Prosecution Insights
Last updated: October 02, 2026
Application No. 19/218,919

DATA PRIVACY ARCHITECTURE, SYSTEMS, AND METHODS

Non-Final OA §101§103
Filed
May 27, 2025
Priority
Jun 30, 2022 — provisional 63/367,426 +2 more
Examiner
AHSAN, SYED M
Art Unit
Tech Center
Assignee
Truist Bank
OA Round
1 (Non-Final)
73%
Grant Probability
Favorable
1-2
OA Rounds
1y 12m
Est. Remaining
95%
With Interview

Examiner Intelligence

Grants 73% — above average
73%
Career Allowance Rate
220 granted / 301 resolved
+13.1% vs TC avg
Strong +22% interview lift
Without
With
+22.3%
Interview Lift
resolved cases with interview
Typical timeline
3y 4m
Avg Prosecution
42 currently pending
Career history
334
Total Applications
across all art units

Statute-Specific Performance

§101
13.4%
-26.6% vs TC avg
§103
52.2%
+12.2% vs TC avg
§102
13.2%
-26.8% vs TC avg
§112
17.7%
-22.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 301 resolved cases

Office Action

§101 §103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Priority This application is a continuation of U.S. Patent Application Serial No. 18/161,133, filed on January 30, 2023, which claims the benefit of U.S. Provisional Patent Application Serial Nos. 63/367,426, filed June 30, 2022, and 63/371,657, filed August 17, 2022, the entireties of which are herein incorporated by reference. Information Disclosure Statement The information disclosure statement (IDS) submitted on 06/02/2025 was filed after the mailing date of the Non-Provisional Patent Application on 05/27/2025. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. DETAILED ACTION This Office Action is in response to a Non-Provisional Patent Application received on 05/27/2025. In the application, claims 1-20 have been received for consideration and have been examined. Specification Applicant’s submitted specification has been reviewed and found to be in compliance. Drawings Applicant’s submitted drawings have been reviewed and found to be in compliance. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1–20 are rejected under 35 U.S.C. § 101 because the claimed invention is directed to a judicial exception—an abstract idea—without reciting additional elements that amount to significantly more than the judicial exception. Step 1: Statutory category Claims recite a “system” (claim 1) comprising a computing system, user device, data resources, processor, memory, and network connection and “method” (claim 20). Accordingly, claims 1, and 20 technically falls within the statutory category of a machine. Step 2A, Prong One: Judicial exception Claims 1 and 20 recite the following limitations: Receiving user data comprising personal information; Receiving a communication request concerning the use of the personal information; Transmitting the request to a data privacy application; Receiving personal-information usage data from external data resources; Filtering the usage data so that certain variables are determined to be private; and Communicating and displaying the filtered usage data to the user. These limitations recite the abstract idea of: Managing a request concerning the use of personal information by collecting information, reviewing or filtering the information according to privacy criteria, and communicating the resulting information to the requesting person. The identified limitations fall within the mental process grouping of abstract ideas because they recite observations, evaluations, judgments, and opinions that can practically be performed in the human mind or with the aid of pen and paper. For example, a person could receive a request concerning the use of personal information, obtain records from different sources, review the records, identify information considered private, remove unwanted portions, and provide the resulting information to the requester. The Specification confirms that at least portions of this process may be performed by human agents, including reviewing requests and identification documentation, determining whether additional documentation is required, examining documentation for legal sufficiency, filtering collected information, and performing quality-assurance review. The claimed concept is analogous to the collection, analysis, and display of information identified as abstract in Electric Power Group, LLC v. Alstom S.A., 830 F.3d 1350, 1353–54 (Fed. Cir. 2016). The MPEP similarly identifies broadly claimed collection, analysis, and display of information as a mental-process abstract idea. MPEP §§ 2106.04(a)(2)(III) and 2106.04(a)(2)(III)(C). Accordingly, claims 1 and 20 recite a judicial exception. Step 2A, Prong Two: Practical application The additional elements beyond the identified abstract idea include: A computing system; A user computing device having a processor and memory; Data resources; A network connection; A user software application; Wireless communication; A data privacy application; and A graphical user interface. Considered individually and in combination, these additional elements do not integrate the abstract idea into a practical application. The computing system, processor, memory, user device, data resources, and network connection are recited only as generic computer components