Prosecution Insights
Last updated: October 01, 2026
Application No. 19/211,559

Systems and Methods for Network Traffic Classification and Filtering via Fingerprinting and Machine Learning

Non-Final OA §103§DOUBLEPATENT
Filed
May 19, 2025
Priority
Feb 12, 2025 — provisional 63/757,468
Examiner
DESROSIERS, EVANS
Art Unit
2491
Tech Center
2400 — Computer Networks
Assignee
Salesforce Inc.
OA Round
1 (Non-Final)
83%
Grant Probability
Favorable
1-2
OA Rounds
1y 7m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 83% — above average
83%
Career Allowance Rate
866 granted / 1046 resolved
+24.8% vs TC avg
Strong +23% interview lift
Without
With
+23.1%
Interview Lift
resolved cases with interview
Typical timeline
2y 12m
Avg Prosecution
22 currently pending
Career history
1072
Total Applications
across all art units

Statute-Specific Performance

§101
11.2%
-28.8% vs TC avg
§103
52.5%
+12.5% vs TC avg
§102
14.5%
-25.5% vs TC avg
§112
8.1%
-31.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 1046 resolved cases

Office Action

§103 §DOUBLEPATENT
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Detailed Action This communication is in response to the application filed on 5/19/2025 in which Claims 1-20 are presented for examination. Drawings The applicant’s drawings submitted on 5/19/2025 are acceptable for examination purposes. Double Patenting The non-statutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory obviousness-type double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); and In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on a nonstatutory double patenting ground provided the conflicting application or patent either is shown to be commonly owned with this application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. Effective January 1, 1994, a registered attorney or agent of record may sign a terminal disclaimer. A terminal disclaimer signed by the assignee must fully comply with 37 CFR 3.73(b). Claims 1-20 are provisionally rejected on the ground of nonstatutory obviousness-type double patenting as being unpatentable over claims 1-20 of US patent application No. 19211563. This is a provisional double patenting rejection since the conflicting claims have not yet been patented. Claims 1-20 recite similar limitations as claims 1-20 of US application No. 19211563 as follows: Instant application US Application No. 19211563 Claim 1. An application gateway within a computing services environment, comprising: a communication interface configured to receive a plurality of application-layer request messages directed to a domain accessible via the computing services environment; a fingerprint database storing a plurality of predetermined filter fingerprint values; a fingerprint engine configured to determine fingerprint information based on an application-layer request message of the plurality of application-layer request messages, the fingerprint information including a locality-based fingerprint determined based on a locality- sensitive hashing function that maps similar input values to similar output values, the fingerprint information including a entropy-based fingerprint sensitive to an amount of information stored in data; and a fingerprint filter configured to block the application-layer request message from being transmitted to a request destination upon determining that the fingerprint information matches a predetermined filter fingerprint value of the plurality of predetermined filter fingerprint values. Claims 9, 17. Claim 1. A method implemented at a computing system, the method comprising: determining a plurality of training data observations corresponding to a plurality of application-layer request messages received at the computing system, the plurality of training data observations including a plurality of fingerprint values determined based on content associated with the plurality of application-layer request messages, a first subset of the plurality of application-layer request messages being classified as malicious, a second subset of the plurality of application-layer request messages being classified as legitimate; determining a classical support vector machine based on a quantum kernel, the quantum kernel being determined based on a quantum feature map and a plurality of quantum states, the quantum feature map embedding the plurality of fingerprint values into a quantum space corresponding to the quantum states; determining a fingerprint value for an application-layer request message received at an application gateway within the computing system; and blocking the application-layer request message from reaching a destination within the computing system based on the fingerprint value and a classification performed by the classical support vector machine. Claims 12, 20. The table above shows that, although the corresponding claims are directed to different statutory categories, the US patent application No. 19211563 implemented on a computer would render the claims in the instant application obvious. It is clearly obvious that the (US application No. 19211563) substantially discloses the subject matter of claim 1 of the instant Application. The Applicant merely broadens the scope of the instant application by deleting a few elements from the (US application No. 19211563). This is a provisional obviousness-type double patenting rejection. The claims 2-8 and 18-20 included in the statement of rejection but not specifically addressed in the body of the rejection have inherited the deficiencies of their parent claim and have not resolved the deficiencies. Therefore, they are rejected based on the same rationale as applied to their parent claims above. