Prosecution Insights
Last updated: August 17, 2026
Application No. 19/183,238

INTELLIGENT FIREWALL RULE HANDLING

Non-Final OA §103
Filed
Apr 18, 2025
Priority
Jul 18, 2023 — continuation of 12/309,155
Examiner
LIN, AMIE CHINYU
Art Unit
Tech Center
Assignee
SAP SE
OA Round
1 (Non-Final)
84%
Grant Probability
Favorable
1-2
OA Rounds
1y 4m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 84% — above average
84%
Career Allowance Rate
257 granted / 304 resolved
+24.5% vs TC avg
Strong +31% interview lift
Without
With
+31.0%
Interview Lift
resolved cases with interview
Typical timeline
2y 8m
Avg Prosecution
11 currently pending
Career history
315
Total Applications
across all art units

Statute-Specific Performance

§101
14.6%
-25.4% vs TC avg
§103
46.7%
+6.7% vs TC avg
§102
15.2%
-24.8% vs TC avg
§112
18.2%
-21.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 304 resolved cases

Office Action

§103
DETAILED ACTION This Office Action is in response to the communication filed on 04/18/2025. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claims 1-20 are pending. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1, 4-6, 9-11, 14-16, and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Dargis (US 2011/0154469) in view of Yeom (US 2007/0192847). Claim 1, Dargis teaches: A system comprising: at least one hardware processor; and a non-transitory computer-readable medium storing executable instructions that, when executed, cause the at least one hardware processor to perform computer operations comprising: (e.g., [0017]-[0018], [0020]) receiving, by a server network and from a client network, a first request to update an access control list to include an external address; (e.g., [0025], “a web browser 112 resident at the client device 110 may send an authentication request message 115 to the authentication server 130…The authentication request message 115 may include, for example, a source IP address and source port identification” [0026], “The access authorization message 125 transmitted to the blocking device 140 may identify this new source port, which information may be used, for example, to modify and access control list (ACL) maintained at the blocking device 140”) obtaining, by the server network, authorization to update the access control list using an access token of the first request; (e.g., [0024], “the authentication server 130 may be configured to transmit access authorization messages 125 that identify an authorized source address and source port, such that the blocking device 140 may responsively modify the access criteria to allow passage of messages from this address and source port to the protected server 160. In some embodiments, the identified source port is determined based on source port information provided to the authentication server 130 by the client device 110”) in response to the obtaining of the authorization, updating, by the server network, the access control list to include the external address; (e.g., [0026], “The access authorization message 125 transmitted to the blocking device 140 may identify this new source port, which information may be used, for example, to modify and access control list (ACL) maintained at the blocking device 140”) receiving, by the server network, a second request to perform an action, the second request including the address; and based on determining that the address in the second request is included in the updated access control list, performing the action. (e.g., [0023], “The blocking device 140 generally controls access to the protected server 160 based on access criteria that may, for example, allow only packets with authorized network (e.g., IP) addresses and port numbers to pass between the internet 120 and the protected server 160” [0024], “the authentication server 130 may be configured to transmit access authorization messages 125 that identify an authorized source address and source port, such that the blocking device 140 may responsively modify the access criteria to allow passage of messages from this address and source port to the protected server 160” [0029], “the blocking device 140 may be configured, for example, to provide a transparent firewall…The blocking device 140 may, for example, block all traffic that is not specifically authorized by its ACL, while also listening for SNMPv3 access authorization messages 125 from the authentication server 130”) Dargis does not appear to explicitly teach but Yeom teaches: an external Internet Protocol (IP) address. (e.g., [0061], “The ACL or firewall rules stored in the ACL memory 112b are updated in real-time according to information/instruction inputted from the IP/port check module 112a” [0062], “Therefore, the firewall 112 judges whether to allow or disallow passage of a received packet according to afore-mentioned ACL. Through this process, this embodiment of the invention enables dynamic network security using firewall” [0067], “upon receiving IP/port information from the VoIP ALG 111 interworking with the IP/port/protocol check module 112a, the ACL memory 112b updates such IP/port information in the ACL so that the IP/port information is stored and managed therein. Then, by using the updated ACL, the IP/port/protocol check module 112a can allow/disallow receipt of packets” [0075], “ALG 111 acquires…IP/port/protocol information when regenerating a signaling payload according to NAT/PT rule…and then transmits it to the IP/port/protocol check module 112a of the firewall 111” [0076], “Upon receiving the IP/port/protocol information for packet receipt allowance/disallowance provided from the VoIP ALG 111, the IP/port check module 112a of the firewall 112 sets the received IP/port/protocol information to be exempted from firewall rule application. That is, the IP/port/protocol information for packet receipt allowance/disallowance is updated in the ACL of the ACL memory 112b of the firewall 112 so that the information is stored and managed therein”) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teachings described by Yeom into the invention of Dargis, and the motivation for such an implementation would be for the purpose of providing reliable firewall construction, overcoming restriction of firewall rule application, and providing convenience in operation and setting (Yeom [0012], [0014], [0098]). Claim 4, Dargis-Yeom teaches: wherein the first request comprises an external port identifier. (e.g., Dargis [0025]) Claim 5, Dargis-Yeom teaches: wherein the updating of the access control list to include the external IP address comprises updating the access control list to include the external port identifier. (e.g., Dargis [0024], [0026]) Claim 6, Dargis-Yeom teaches: wherein the performing of the action is further based on determining that a port included in the second request is included in the updated access control list. (e.g., Dargis [0023]-[0024], [0029]) Claim 9, Dargis-Yeom teaches: wherein the