Prosecution Insights
Last updated: August 17, 2026
Application No. 19/222,944

ADAPTIVE SECURITY ARCHITECTURE USING EMBEDDED PROTECTION IN VENDOR APPLICATIONS

Non-Final OA §101
Filed
May 29, 2025
Priority
May 31, 2022 — provisional 63/347,389 +3 more
Examiner
SAADOUN, HASSAN
Art Unit
Tech Center
Assignee
As0001 Inc.
OA Round
1 (Non-Final)
92%
Grant Probability
Favorable
1-2
OA Rounds
11m
Est. Remaining
91%
With Interview

Examiner Intelligence

Grants 92% — above average
92%
Career Allowance Rate
259 granted / 283 resolved
+31.5% vs TC avg
Minimal -0% lift
Without
With
+-0.4%
Interview Lift
resolved cases with interview
Fast prosecutor
2y 1m
Avg Prosecution
9 currently pending
Career history
289
Total Applications
across all art units

Statute-Specific Performance

§101
12.8%
-27.2% vs TC avg
§103
49.2%
+9.2% vs TC avg
§102
4.4%
-35.6% vs TC avg
§112
16.3%
-23.7% vs TC avg
Black line = Tech Center average estimate • Based on career data from 283 resolved cases

Office Action

§101
DETAILED ACTION This office action is in response to the application filed on 05/29/2025. Claims 1-20 are pending and are examined. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Priority Applicant’s benefit claim is hereby acknowledged of the U.S patent application No. 18/614,127, filed on March 22, 2024, which is a Continuation of U.S. Application No. 18/204,250, filed on May 31, 2023, which claims priority to U.S. Provisional Application No. 63/457,671, filed April 6, 2023, and U.S. Provisional Application No. 63/347,389, filed May 31, 2022, each of which are incorporated herein by reference in their entireties and for all purposes. Information Disclosure Statement The information disclosure statements (IDS) submitted on 05/29/2025, 07/23/2025, 11/28/2025, 03/17/2026, 05/14/2026 and 07/09/2026, were filed. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statements are being considered by the examiner. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the "right to exclude" granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. Claims 1-20 are rejected on the ground of nonstatutory obviousness-type double patenting as being unpatentable over claims 1-20 of any patents granted on application No. 18/614,127. Although the claims at issue are not identical, they are not patentably distinct from each other because they are both claiming a common subject matter, “generating a protection product based on a protection readiness corresponding to a vendor application data and providing it to the interface of the vendor application.”. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 19-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Independent claim 19 recites, “embed a component into an interface of a vendor application, wherein the component comprises a plurality of protection products; generate a protection product based on a protection readiness corresponding to a plurality of protection requirements; and provide, via the component, the protection product to the interface of the vendor application.” This is a process under its broadest reasonable interpretation which represents, embed a component into an interface of a vendor application, generate a protection product based on a protection readiness and provide the protection product to the interface of the vendor application . The underlying process would be performed exactly the same with in the human mind or with pencil and paper. Thus, all of the limitations are in fact a mental process and certain methods of organizing human activity; See MPEP §§ 2106.04(a)(2)(II)-(III). While the claims do recite some functional steps, the underlying operations recited in the claim are acts that could be performed mentally and by pen & paper without the use of a computer. Our reviewing court has concluded that mental processes include similar concepts of collecting, manipulating and providing data. See Intellectual Ventures I LLC v. Capital One Fin. Corp., 850 F.3d 1332, 1340 (Fed. Cir. 2017) (the Federal Circuit held “the concept of . . . collecting data, . . . recognizing certain data within the collected data set,” ineligible); and Electric Power Grp., LLC v. Alstom S.A., 830 F.3d 1350, 1353 (Fed. Cir. 2016) (merely selecting information, by content or source, for collection, analysis, and display does nothing significant to differentiate a process from ordinary mental processes). However, mental processes remain unpatentable even when automated to reduce the burden on the user of what once could have been done with pen and paper. See CyberSource Corp. v. Retail Decisions, Inc., 654 F.3d 1366, 1375 (Fed. Cir. 2011) (“That purely mental processes can be unpatentable, even when performed by a computer, was precisely the holding of the Supreme Court in Gottschalk v. Benson.”). We now turn to USPTO Step 2A, Prong 2, of the Revised Guidance to determine whether the abstract idea is integrated into a practical application. See Revised Guidance, 84 Fed. Reg. at 54–55. Accordingly, the claim recites an abstract idea. This judicial exception is not integrated into a practical application because the claim does not recite how the protection product is being accessed and identified. Accordingly the claim is directed to an abstract idea. The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception because the claim does not recite any additional elements to make the claim an inventive concept. Accordingly the claim is not patent eligible. Claim 20 depends on claim 19, and is of consequence rejected under 35 U.S.C. 101. Allowable