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of pre-AIA 35 U.S.C. 103(a) which forms the basis for all obviousness rejections set forth in this Office action: (a) A patent may not be obtained though the invention is not identically disclosed or described as set forth in section 102 of this title, if the differences between the subject matter sought to be patented and the prior art are such that the subject matter as a whole would have been obvious at the time the invention was made to a person having ordinary skill in the art to which said subject matter pertains. Patentability shall not be negatived by the manner in which the invention was made. Claims 1-18 are rejected under pre-AIA 35 U.S.C. 103(a) as being unpatentable over HARJANTO U.S. Patent application No. 20120317622 A1 (hereinafter " HARJANTO ") in view of Montoya US 20210014205 A1. As to claim 1, HARJANTO teaches an application gateway within a computing services environment, comprising: a communication interface configured to receive a plurality of application-layer request messages directed to a domain accessible via the computing services environment (HARJANTO Pa. [0009]) [client device authentication at the application layer, such a message generates a responsive message that indicates denial of the request due to inadequate authorization]; a fingerprint database storing a plurality of predetermined filter fingerprint values (HARJANTO Pa. [0048]) [a digital fingerprint stored in client device whitelist 424 (FIG. 4) as a precondition to performing services at the request of client device 102] [0045] [digital fingerprint 322 may be stored in volatile memory and erased after transmission of a challenge response. In another embodiment, digital fingerprint 322 may be stored in persistent memory and written over each time a new fingerprint is generated by fingerprint logic 321]; and a fingerprint filter configured to block the application-layer request message from being transmitted to a request destination upon determining that the fingerprint information matches a predetermined filter fingerprint value of the plurality of predetermined filter fingerprint values (HARJANTO Pa. [0061-0063]) [application-layer server protocol logic 422 can determine that digital fingerprint 322 matches a digital fingerprint in client device whitelist 424 if all "must match" portions match and no more that a predetermined number of "optional match" portions mismatch- [0063] (If the encoded digest of the authorization response message of step 510 matches an encoded digest of any of client device whitelist 424, application-layer server protocol logic 422 grants authorization to application-layer client protocol logic 326 and reports the granting in step 512. In this illustrative example, the message of step 512 can be a HTTP 200 OK message. Conversely, if the encoded digest of the authorization response message of step 510 does not match any encoded digest of any of client device whitelist 424, application-layer server protocol logic 422 denies authorization to application-layer client protocol logic 326 and reports the denial in step 512. In this illustrative example, the message of step 512 can be another HTTP 401 Unauthorized message.)]. It is noted that HARJANTO not appear explicitly disclose a fingerprint engine configured to determine fingerprint information based on an application-layer request message of the plurality of application-layer request messages, the fingerprint information including a locality-based fingerprint determined based on a locality- sensitive hashing function that maps similar input values to similar output values, the fingerprint information including a entropy-based fingerprint sensitive to an amount of information stored in data. However, Montoya discloses a fingerprint engine configured to determine fingerprint information based on an application-layer request message of the plurality of application-layer request messages (Montoya Pa. [0014]) [An artificial neural network is a computational model that may, in some embodiments, be configured to determine and detect high-entropy information. This information is referred to herein as a fingerprint, but it can also be referred to as a watermark, signature, or other pattern], the fingerprint information including a locality-based fingerprint (Montoya Pa. [0037]) [fingerprint insertion component 34 may combine the obtained plaintext with the fingerprint locally] determined based on a locality- sensitive hashing function that maps similar input values to similar output values (Montoya Pa. [0117]) [executing a computer program to perform functions of the techniques by operating on input data and generating output] [0002] [Underlying most encryption algorithms are the principles of entropy and randomness, the algorithms being most successful if they completely obfuscate plaintext information via generated keystreams], the fingerprint information including a entropy-based fingerprint sensitive to an amount of information stored in data (Montoya Pa. [0012]) [trace the presence of high-entropy information (i.e., a fingerprint) in any communication system, e.g., practically regardless of the encryption algorithm used to obfuscate it] Thus, it would have been recognized by one of ordinary skill in the art before the effective filing date of the claimed invention, that applying the known technique taught by Montoya to the application-layer system of HARJANTO would have yield predictable results and resulted in an improved system, namely, a system that would exploit pseudo-randomness of any encryption scheme to evaluate and/or monitor secrecy of a channel or network. (Montoya Pa. [0001]) As to claim 2, the combination of HARJANTO and Montoya teaches wherein the fingerprint information includes a unified fingerprint that combines the locality-based fingerprint (Montoya Pa. [0117]) [executing a computer program to perform functions of the techniques by operating on input data and generating output] [0002] [Underlying most encryption algorithms are the principles of entropy and randomness, the algorithms being most successful if they completely obfuscate plaintext information via generated keystreams] and the entropy-based fingerprint (Montoya Pa. [0012]) [trace the presence of high-entropy information (i.e., a fingerprint) in any communication system, e.g., practically regardless of the encryption algorithm used to obfuscate it] Thus, it would have been recognized by one of ordinary skill in the art before the effective filing date of the claimed invention, that applying the known technique taught by Montoya to the application-layer system of HARJANTO would have yield predictable results and resulted in an