performing their ordinary functions of receiving, processing, transmitting, and displaying information. The Specification expressly contemplates implementation using a general-purpose computer and broadly describes the user device as a conventional smartphone, laptop, desktop computer, server, workstation, or cloud-based system using known operating systems. Receiving and transmitting the request over a wireless network merely uses a computer as a tool to implement the abstract information-management process. Receiving or transmitting data over a network ordinarily does not integrate an abstract idea into a practical application. See buySAFE, Inc. v. Google, Inc., 765 F.3d 1350, 1355 (Fed. Cir. 2014); TLI Communications LLC v. AV Automotive, LLC, 823 F.3d 607, 610–13 (Fed. Cir. 2016); MPEP § 2106.05(f). The graphical user interface merely permits entry of a request and displays the resulting information. Claims 1, and 20 do not recite a specific interface layout, interaction technique, or improvement in the operation of the user device. The limitation that filtering “allows for the computing system to be simplified by eliminating undesired interactions” merely states an intended benefit or result. The claim does not identify: What constitutes an “undesired interaction”; What particular variables are determined to be private; What filtering rules or algorithm are applied; How the filtering modifies operation of the computer or network; or How the filtering technically causes the alleged simplification. A result-oriented limitation that identifies a desired outcome without specifying a particular technological mechanism for achieving it does not integrate an abstract idea into a practical application. See Electric Power Group, 830 F.3d at 1356; Two-Way Media Ltd. v. Comcast Cable Communications, LLC, 874 F.3d 1329, 1337–39 (Fed. Cir. 2017). Although the Specification alleges reduced network traffic and simplified computer operation, claims 1, and 20 do not recite a particular technical arrangement that produces those results. Accordingly, claims 1, and 20 are directed to the identified abstract idea. Step 2B: Significantly more The additional elements, considered individually, do not amount to significantly more than the abstract idea. Generic processors, memories, computing devices, software applications, network connections, data resources, and graphical user interfaces merely perform conventional computer functions such as: Receiving data; Storing data; Transmitting data; Applying rules to data; Formatting data; and Displaying data. See Alice Corp. v. CLS Bank International, 573 U.S. 208, 223–26 (2014); Content Extraction & Transmission LLC v. Wells Fargo Bank, N.A., 776 F.3d 1343, 1347–48 (Fed. Cir. 2014); and Electric Power Group, 830 F.3d at 1354–56. The ordered combination likewise amounts to no more than implementing the abstract process through a conventional client-server request-and-response arrangement. Unlike BASCOM Global Internet Services, Inc. v. AT&T Mobility LLC, 827 F.3d 1341 (Fed. Cir. 2016), claim 1 does not require a filtering tool installed at a particular network location, individualized filtering associated with particular network accounts, or another nonconventional arrangement of computer components. Accordingly, claims 1, and 20 do not recite significantly more than the judicial exception and is ineligible under 35 U.S.C. § 101. Dependent claims 2–19 Claims 2–19 are rejected for the same reasons as claims 1 and 20. Their additional limitations do not integrate the abstract idea into a practical application or provide an inventive concept. Claim 2 recites receiving login credentials. This is insignificant data gathering performed using the generic user device. Claim 3 recites verifying credentials of an unauthenticated user. Verifying submitted information is itself a mental evaluation and no particular technological authentication procedure is claimed. Claim 4 recites displaying a request for identification documentation. Displaying a request is an insignificant pre-solution or extra-solution activity performed by a generic GUI. Claim 5 recites receiving identification documentation. Receiving documentation constitutes data gathering and does not meaningfully limit the abstract idea. Claim 6 recites verifying identification documentation. A person can review documentation and determine whether it sufficiently establishes identity. No particular image-processing, biometric, cryptographic, or document-authentication technology is claimed. Claim 7 recites filtering user data before transmitting the communication. Filtering information according to privacy criteria is part of the identified abstract mental process. The claim does not recite a specific filtering algorithm or technical mechanism. Claim 8 recites collecting personal-information usage data from data sources. Collecting information is insignificant data-gathering activity ancillary to the subsequent evaluation and communication of the information. Claim 9 recites transforming the filtered information into communication. This amounts to generic formatting or presentation of information without specifying a particular data transformation or improvement in