Prosecution Insights
Last updated: August 15, 2026
Application No. 19/231,203

SYSTEM AND METHOD FOR HIGHLY SECURE REMOTE CONNECTION PATHWAYS BETWEEN ENDPOINT DEVICES AND CLOUD DESKTOPS

Non-Final OA §101§103§112
Filed
Jun 06, 2025
Priority
Jun 06, 2024 — provisional 63/656,957
Examiner
NANO, SARGON N
Art Unit
Tech Center
Assignee
Workspot Inc.
OA Round
1 (Non-Final)
81%
Grant Probability
Favorable
1-2
OA Rounds
1y 8m
Est. Remaining
79%
With Interview

Examiner Intelligence

Grants 81% — above average
81%
Career Allowance Rate
549 granted / 680 resolved
+20.7% vs TC avg
Minimal -2% lift
Without
With
+-1.6%
Interview Lift
resolved cases with interview
Typical timeline
2y 11m
Avg Prosecution
34 currently pending
Career history
726
Total Applications
across all art units

Statute-Specific Performance

§101
26.5%
-13.5% vs TC avg
§103
32.7%
-7.3% vs TC avg
§102
20.8%
-19.2% vs TC avg
§112
10.7%
-29.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 680 resolved cases

Office Action

§101 §103 §112
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION This office action is responsive to application filed on 6/6/2025. Claims 1-21 are pending examination. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 6 and 16 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. The claims recite connection analyzer that accesses a “model template” to create connection pathway model; and accessing “model template” to create pathway model.. Although the specification describes a “connection pathway template” and a “pathway model template”, the claims do not recite those terms. Accordingly, it is unclear whether the claimed “model template” corresponds to the disclosed “connection pathway template”, the disclosed “pathway model template, or some other structure. clarification is required. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-21 are rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception (i.e., a law of nature, a natural phenomenon, or an abstract idea) without significantly more. Step 2A, Prong One. Claim 1 recites limitations directed to: collecting connection information from an endpoint deice, a gateway, and a virtual desktop; storing current and historical connection information; comparing current connection information with historical connection models; and determining whether to block a connection based on the comparison. These limitations describe concepts involving the collection, analysis and evaluation of information to make a security determination, which are activities that can be practically performed in the human mind or with pen and paper. For example, a network administrator could review a user’s current and historical connection information and decide whether to permits or deny access. Step 2A, Prong Two. The claims do not integrate the abstract idea into a practical application. The additional elements including an endpoint device; one or more servers; a gateway; monitors; supervisors; databases; a control plane; and a connection orchestrator are recited at a high level of generality and perform their ordinary functions of collecting, storing, transmitting and processing data. The claims do not recite an improvement to computer functionality, network communications, remote-desktop protocols, or virtual desktop technology. Additionally, the claims do not recite any particular algorithm or technical mechanism for generating the connection pathway model or performing comparison. Step 2B. The claims do not recite an inventive concept because the additional elements, individually and as an ordered combination, amount to well-understood, routine and conventional computer activities, such as monitoring network activity, storing information in databases, analyzing data, and allowing or blocking connections. The dependent claims do not significantly more than the abstract idea. Accordingly, when considered individually and as an ordered combination, the claims apply the abstract idea using generic computer components and therefore do not recite patent eligible subject matter. Claims 1-21 are therefore rejected under 35 USC § 101. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-21 are rejected under 35 U.S.C. 103 as being unpatentable over Sinha et al. U.S. patent Pub. No. 2024/0114068 (referred to herein after as Sinha) further in view of Pole U.S. Patent Pub. No. 2024/0080357 (referred to herein after as Pole). As to claim1, Sinha teaches a system providing a secure pathway between an endpoint device and a virtual desktop executed by one or more servers, the system comprising: a client monitor that receives connection information from an endpoint device operated by a user during an endpoint device stage of a connection pathway (see paragraph 0041, Sinha teaches desktop client 210(client monitor) running on endpoint device 240 and monitoring latency, response time, and other metrics; paragraph 0043 further explains that the monitoring service collects context data); a gateway monitor receiving connection information from a gateway accessible by the endpoint device during a gateway stage of the connection pathway (see at least paragraph 0040, Sinha teaches a protocol gateway agent 232 (gateway monitor). The gateway agent monitors activity on the gateway and assists the desktop service control plane with gateway management); a virtual desktop monitor receiving connection information from the virtual desktop during a desktop stage of the connection pathway (see at least paragraph 