Prosecution Insights
Last updated: September 17, 2026
Application No. 19/235,251

Secure Access Via A Remote Client

Non-Final OA §103
Filed
Jun 11, 2025
Priority
May 16, 2022 — provisional 63/342,626 +2 more
Examiner
BROWN, ANTHONY D
Art Unit
Tech Center
Assignee
Sonet Io Inc.
OA Round
1 (Non-Final)
85%
Grant Probability
Favorable
1-2
OA Rounds
1y 5m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 85% — above average
85%
Career Allowance Rate
744 granted / 871 resolved
+25.4% vs TC avg
Strong +15% interview lift
Without
With
+15.1%
Interview Lift
resolved cases with interview
Typical timeline
2y 8m
Avg Prosecution
23 currently pending
Career history
888
Total Applications
across all art units

Statute-Specific Performance

§101
15.5%
-24.5% vs TC avg
§103
51.3%
+11.3% vs TC avg
§102
17.2%
-22.8% vs TC avg
§112
5.4%
-34.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 871 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer. Double Patenting Claims 1, 10 and 19-20 are rejected on the ground of non statutory double patenting as being unpatentable over claims 1, 10 and 19 of U.S. Patent No. 12107828. Although the claims at issue are not identical, they are not patentably distinct from each other because the limitations in each claim set relate to the same concept. US Patent App. 19/235,251 US Patent 12341782 A non-transitory computer readable medium comprising instructions that, when executed by one or more hardware processors, causes performance of operations comprising: transmitting, to a browser executed on a computing device of a user, a first set of media instructions that cause the browser to render a user interface for a client application; receiving, from the browser, a first set of upstream information entered via the user interface rendered by the browser, wherein the first set of upstream information comprises one or more user inputs to the client application; determining that the user has permission to share the first set of upstream information; responsive to determining that the user has permission to share the first set of upstream information, transmitting the first set of upstream information to the client application for mimicking the one or more user inputs by the client application; receiving, from the client application, a second set of media instructions, wherein the second set of media instructions represent the user interface of the client application updated based on the one or more user inputs; and transmitting, to the browser, the second set of media instructions, wherein the second set of media instructions cause the browser to render the updated user interface of the client application. A non-transitory computer readable medium comprising instructions that, when executed by one or more hardware processors, causes performance of operations comprising: receiving, from a client application, a first set of information for a user interface of a software application executed at a remote server, wherein the first set of information includes first content to be presented to a user of the client application; determining that the user lacks permission to access at least a subset of the first content based on permissions for the user; responsive to determining that the user lacks permission to access at least the subset of the first content, modifying the first content to remove at least the subset of the first content to generate a modified first content; generating a first set of media instructions for a user browser, the first set of media instructions including the modified first content; and transmitting, to the user browser at a computing device of the user, the first set of media instructions, wherein the first set of media instructions represent the user interface including the modified first content. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-5, 10-14 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Litty (US Patent 11,611,482) in view of Koszek (US Patent Pub. 2019/0227857). As per claims 1, 10 and 19: Litty discloses a non-transitory computer readable medium comprising instructions that, when executed by one or more hardware processors, causes performance of operations comprising (see abstract): transmitting, to a browser executed on a computing device of a user, a first set of media instructions that cause the browser to render a user interface for a client application (Col 5, lines 8-15; An image of the page is sent by surrogate browsing system 302 to client 102 (308). In some embodiments, the image sent to Alice is transcoded so that, for example, an attacker cannot send malicious pixels to Alice. When Alice interacts with the image via her browser 104, her events, such as mouse clicks and keyboard presses, are observed and transmitted by the JavaScript executing on client 102 to virtual machine 304 (310)); receiving, from the browser, a first set of upstream information entered via the user interface rendered by the browser, wherein the first set of upstream information comprises one or more user inputs to the client application (Col 5, lines 11-19; When Alice interacts with the image via her browser 104, her events, such as mouse clicks and keyboard presses, are observed and transmitted by the JavaScript executing on client 102 to virtual machine 304 (310). System 302 interprets the received events (e.g., by overlaying the position of the events on Alice's rendering of the page on top of the page as seen by system 302) and surrogate browser 306 takes the corresponding actions with respect to site 110, if applicable); responsive to determining that the user has permission to share the first set of upstream information, transmitting the first set of upstream information to the client application for mimicking the one or more user inputs by the client application (Col 5, lines 20-26; if Alice attempts to click a link on the page she is viewing, her click event is sent to system 302 and browser 306 replicates Alice's click on site 110. If Alice is randomly clicking in white space, in some embodiments, the event is not