computer operation. Claims 10 and 11 merely specify whether the request is received from an authenticated or unauthenticated user. These limitations identify the status of the requesting person but do not improve authentication or computer technology. Claims 12 and 13 recite hosting the request or resulting communication on the data privacy application. Hosting information through an application merely confines the abstract idea to a particular technological environment. Claim 14 recites providing access to the privacy application through a dashboard. The dashboard is a generic graphical interface, and no particular layout, data structure, interaction technique, or improved interface functionality is claimed. Claims 15 and 16 recite receiving the communication request and identification documentation through the dashboard. These limitations merely use the dashboard to collect information. Claim 17 recites making the resulting communication accessible through a user-specific dashboard. This merely displays information through a generic interface. Claims 18 and 19 recite respectively providing a generic dashboard to an unauthenticated user and a user-specific dashboard to an authenticated user. These limitations apply conventional access-dependent presentation rules and do not recite a specific improvement in graphical interfaces, authentication technology, or computer security. Even when considered as ordered combinations with claim 1, the dependent limitations merely add conventional data collection, identity review, application hosting, access control, and presentation of information. They do not require a particular machine integral to the abstract idea, effect a transformation of an article into a different state or thing, improve the functioning of a computer, or apply the abstract idea through a meaningful technological limitation. Conclusion For the foregoing reasons, claims 1–20 are directed to the abstract idea of collecting, evaluating, filtering, and communicating information concerning the use of personal information. The claims merely implement that abstract idea using generic computing devices, software applications, network communications, authentication activities, and graphical dashboards. Therefore, claims 1–20 do not integrate the judicial exception into a practical application and do not recite significantly more than the judicial exception. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-13, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Barday et al., (US20190266350A1) in view of Brannon et al., (US20210200902A1). Regarding claim 1, Barday discloses: a system for managing data, particularly a data-subject-access-request (“DSAR”) processing and fulfillment system used to provide an individual with information concerning personal data collected, stored, or processed by an organization. See Barday ¶¶ 16–20, 29–40 and 114. System components Regarding “a computing system,” Barday discloses a DSAR processing and fulfillment system comprising a data model generation server, data model population server, identity scanning server, DSAR processing and fulfillment server, databases, third-party servers, and remote computing devices. Barday ¶¶ 29–30; Fig. 1. Regarding “at least one user device including a computing device” having a processor and memory, Barday discloses remote computing devices including desktop computers, laptops, tablets, and smartphones. Barday further discloses a computer having a processing device, main memory, static memory, and data-storage device. Barday ¶¶ 30–38; Figs. 1 and 2A. Regarding “one or more data resources,” Barday discloses multiple databases, data models, data repositories, organization computer systems, and third-party data-aggregation systems containing personal data. Barday ¶¶ 30, 48, 54–55, 102–105 and 114; claims 2–5, 8 and 18–19. Regarding the claimed network connection, Barday discloses one or more wired or wireless computer networks connecting the servers, databases, third-party servers, and remote computing devices. The disclosed networks may include the Internet, LAN, intranet, cellular network, or other wired or wireless network. Barday ¶¶ 30–33. Software application and graphical interface Regarding receiving a user software application for installation and wirelessly communicating with the computing system through that application, Barday discloses that the DSAR system may be implemented as computer software, web-implemented software, or a computer program product; that software instructions may be transmitted or received over a network; and that a user may submit a DSAR through a computer software application, webform, chatbot, API, email, or other electronic mechanism. Barday ¶¶ 16, 23–27 and 34–38. Barday does not expressly state that the application is “received for installation” using the exact language of claim 1. However, it would have been obvious to provide Barday’s disclosed client software with a remote computing device for installation. Downloading and installing the client application was one of a finite number of conventional alternatives to accessing the same functions through a web browser, and Barday expressly contemplates both computer software