improved system, namely, a system that would exploit pseudo-randomness of any encryption scheme to evaluate and/or monitor secrecy of a channel or network. (Montoya Pa. [0001]) As to claim 3, the combination of HARJANTO and Montoya teaches wherein the unified fingerprint also combines a third fingerprint determined by truncating a traffic feature of the application-layer request message (Montoya Pa. [0056]) [reducing the amount of data required by application-layer server protocol logic 422 and therefore traffic on wide area network 104 (FIG. 1).] As to claim 4, the combination of HARJANTO and Montoya teaches wherein the fingerprint information is determined based on traffic features selected from the group consisting of: User-Agent, Server Name, and Uniform Resource Identifier (Montoya Pa. [0031]) [resource identified by the URL (Uniform Resource Location)] As to claim 5, the combination of HARJANTO and Montoya teaches wherein the locality-sensitive hashing function is a vector of minimum hash values obtained by applying a plurality of independent hash functions over a plurality of n-grams of a feature of the application-layer request message (Montoya Pa. [0039]) [train machine-learning models to learn relevant features of encrypted data and to learn a classification based on the features, an encryption algorithm being used in some embodiments as a label into the classifier.] Thus, it would have been recognized by one of ordinary skill in the art before the effective filing date of the claimed invention, that applying the known technique taught by Montoya to the application-layer system of HARJANTO would have yield predictable results and resulted in an improved system, namely, a system that would exploit pseudo-randomness of any encryption scheme to evaluate and/or monitor secrecy of a channel or network. (Montoya Pa. [0001]) As to claim 6, the combination of HARJANTO and Montoya teaches wherein the entropy-based fingerprint is Shannon entropy computed over a plurality of n-grams of a feature of the application-layer request message (Montoya Pa. [0039]) [train machine-learning models to learn relevant features of encrypted data and to learn a classification based on the features, an encryption algorithm being used in some embodiments as a label into the classifier.] Thus, it would have been recognized by one of ordinary skill in the art before the effective filing date of the claimed invention, that applying the known technique taught by Montoya to the application-layer system of HARJANTO would have yield predictable results and resulted in an improved system, namely, a system that would exploit pseudo-randomness of any encryption scheme to evaluate and/or monitor secrecy of a channel or network. (Montoya Pa. [0001]) As to claim 7, the combination of HARJANTO and Montoya teaches wherein the fingerprint information includes a plurality of entropy-based fingerprints corresponding to a plurality of different traffic features of the application-layer request message (Montoya Pa. [0056]) [reducing the amount of data required by application-layer server protocol logic 422 and therefore traffic on wide area network 104 (FIG. 1).], plurality of entropy-based fingerprints including the entropy-based fingerprint (Montoya Pa. [0012]) [trace the presence of high-entropy information (i.e., a fingerprint) in any communication system, e.g., practically regardless of the encryption algorithm used to obfuscate it] Thus, it would have been recognized by one of ordinary skill in the art before the effective filing date of the claimed invention, that applying the known technique taught by Montoya to the application-layer system of HARJANTO would have yield predictable results and resulted in an improved system, namely, a system that would exploit pseudo-randomness of any encryption scheme to evaluate and/or monitor secrecy of a channel or network. (Montoya Pa. [0001]) As to claim 8, the combination of HARJANTO and Montoya teaches wherein the fingerprint information includes a plurality of locality-sensitive fingerprints corresponding to a plurality of different traffic features of the application-layer request message Montoya Pa. [0056]) [reducing the amount of data required by application-layer server protocol logic 422 and therefore traffic on wide area network 104 (FIG. 1).], plurality of locality-sensitive fingerprints including the locality-based fingerprint (Montoya Pa. [0117]) [executing a computer program to perform functions of the techniques by operating on input data and generating output] [0002] [Underlying most encryption algorithms are the principles of entropy and randomness, the algorithms being most successful if they completely obfuscate plaintext information via generated keystreams] and the entropy-based fingerprint (Montoya Pa. [0012]) [trace the presence of high-entropy information (i.e., a fingerprint) in any communication system, e.g., practically regardless of the encryption algorithm used to obfuscate it] Thus, it would have been recognized by one of ordinary skill in the art before the effective filing date of the claimed invention, that applying the known technique taught by Montoya to the application-layer system of HARJANTO would have yield predictable results and resulted in an improved system, namely, a system that would exploit pseudo-randomness of any encryption scheme to evaluate and/or monitor secrecy of a channel or network. (Montoya Pa. [0001]) As to claims 9-16, claim 9-16 recite the claimed that contain respectively similar limitations as claims 1-8; therefore, they are rejected under the same rationale. As to claims 17-20, claim 17-20 recite the claimed that contain respectively similar limitations as claims 1, 2&3, 4-5; therefore, they are rejected under the same rationale. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to EVANS DESROSIERS whose telephone number is (571)270-5438. The examiner can normally be reached Monday -Friday 8:00 am - 5:30 pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, William Korzuch can be reached at (571)272-7589. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /EVANS DESROSIERS/Primary Examiner, Art Unit 2491
Read full office action