Subject Matter Claims 1-18 would be allowable with a terminal disclaimer or rewritten to overcome the Non-Statutory Double Patenting rejection, set forth in this office action. Claims 19-20 would be allowable with a terminal disclaimer or rewritten to overcome the Non-Statutory Double Patenting rejection also should Applicant overcome the rejection under 35 U.S.C. 101, set forth in this office action. The following is an examiner’s statement of reasons for identifying allowable subject matter. The closest prior arts made of records are, Kudale et al. (U.S. Patent. No. 11,888,886 B1, referred to as Kudale), Belfiore, JR et al. (U.S Pub No. 2018/0,146,004 A1, referred to as Belfiore) and Kibler et al. (U.S Pub No. 2019/0,052,664 A1, referred to as Kibler). Kudale discloses a cyber security risk assessment system is described, the system may generate an input feature space including data associated with a computing system by collecting the data from a plurality of computer sources, compute a likelihood of data-security breach incidents based on the input feature space using a first computer model, recognize events based on the input feature space using a second computer model, and determine a severity of the data-security breach incident or the event using a third computer model. Belfiore discloses methods and systems for cybersecurity assessment of an organization's technology infrastructure include identifying features of the technology infrastructure and automatically generating a threat profile relevant to both the technology infrastructure and the organization's business (and/or business objectives), where the threat profile includes potential threat actors and threat scenarios applicable to the technology infrastructure. Kibler discloses systems and methods for assessing cybersecurity risk of a computer network include the use of a risk model application that is configured to determine an initial cyber risk score value based upon an underwriting process. A cyber risk data stream is sent from the client's computer network to the system processor to periodically calculate an updated cyber risk score based upon actual data. The system processor is adapted to use the data stream to generate client information that is accessible by the client via a web-based client portal. The cyber risk data stream can be actively monitored to identify a threat of a cybersecurity breach. However, regarding claim 1, the prior art of Kudale, Belfiore and Kibler when taken in the context of the claim as a whole do not disclose nor suggest, “accessing, by the one or more processing circuits, data of the vendor application; generating, by the one or more processing circuits, a protection product based on a protection readiness corresponding to a plurality of protection requirements, the protection readiness corresponding to the data; and providing, by the one or more processing circuits via the component, the protection product to the interface of the vendor application.”. Regarding claim 10, the prior art of Kudale, Belfiore and Kibler when taken in the context of the claim as a whole do not disclose nor suggest, “access data of the vendor application; identify a protection product based on a protection readiness corresponding to one or more protection requirements, the protection readiness corresponding to the data; and provide, via the component, the protection product to the interface of the vendor application.”. Regarding claim 19, the prior art of Kudale, Belfiore and Kibler when taken in the context of the claim as a whole do not disclose nor suggest, “generate a protection product based on a protection readiness corresponding to a plurality of protection requirements; and provide, via the component, the protection product to the interface of the vendor application.”. Claims 2-9 depends on claim 1, claims 11-18 depend on claim 10 and claim 20 depends on claim 18, and are of consequence identified as allowable. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: See PTO-892. Any inquiry concerning this communication or earlier communications from the examiner should be directed to HASSAN SAADOUN whose telephone number is (571)272-8408. The examiner can normally be reached Mon-Fri 9:00-5:00. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Mehrmanesh Amir can be reached at 571-2703351. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /HASSAN SAADOUN/Examiner, Art Unit 2435 /AMIR MEHRMANESH/Supervisory Patent Examiner, Art Unit 2435
Read full office action

Prosecution Timeline

May 29, 2025
Application Filed
Jul 27, 2026
Non-Final Rejection mailed — §101 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12684003
APPROACHES TO INGESTING INFORMATION REGARDING DIGITAL ACTIVITIES PERFORMED ACROSS DIFFERENT SERVICES AND USING THE SAME FOR DETECTING THREATS
2y 2m to grant Granted Jul 14, 2026
Patent 12681830
DYNAMIC SYSTEM RESOURCE-SENSITIVE MODEL SOFTWARE AND HARDWARE SELECTION
1y 10m to grant Granted Jul 14, 2026
Patent 12659338
CYBER SECURITY RESTORATION ENGINE
2y 10m to grant Granted Jun 16, 2026
Patent 12652295
ARRANGEMENT AND A METHOD OF THREAT DETECTION IN A COMPUTING DEVICE OR A COMPUTER NETWORK
2y 6m to grant Granted Jun 09, 2026
Patent 12652297
AUTOMATIC RISK REMEDIATION IN MULTI-CLOUD ENVIRONMENT
1y 10m to grant Granted Jun 09, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
92%
Grant Probability
91%
With Interview (-0.4%)
2y 1m (~11m remaining)
Median Time to Grant
Low
PTA Risk
Based on 283 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month