replicated to site 110. As browser 306's view of the page changes (e.g., a new page is displayed due to following a link), updated images are streamed to Alice's browser 104); receiving, from the client application, a second set of media instructions, wherein the second set of media instructions represent the user interface of the client application updated based on the one or more user inputs and transmitting, to the browser, the second set of media instructions, wherein the second set of media instructions cause the browser to render the updated user interface of the client application (Col 5, lines 24-26; browser 306's view of the page changes (e.g., a new page is displayed due to following a link), updated images are streamed to Alice's browser 104). However, Litty does not specifically disclose determining that the user has permission to share the first set of upstream information (See Koszek; Paragraph 37; evaluates permissions on a static payload/data buffer during a discrete copy/paste action to determine if data can cross boundaries). Therefore, it would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains, having the teachings of Litty and Koszek in it’s entirety, to modify the technique of Litty for a surrogate browsing system by adopting Koszek's teaching for selecting the copy through a menu selection or keystroke combination. The motivation would have been to improve secure access via a remote client. As per claims 2 and 11: The combination of Litty and Koszek discloses the non-transitory computer readable medium of claim 1, wherein the user interface of the client application comprises an interactive user interface of an operating system (See Litty, Col 3, lines 34-43; Fig 2A; FIG. 2A illustrates an embodiment of an interface as rendered in a browser. As shown, Alice has navigated to page 204 using her browser 104. Interface 200 is a web page served by system 106. Alice enters the URL of the page she wishes to securely visit (e.g., http://examplenews.com/solareclipse.html) by typing the URL into box 202 and selecting button 206. The services of system 106 can also be accessed in a variety of other ways). As per claims 3 and 12: The combination of Litty and Koszek discloses the non-transitory computer readable medium of claim 1, wherein the one or more user inputs comprise at least one of: a text input, keyboard input, a pointer input, a voice input, a visual input, webcam, a biometric input, or an input from an input/output device (See Litty, Col 14, lines 47-51; the policy enforcement described as being performed on files can also be performed on other kinds of input, such as user input. For example, if Alice attempts to paste credit card numbers from her clipboard to a site such as pastebin.com, that input can be checked first, and blocked, as applicable). As per claims 4 and 13: The combination of Litty and Koszek discloses the non-transitory computer readable medium of claim 1, wherein the first set of upstream information further comprises content (See Litty, Col 4, lines 45-55; the content displayed in interface 250 appears, to Alice, to be identical to the content that would have been shown to her if she had visited the page “examplenews.com/solareclipse.html” directly with her browser. As will be described in more detail below, system 106 has fetched the content from site 110 on behalf of Alice). As per claims 5 and 14: The combination of Litty and Koszek discloses the non-transitory computer readable medium of claim 4, the content comprises information cut content, copied content, pasted content, or content output from a device (See Litty, Col 4, lines 45-55; FIG. 2B depicts interface 200 after Alice has typed (or copy and pasted) the URL “examplenews.com/solareclipse.html” into box 202 and pressed button 206. In some embodiments, the content displayed in interface 250 appears, to Alice, to be identical to the content that would have been shown to her if she had visited the page “examplenews.com/solareclipse.html” directly with her browser). Claim(s) 6-9, 15-18 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Litty (US Patent 11,611,482) in view of Koszek (US Patent Pub. 2019/0227857) and Xu (US Patent Pub. 20060021068). As per claims 6 and 15: The combination of Litty and Koszek discloses the non-transitory computer readable medium of claim 1, wherein the operations further comprise: receiving, from the browser, a second set of upstream information entered via the user interface rendered by the browser (See Litty, Col 5, lines 8-15; An image of the page is sent by surrogate browsing system 302 to client 102 (308). In some embodiments, the image sent to Alice is transcoded so that, for example, an attacker cannot send malicious pixels to Alice. When Alice interacts with the image via her browser 104, her events, such as mouse clicks and keyboard presses, are observed and transmitted by the JavaScript executing on client 102 to virtual machine 304 (310)); determining that the user lacks permission to share at least a subset of the second set of upstream information (See Koszek; Paragraph 37; evaluates permissions on a static payload/data buffer during a discrete copy/paste action to determine if data can cross boundaries evaluates permissions on a static payload/data buffer during a discrete copy/paste action to determine if data can cross boundaries); However, Litty in view of Koszek does not specifically disclose responsive to determining that the user lacks permission to share at least the subset of the second set of upstream information, generating a modified set of upstream information by removing at least the subset of the second set of upstream information; and transmitting the modified set of upstream information to the client application (See Xu, claim 11: permitting authorized use of a digital content file, the method comprising: generating a modified digital content file, said generating including: removing a portion of said digital content file; and replacing said portion with a header, said header including information enabling an authorized