0042, Sinha teaches a managed cloud desktop 222 (desktop stage) and desktop agent 230 (virtual desktop monitor), which monitors activity on the managed cloud desktop and communicates with the desktop control plane); a real-time connection database storing the connection information from the client monitoring interface, gateway monitor and virtual desktop monitor (see at least paragraph 0043, Sinha teaches that the desktop service control plane includes a monitoring service having data collection engine and an analysis engine that collect endpoint context data and connection quality information; paragraph 0036, explains that the control plane continuously gathers latency and packet drop information from both sides of the remote desktop connection); a models database storing a connection pathway model with connection information from previous connections made by an endpoint device operated by the user (see at least paragraph 0029, Sinha teaches that the system produces performance baseline metrics for each user from endpoint-device context; paragraph 0008 and 0010, disclose that the analysis engine compares collected connection data against baseline values associated with the endpoint context); and a connection orchestrator that compares the connection pathway model with the connection information received by at least one of the client monitor, the gateway monitor, or the virtual desktop monitor (see at least paragraph 0036, Sinha teaches that eh desktop service control plane monitors and analyses operational data; paragraph 0043 teaches that he control plane includes an analysis engine and monitoring service; paragraph 0008, teaches comparing connection metrics to baseline values) Sinha teaches the invention as mentioned above. Sinha does not explicitly teach “determines whether to block the connection based on the comparison”. However, Pole (2024/0080357) teaches in abstract and claim 1, storing client device information and comparing usernames and IP addresses against stored information. If the information matches, access is permitted and restricting access when comparison fails (claim 3). It would have been obvious to one of the ordinary killed in the art, before the effective filing date, to combine the teachings of Pole wit those of Sinha to improve security by proactively preventing suspicious connections from accessing cloud desktops instead of merely detecting abnormal behavior after the connection had already been established. As to claim 2, Sinha-Pole teaches the system of claim 1, wherein the models database includes a plurality of connection pathway models (multiple baseline metrics for multiple endpoint contexts and cloud regions), each associated with the user (baselines generated for each user’s endpoint context), and wherein the connection orchestrator compares all of the connection pathway models with the connection information (analysis engine compares connection metrics to baseline values) (see Sinha at least paragraphs 0005 and 0029). As to claim 3, Sinha-Pole teaches the system of claim 1, further comprising: a client connection supervisor coupled to the endpoint device (desktop cline 210 executes on endpoint device 240 and communicates with the desktop control plane); a gateway connection supervisor coupled to the gateway; a desktop connection supervisor coupled to the virtual desktop (gateway agent 232 is deployed on the gateway virtual machine and monitors gateway activity); and a control plane coupled to the client connection supervisor, gateway connection supervisor and desktop connection supervisor, (the desktop service control plane orchestrates all layers of the cloud desktop service and coordinates gateways, desktop templates, connection brokers and other resources) the control plane including the connection analyzer (the desktop service control plane includes monitoring service comprising a data collection engine and an analysis engine- paragraphs 0038), the control plane operable to control one of the client connection supervisor, gateway connection supervisor and desktop connection supervisor to block the connection(see Pole paragraph 0006 and claims 3, 5 and 9 , Pole teaches restricting user access when usernames or IP addresses do not match stored information. Pole further teaches a dedicated gateway control service that provides user and device information to an agent in the public cloud infrastructure. Furthermore, Pole teaches denying access across cloud regions and desktop pools). As to claim 4, Sinha-Pole teaches the system of claim 1, wherein the connection orchestrator is operable to flag the connection based on the comparison (see Sinha paragraphs 0008 and 0024, teaches the analysis engine determines substandard performance based on comparing connection metrics to baseline values and generates alerts when standard performance is detected). As to claim 5, Sinha-Pole teaches the system of claim 1, wherein the connection orchestrator is operable to perform the comparison at each of the stages of the connection pathway (see Sinha, paragraphs 0006, 0038,0040 and 0042, teaches that the desktop service control continuously gathers latency and packet drop information from both sides of every remote desktop protocol connection, including endpoint context and cloud region information). As to claim 6, Sinha-Pole teaches the system of claim 1, further comprising a connection analyzer that accesses a model template to create the connection pathway model with the