through a comparison of the roles determined in step 214 above and the roles associated with the user with the successful user ids and shared attributes…For example, a new employee shares the same job title, manager, and department as a co-worker within historical reference 122 with access to managed system 126.” and Fig. 3, label 312-314, see [0054]); and However Choi does not explicitly disclose generate, based on the change, a second electronic resource to the computer network. But, Pulier discloses generate, based on a change, a second electronic resource to a computer network (column 9, lines 9-24; particularly, “If, in contrast, reprovisioning is needed, the provisioner 134 reassigning the provisioning environment 122 based on the reevaluation, as depicted at step 334, and control reverts to step 311 to establish a new provisioned environment 122 for the user. Reprovisioning may also involve modifying environment parameters 198 in the user profile, without changing the class 144.”) Therefore it would have been obvious to one of ordinary skill in the art prior to the effective filing date to combine the teachings of Pulier and Choi in order to provide a system that can provision resources on demand to meet the changes of live systems. As to claims 8 and 15, they are rejected by a similar rationale to that set forth in claim 1’s rejection. As to claim 2, 9, and 16, the teachings of Choi and Pulier as combined for the same reasons set forth in claim 1’s rejection further disclose the instructions further cause the processor to: revoke, from the user, an access to the first electronic resource of the computer network based on the second user entitlement when the user has not accessed the first electronic resource of the computer network based on the first user entitlement during a time greater than a predetermined time threshold value; and update the user profile to indicate that the user does not have access to the second user entitlement (Choi, [0032] and[0044]) . As to claim 3, 10, and 17, the teachings of Choi and Pulier as combined for the same reasons set forth in claim 1’s rejection further disclose to revoke the user with the access to the first electronic resource of the computer network is determined at least in part by an output of a probability inference network (Choi, [0044] and [0054]). As to claim 4 and 11, the teachings of Choi and Pulier as combined for the same reasons set forth in claim 1’s rejection further disclose the first electronic resource is at least one of a computer network service and computer network data (Choi, Abstract and [0002]-[0003]). As to claim 5, 12, and 18, the teachings of Choi and Pulier as combined for the same reasons set forth in claim 1’s rejection further disclose the instructions further cause the processor to: determine a new user entitlement associated with usage of the second electronic resource; and input, into an inference machine learning model, at least one of the first user entitlement or the second user entitlement, to determine when to provide the new user entitlement to the first user entitlement with an access to the second electronic resource of the computer network (Fig. 2, label 224 and [0037], particularly, “In step 224, event analytics access provision 200 determines a recommended role for the failed user id from previous successful user id roles. In an embodiment, event analytics access provision 200 determines new roles for the failed user id through a comparison of the roles determined in step 214 above and the roles associated with the user with the successful user ids and shared attributes…For example, a new employee shares the same job title, manager, and department as a co-worker within historical reference 122 with access to managed system 126.” and Fig. 3, label 312-314, see [0054]). As to claim 6, 13, and 19, the teachings of Choi and Pulier as combined for the same reasons set forth in claim 1’s rejection further disclose the determination to provide the new user entitlement to the first user entitlement is determined at least in part by an output of a probability inference network (Fig. 2, label 224 and [0037], particularly, “In step 224, event analytics access provision 200 determines a recommended role for the failed user id from previous successful user id roles. In an embodiment, event analytics access provision 200 determines new roles for the failed user id through a comparison of the roles determined in step 214 above and the roles associated with the user with the successful user ids and shared attributes…For example, a new employee shares the same job title, manager, and department as a co-worker within historical reference 122 with access to managed system 126.” and Fig. 3, label 312-314, see [0054]). As to claim 7, 8, and 20, the teachings of Choi and Pulier as combined for the same reasons set forth in claim 1’s rejection further disclose the second electronic resource is at least one of a computer network service and computer network data (Choi, Abstract and [0002]-[0003] and Pulier, column 9, lines 9-24). Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to THOMAS J DAILEY whose telephone number is (571)270-1246. The examiner can normally be reached 9:30am-6:00pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Umar Cheema can be reached on 571-270-3037. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /THOMAS J DAILEY/ Primary Examiner, Art Unit 2458
Read full office action

Prosecution Timeline

Apr 02, 2025
Application Filed
Aug 11, 2026
Non-Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750251
Context-Dependent In-Call Video Codec Switching
2y 1m to grant Granted Sep 29, 2026
Patent 12744953
MACHINE LEARNING FOR ADAPTIVE BITRATE SELECTION
1y 11m to grant Granted Sep 22, 2026
Patent 12726488
AUTONOMOUS POLICY ENFORCEMENT POINT CONFIGURATION FOR ROLE BASED ACCESS CONTROL
4y 6m to grant Granted Sep 01, 2026
Patent 12706810
METHODS FOR INTELLIGENT SIGNALING MESSAGE STEERING IN 5G CORE
2y 0m to grant Granted Aug 11, 2026
Patent 12701125
DEEP LEARNING FOR IN-LINE DETECTION OF MALICIOUS COMMAND AND CONTROL TRAFFIC FROM UNSTRUCTURED PAYLOADS
2y 3m to grant Granted Aug 04, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
81%
Grant Probability
96%
With Interview (+14.9%)
3y 2m (~1y 8m remaining)
Median Time to Grant
Low
PTA Risk
Based on 878 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month