applications and web-implemented software. Such implementation would predictably permit the remote user device to communicate with the DSAR system. Regarding access to a data privacy application through a graphical user interface, Barday discloses that the DSAR system is part of a privacy-compliance or privacy-management system and provides webforms, computer-screen displays, graphical interfaces, and a DSAR processing dashboard. Barday ¶¶ 13–20, 29, 42–47 and 59–88; Figs. 3–49. Receiving personal information and a usage request Regarding receiving user data comprising personal information, Barday defines personal data as including personal identifiable information such as names, addresses, dates of birth, Social Security numbers, biometric identifiers, browsing history, purchase history, and preferences. Barday ¶¶ 2–3. Barday’s webform receives information supplied by a data subject, and the system may receive account credentials, identifying information, out-of-wallet information, authentication responses, and identification documents. Barday ¶¶ 16–18 and 99–109. Regarding receiving a communication request related to usage of personal information, Barday discloses receiving a DSAR through a webform or software application. The DSAR may request the personal data held by the organization and information indicating whether and for what purpose the organization collects, stores, processes, or uses the personal data. Barday ¶¶ 3, 16–20, 42–55 and 114; claims 1–2, 7, 17–19. Transmitting and processing the request Regarding transmitting the communication request to the data privacy application, Barday discloses transmitting or routing the DSAR received through the webform, software application, or API to the DSAR processing and fulfillment system for verification and processing. Barday ¶¶ 16–20, 30–33 and 42–55; Fig. 2B. Collecting usage data from external resources Regarding receiving personal-information usage data from external data resources, Barday discloses: Identifying personal data associated with the requestor in one or more data repositories; Accessing data models identifying where personal information is stored; Accessing one or more external or third-party systems; Obtaining requested information from the data model; and Providing the data subject with information regarding what data the organization collects and the purpose for which it is collected or used. Barday ¶¶ 48, 54–55, 102–105 and 114; claims 2–5, 8 and 17–19. Filtering private information Barday does not expressly disclose filtering the retrieved personal-information usage data so that particular variables are determined to be private before providing the resulting information to the user. Brannon, however, teaches a privacy-management system that: Accesses personal data from one or more networked data assets; Scans the data assets to generate a catalog of personal information; Analyzes data models to identify particular portions of personal data based on privacy-related criteria; Separates data that should be retained from data that should be removed; and Removes the identified unwanted portion of the personal data. Brannon ¶¶ 2–6, 8–16, 25–30 and 34–42. In particular, Brannon teaches analyzing mapped personal data to identify a first portion meeting privacy criteria and automatically removing that portion. Brannon ¶¶ 6, 34–36. Brannon also recognizes the need to ensure that sensitive personal information associated with DSARs remains private. Brannon ¶¶ 3–4. Thus, Brannon teaches filtering personal data based on privacy-related variables or classifications before the data is further used or provided. It would have been obvious to modify Barday’s DSAR response system to apply Brannon’s privacy-data identification and removal process to the information collected for the response. Both references concern privacy-management systems that locate, and process personal data stored across organizational data resources. A person of ordinary skill would have been motivated to apply Brannon’s filtering before Barday communicates the DSAR results to: Prevent disclosure of sensitive or nonresponsive personal information; Ensure that only information appropriate for the requesting user is included; Comply with applicable privacy requirements; Reduce the amount of information requiring review and transmission; and Avoid additional communications caused by disclosure of unnecessary or inappropriate data. The combination would involve applying Brannon’s known privacy filtering to Barday’s known DSAR response data and would yield the predictable result of a response containing a filtered subset of the collected personal information. The statement that filtering “allows for the computing system to be simplified by eliminating undesired interactions” does not require a particular structure or filtering algorithm beyond the identified filtering. Moreover, the combined system would be capable of producing that result because removing nonresponsive, unnecessary, or sensitive portions before transmission reduces subsequent processing and communications relating to those portions. Communication and display of filtered results Barday discloses automatically obtaining the requested