Prosecution Timeline

May 19, 2025
Application Filed
Aug 19, 2026
Non-Final Rejection mailed — §103, §DOUBLEPATENT (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12744685
METHOD FOR COMPUTER-IMPLEMENTED SERVICE PROVISION IN A BLOCKCHAIN, CORRESPONDING BLOCKCHAIN NETWORK NODE AND COMPUTER PROGRAM
2y 6m to grant Granted Sep 22, 2026
Patent 12719698
METHOD AND SYSTEM FOR BLOCKCHAIN-BASED COOPERATIVE SOCIETY TRANSACTIONS
1y 11m to grant Granted Aug 25, 2026
Patent 12699794
SYSTEMS AND METHODS OF FACILITATING CONTROLLING ACCESS TO DATA
1y 12m to grant Granted Aug 04, 2026
Patent 12682086
ELECTRONIC ACCESS CONTROL SYSTEM
2y 1m to grant Granted Jul 14, 2026
Patent 12683993
SYSTEM AND METHOD FOR PROVIDING FLEET CYBER-SECURITY
2y 0m to grant Granted Jul 14, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
83%
Grant Probability
99%
With Interview (+23.1%)
2y 12m (~1y 7m remaining)
Median Time to Grant
Low
PTA Risk
Based on 1046 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month