connection information from previous connections made by an endpoint device operated by the user (see Sinha paragraphs 0004, 0029, 0034 and 0043) . As to claim 7, Sinha-Pole teaches the system of claim 1, further comprising another monitor and another supervisor, wherein the connection pathway includes another stage, wherein the another monitor collects information from the another stage, and the another supervisor blocks connection at the another stage (see Sinha paragraphs 0036, 0045; Pole paragraph 0038 and claim 6, Sinha teaches enterprise connectors, connection brokers, gateways and additional security infrastructure distributed across cloud regions. Pole further teaches denying access across cloud regions and desktop pools). As to claim 8, Sinha-Pole teaches the system of claim 1, wherein the connection information collected by the endpoint device monitor includes at least one of device operating system, device location, network type, IP address, gateway, a unique device identifier, and a unique network identifier (see Sinha paragraphs 0005, 0009 and Pole paragraphs 0006 and 0022), maintaining whitelists of approved users and client devices). As to claim 9, Sinha-Pole teaches the system of claim 1, wherein the connection information collected by the gateway monitor includes at least one of a gateway name, a gateway protocol, ports use, network tracking, a network latency, and an authentication method (see Sinha paragraphs 0006 and 0040 and Pole paragraphs 0022, 0040 and claim 2). As to claim10, Sinha-Pole teaches the system of claim 1, wherein the connection information collected by the Cloud desktop monitor includes at least one of a name of the gateway, a regional data center, and a network ID (see Sinha paragraphs 0004, 0006 and 0038, teaches that the control plane gathers information form the destination cloud region associated with each remote- desktop connection; Pole in paragraph 0029 defines a cloud region as a collection of computing resources, including protocol gateways, networks and servers located within a regional data center). Claims 11-21 do not teach anything above and beyond the limitations of claims 1-10 and rejected are for similar reasons. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. KATMORE US-20240080244-A1, discloses Systems and methods for enabling context-aware zero-trust network access (ZTNA) using security posture insights received from an endpoint agent are provided. According to an embodiment, of a Zero Trust Network Access (ZTNA) service module receives from an endpoint device an access request to a protected object. An identity of a user of the endpoint device is verified via an identity management system. When the identify verification is affirmative: (i) receiving from an endpoint agent running on the endpoint device, security posture information associated with one or more of the endpoint device, the user, and the protected object; (ii) determining based on a set of ZTNA policies and the security posture information whether to allow the access request; and (iii) when the determination is affirmative, granting access to the protected object by the user via the endpoint device. LIU ET AL U.S Patent Pub. No.20240080244, discloses Methods, systems, and computer readable media for testing a system under test (SUT). An example system includes a distributed processing node emulator configured for emulating a multi-processing node distributed computing system using a processing node communications model and generating intra-processing node communications and inter-processing node communications in the multi-processing node distributed computing system. At least a portion of the inter-processing node communications comprises one or more messages communicated with the SUT by way of a switching fabric. The system includes a test execution manager configured for managing the distributed processing node emulator to execute a pre-defined test case, monitoring the SUT, and outputting a test report based on monitoring the SUT during execution of the pre-defined test case. Any inquiry concerning this communication or earlier communications from the examiner should be directed to SARGON N NANO whose telephone number is (571)272-4007. The examiner can normally be reached 7:30 AM-3:30 PM. M.S.T.. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Nicholas Taylor can be reached at 571 272 3889. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /SARGON N NANO/Primary Examiner, Art Unit 2443
Read full office action

Prosecution Timeline

Jun 06, 2025
Application Filed
Oct 30, 2025
Response after Non-Final Action
Jul 15, 2026
Non-Final Rejection mailed — §101, §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12689603
Configuring a Monitor Mode for Suspicious Content in Emails
2y 6m to grant Granted Jul 21, 2026
Patent 12683986
Systems and methods for processing electronic communications
2y 10m to grant Granted Jul 14, 2026
Patent 12665768
OBLIVIOUS TRANSFER FROM KEY ENCAPSULATION MECHANISMS
2y 7m to grant Granted Jun 23, 2026
Patent 12665833
DYNAMIC MAPPING OF NETWORKS TO MULTI-TENANTED BGP SERVERS
1y 7m to grant Granted Jun 23, 2026
Patent 12659372
LINKAGE SYSTEM, METHOD, VEHICLE, STORAGE MEDIUM AND CHIP
2y 11m to grant Granted Jun 16, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
81%
Grant Probability
79%
With Interview (-1.6%)
2y 11m (~1y 8m remaining)
Median Time to Grant
Low
PTA Risk
Based on 680 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month