information, communicating the information to the requestor, and displaying the obtained information to the user as fulfillment of the DSAR. Barday ¶¶ 20 and 48; claims 17–19. Brannon additionally teaches generating and providing a privacy-data report after analyzing personal information according to privacy criteria. Brannon ¶¶ 48–58. Accordingly, Barday in view of Brannon teaches or suggests receiving the filtered information as a communication and displaying that communication through the user interface. Claim 1 is therefore unpatentable over Barday in view of Brannon. Regarding claim 20, it is a method claim and recites similar subject matter as claim 1 and therefore rejected under similar grounds of rejection. Regarding claim 2, the combination of Barday and Brannon discloses: receiving login credentials from a user. In particular, Barday teaches validating a user through account credentials and authenticating employees or customers based on successful login through an employee authentication system or consumer portal (Barday ¶¶ 18, 101 and 109). Regarding claim 3, the combination of Barday and Brannon discloses: verifying credentials of a user who has not yet been authenticated. Barday teaches receiving a DSAR, determining the authentication required, prompting the requestor for authentication information, and automatically validating the requestor before processing the request (Barday ¶¶ 18 and 98–107). Regarding claim 4, the combination of Barday and Brannon discloses: displaying a request for identification documentation. Barday teaches automatically issuing a request that the data subject verify identity against a required form of identification and prompting the requestor to provide identifying information or images of identifying documents (Barday ¶¶ 99 and 105–106; Fig. 46). Regarding claim 5, the combination of Barday and Brannon discloses: receiving identification documentation from the user, including an image of a birth certificate, Social Security card, driver’s license, contract, certificate, or other identifying document supplied through the requestor’s computing device (Barday ¶¶ 18, 106 and 108; claim 12). Regarding claim 6, the combination of Barday and Brannon discloses: verifying the identification documentation of a user before authenticating the user and processing the request. Barday teaches comparing submitted information with information obtained from third-party data-aggregation systems and authenticating the requestor when the information matches (Barday ¶¶ 100–107). Regarding claim 7, the combination of Barday and Brannon discloses: filtering personal data before the data is retained, removed, reported, or otherwise provided. (Brannon ¶¶ 6, 8–16, 25–30 and 34–42). As explained in claim 1, it would have been obvious to apply this filtering to Barday’s collected data before transmitting the DSAR response to the user. Regarding claim 8, the combination of Barday and Brannon discloses: collecting personal-information usage data from multiple data sources, including organization databases, data repositories, data models, third-party servers, and third-party aggregation systems (Barday ¶¶ 30, 48, 54–55, 102–105 and 114). Regarding claim 9, the combination of Barday and Brannon discloses: automatically obtaining requested personal information and communicating or displaying the obtained information to the requester. Barday ¶¶ 20 and 48. Brannon teaches generating a privacy-data report from analyzed personal data and providing that report to an individual (Brannon ¶¶ 48–58). It would have been obvious to transform the filtered data into an electronic communication or report because this is the ordinary and expressly taught mechanism for delivering the results of the privacy request. Regarding claim 10, the combination of Barday and Brannon discloses: DSARs received from authenticated users, including employees and customers successfully logged into an employee authentication system or consumer portal using their credentials (Barday ¶¶ 101 and 109). Regarding claim 11, the combination of Barday and Brannon discloses: receiving a DSAR before authenticating the requestor and thereafter determining the authentication required and validating the requestor. Thus, at the time the request is received, the requestor may be unauthenticated (Barday ¶¶ 16–18 and 98–100). Regarding claim 12, the combination of Barday and Brannon discloses: receiving, storing, routing, and managing the DSAR within the privacy-management application or ticket-management system (Barday ¶¶ 16–20 and 39–47; Fig. 2B). Regarding claim 13, the combination of Barday and Brannon discloses: obtaining the requested information and displaying it through the web-implemented DSAR fulfillment system. (Barday ¶¶ 20 and 48; claims 17–19). Claim(s) 14-19 are rejected under 35 U.S.C. 103 as being unpatentable over Barday et al., (US20190266350A1) in view of Brannon et al., (US20210200902A1) and further in view of Hollander et al., (US20200301939A1). Regarding claim 14, the combination of Barday and Brannon discloses: accessing the privacy-management system through a graphical interface and further discloses a DSAR request-processing dashboard. (Barday ¶¶ 19 and 59–88; Figs. 