external IP address was assigned to a client application by an edge component of the client network. (e.g., Yeom [0064], [0075]-[0076]) Same motivation as presented in claim 1 would apply. Claim 10, Dargis-Yeom teaches: wherein the external IP address was generated by the edge component using a network address translation (NAT) process. (e.g., Yeom [0064], [0075]-[0076]) Same motivation as presented in claim 1 would apply. Claim 11, this claim is directed to a non-transitory machine-readable storage medium containing similar limitations as recited in claim 1 and is rejected using the same rationale to combine the references. Claim 14, this claim is directed to a non-transitory machine-readable storage medium containing similar limitations as recited in claim 4 and is rejected using the same rationale to combine the references. Claim 15, this claim is directed to a non-transitory machine-readable storage medium containing similar limitations as recited in claim 5 and is rejected using the same rationale to combine the references. Claim 16, this claim is directed to a non-transitory machine-readable storage medium containing similar limitations as recited in claim 6 and is rejected using the same rationale to combine the references. Claim 18, this claim is directed to a method containing similar limitations as recited in claim 1 and is rejected using the same rationale to combine the references. Claims 2-3, 12-13, and 19-20 are rejected under 35 U.S.C. 103 as being unpatentable over Dargis (US 2011/0154469) in view of Yeom (US 2007/0192847) further in view of Birgisson et al. (US 2017/0220793). Claim 2, Dargis-Yeom teaches the access token (see above) and does not appear to explicitly teach but Birgisson teaches: an access token is restricted to being valid for only a limited period of time. (e.g., [0035]) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teachings described by Birgisson into the invention of Dargis-Yeom, and the motivation for such an implementation would be for the purpose of preventing replay attacks and protecting against security breaches in resource-constrained computing environments due to the limits on computing or storage resources that are available or when there is limited or unreliable network connectivity (Birgisson [0004]). Claim 3, Dargis-Yeom teaches the access token (see above) and does not appear to explicitly teach but Birgisson teaches: an access token is restricted to being valid for only a limited set of one or more geographical locations. (e.g., [0035]) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teachings described by Birgisson into the invention of Dargis-Yeom, and the motivation for such an implementation would be for the purpose of preventing replay attacks and protecting against security breaches in resource-constrained computing environments due to the limits on computing or storage resources that are available or when there is limited or unreliable network connectivity (Birgisson [0004]). Claim 12, this claim is directed to a non-transitory machine-readable storage medium containing similar limitations as recited in claim 2 and is rejected using the same rationale to combine the references. Claim 13, this claim is directed to a non-transitory machine-readable storage medium containing similar limitations as recited in claim 3 and is rejected using the same rationale to combine the references. Claim 19, this claim is directed to a method containing similar limitations as recited in claim 2 and is rejected using the same rationale to combine the references. Claim 20, this claim is directed to a method containing similar limitations as recited in claim 3 and is rejected using the same rationale to combine the references. Claims 7-8, and 17 are rejected under 35 U.S.C. 103 as being unpatentable over Dargis (US 2011/0154469) in view of Yeom (US 2007/0192847) further in view of Williams et al. (US 2023/0020193). Claim 7, Dargis-Yeom teaches the obtaining of the authorization to update the access control list (see above) and does not appear to explicitly teach but Williams teaches: performing a multi-factor authentication to confirm that an updating of the access control list is to be performed. (e.g., [0409]-[0410]) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teachings described by Williams into the invention of Dargis-Yeom, and the motivation for such an implementation would be for the purpose of preventing malevolent actor or hacker attacks and providing failsafe measures that enhances the security and integrity of data items stored (Williams [0534]-[0535]). Claim 8, Dargis-Yeom teaches the performing of the action (see above) and does not appear to explicitly teach but Williams teaches: performing of an action is further based on a successful multi-factor authentication process. (e.g., [0414]) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to incorporate the teachings described by Williams into the invention of Dargis-Yeom, and the motivation for such an implementation would be for the purpose of preventing malevolent actor or hacker attacks and providing failsafe measures that enhances the security and integrity of data items stored (Williams [0534]-[0535]). Claim 17, this claim is directed to a non-transitory machine-readable storage medium containing similar limitations as recited in claim 7 and is rejected using the same rationale to combine the references. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: US 11,178,150 discloses methods for enforcing access control list based on managed application and devices thereof. Any inquiry concerning this communication or earlier communications from the examiner should be directed to AMIE C LIN whose telephone number is (571)272-7752. The examiner can normally be reached M-F 9:00AM -5:00PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, GELAGAY SHEWAYE can be reached at (571)272-4219. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /AMIE C. LIN/Primary Examiner, Art Unit 2436
Read full office action

Prosecution Timeline

Apr 18, 2025
Application Filed
Jul 15, 2026
Non-Final Rejection mailed — §103
Aug 04, 2026
Interview Requested

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12699764
CERTIFICATE RESILIENCY VALIDATION USING CHAOS ENGINEERING
3y 4m to grant Granted Aug 04, 2026
Patent 12665894
SYSTEMS AND METHODS FOR AUTHENTICATION BROKERING
2y 9m to grant Granted Jun 23, 2026
Patent 12664268
METHODS AND APPARATUS TO IDENTIFY STRUCTURAL SIMILARITY BETWEEN WEBPAGES
2y 8m to grant Granted Jun 23, 2026
Patent 12664255
Preventing EDR Termination using Vulnerable Drivers
2y 0m to grant Granted Jun 23, 2026
Patent 12665950
CENTRALIZED IOT DASHBOARD
1y 5m to grant Granted Jun 23, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
84%
Grant Probability
99%
With Interview (+31.0%)
2y 8m (~1y 4m remaining)
Median Time to Grant
Low
PTA Risk
Based on 304 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month