12–43). The combination of Barday and Brannon fails to disclose: a software-based dashboard displayed through a graphical user interface, including dashboard views that present data retrieved from networked database resources. However, Hollander discloses: a software-based dashboard displayed through a graphical user interface, including dashboard views that present data retrieved from networked database resources (Hollander ¶¶ 97, 129–144; Figs. 24A–24D). It would have been obvious to an ordinary skill in the art before the effective filing date of the claimed invention to combine references teach providing access to the data privacy application through a dashboard displayed on the user device. Regarding claim 15, the combination of Barday, Brannon and Hollander discloses: Barday discloses receiving the DSAR through an electronically displayed webform or other graphical interface (Barday ¶¶ 16–18 and 42–55). Hollander teaches interactive dashboard interfaces through which users access data and perform dashboard operations (Hollander ¶¶ 97, 129–144). It would have been obvious to place Barday’s DSAR webform within the combined dashboard so the communication request could be received through the same interface. Regarding claim 16, the combination of Barday, Brannon and Hollander discloses: Barday discloses prompting for and receiving identification information and images of identification documents through the requestor’s computing device. Barday ¶¶ 99 and 105–106. For the reasons stated for claim 15, it would have been obvious to receive the documentation through the dashboard interface used to submit and manage the privacy request. Regarding claim 17, the combination of Barday, Brannon and Hollander discloses: Barday discloses obtaining and displaying the personal-information results to the user (Barday ¶¶ 20 and 48). Hollander discloses authenticated-user dashboards, “My Dashboard” displays, user-specific filters, and linking individual users with unique dashboard identifiers to preserve user-specific customization (Hollander ¶¶ 97, 129–144 and 329–333). It would have been obvious to an ordinary skill in the art before the effective filing date of the claimed invention to combine references teach providing access to the data privacy application through a dashboard displayed on the user device. Regarding claim 18, the combination of Barday, Brannon and Hollander discloses: Hollander discloses that a dashboard may be shared with anonymous, unauthenticated users. Hollander explains that where users are not authenticated, a dashboard may be shared with all anonymous users (Hollander ¶ 132 and Table C). A dashboard shared generally with anonymous users rather than populated with authenticated-user information constitutes the claimed generic dashboard. It would have been obvious to an ordinary skill in the art before the effective filing date of the claimed invention to combine references teach providing access to the data privacy application through a dashboard displayed on the user device. Regarding claim 19, the combination of Barday, Brannon and Hollander discloses: Hollander discloses that registered users log in using valid credentials and are provided a “My Dashboard” display. Hollander further teaches storing user-specific dashboard settings and filters and linking a unique dashboard identifier to a particular user to preserve that user’s customizations (Hollander ¶¶ 97, 129–130, 139–144 and 329–333). Accordingly, Hollander teaches a user-specific dashboard provided when the user is authenticated. It would have been obvious to an ordinary skill in the art before the effective filing date of the claimed invention to combine references teach providing access to the data privacy application through a dashboard displayed on the user device. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to SYED M AHSAN whose telephone number is (571)272-5018. The examiner can normally be reached 8:30 AM - 6:00 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, William Korzuch can be reached at 571-272-7589. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /SYED M AHSAN/Primary Examiner, Art Unit 2491
Read full office action

Prosecution Timeline

May 27, 2025
Application Filed
Sep 10, 2026
Non-Final Rejection mailed — §101, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12748869
Dynamically Controlling Access to Linked Content in Electronic Communications
2y 1m to grant Granted Sep 29, 2026
Patent 12732494
NETWORK REPOSITORY FUNCTION FAILURE HANDLING
2y 1m to grant Granted Sep 08, 2026
Patent 12726513
Method and Apparatus for Route Verification and Data Sending, Device, and Storage Medium
2y 11m to grant Granted Sep 01, 2026
Patent 12721547
AUTHENTICATION DEVICE, AUTHENTICATION METHOD, AND RECORDING MEDIUM
1y 11m to grant Granted Sep 01, 2026
Patent 12719930
SYSTEM FOR PROVIDING END-TO-END SECURITY SERVICE USING PORTABLE SECURITY UNIT BASED ON INTELLIGENT HOME NETWORK
2y 9m to grant Granted Aug 25, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
73%
Grant Probability
95%
With Interview (+22.3%)
3y 4m (~1y 12m remaining)
Median Time to Grant
Low
PTA Risk
Based on 301 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month