user to retrieve said removed portion; providing said modified digital content file to said authorized user; and providing said authorized user access to said removed portion). Therefore, it would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains, having the teachings of Litty, Koszek and Xu in it’s entirety, to modify the technique of Litty for a surrogate browsing system by adopting Xu's teaching for permitting authorized use of a digital content file. The motivation would have been to improve secure access via a remote client. As per claims 7 and 16: The combination of Litty and Koszek discloses the non-transitory computer readable medium of claim 6, wherein determining that the user lacks permission to share at least the subset of the second set of upstream information comprises: scraping content included in the second set of upstream information (See Xu, claim 11: permitting authorized use of a digital content file, the method comprising: generating a modified digital content file, said generating including: removing a portion of said digital content file; and replacing said portion with a header, said header including information enabling an authorized user to retrieve said removed portion; providing said modified digital content file to said authorized user; and providing said authorized user access to said removed portion). As per claims 8 and 17: The combination of Litty and Koszek discloses the non-transitory computer readable medium of claim 6, wherein generating the modified set of upstream information comprises: excluding at least the subset of the second set of upstream information based on user permissions (See Xu, claim 11: permitting authorized use of a digital content file, the method comprising: generating a modified digital content file, said generating including: removing a portion of said digital content file; and replacing said portion with a header, said header including information enabling an authorized user to retrieve said removed portion; providing said modified digital content file to said authorized user; and providing said authorized user access to said removed portion). As per claims 9 and 18: The combination of Litty and Koszek discloses the non-transitory computer readable medium of claim 6, wherein the operations further comprise, responsive to determining that the user lacks permission to share at least the subset of the second set of upstream information: transmitting, to the browser, a third set of media instructions, wherein the third set of media instructions cause the browser to render a notification indicating that sharing at least the subset of the second set of upstream information is restricted (See Litty, Col 5, lines 20-26if Alice attempts to click a link on the page she is viewing, her click event is sent to system 302 and browser 306 replicates Alice's click on site 110. If Alice is randomly clicking in white space, in some embodiments, the event is not replicated to site 110. As browser 306's view of the page changes (e.g., a new page is displayed due to following a link), updated images are streamed to Alice's browser 104). As per claim 20: The combination of Litty and Koszek discloses the system of claim 19, wherein the operations further comprise: receiving, from the browser, a second set of upstream information entered via the user interface rendered by the browser (See Litty, Col 5, lines 8-15; An image of the page is sent by surrogate browsing system 302 to client 102 (308). In some embodiments, the image sent to Alice is transcoded so that, for example, an attacker cannot send malicious pixels to Alice. When Alice interacts with the image via her browser 104, her events, such as mouse clicks and keyboard presses, are observed and transmitted by the JavaScript executing on client 102 to virtual machine 304 (310)); determining that the user lacks permission to share at least a subset of the second set of upstream information (See Koszek; Paragraph 37; evaluates permissions on a static payload/data buffer during a discrete copy/paste action to determine if data can cross boundaries); However Litty in view of Koszek does not specifically disclose responsive to determining that the user lacks permission to share at least the subset of the second set of upstream information, generating a modified set of upstream information by removing at least the subset of the second set of upstream information (See Xu, claim 11); transmitting the modified set of upstream information to the client application; responsive to determining that the user lacks permission to share at least the subset of the second set of upstream information, generating a modified set of upstream information by removing at least the subset of the second set of upstream information; and transmitting the modified set of upstream information to the client application (See Xu, claim 11: permitting authorized use of a digital content file, the method comprising: generating a modified digital content file, said generating including: removing a portion of said digital content file; and replacing said portion with a header, said header including information enabling an authorized user to retrieve said removed portion; providing said modified digital content file to said authorized user; and providing said authorized user access to said removed portion). Therefore, it would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains, having the teachings of Litty, Koszek and Xu in it’s entirety, to modify the technique of Litty for a surrogate browsing system by adopting Xu's teaching for permitting authorized use of a digital content file. The motivation would have been to improve secure access via a remote client. Relevant Prior Art References The following prior art is cited as being of interest to the claimed invention but has not been applied in any of the current rejections. Yacov et al.- US Patent Publication 2022/0263835- the prior art teaches techniques for providing improved internet access security. Petry et al.- US Patent Pub. 2019/0075130 - the prior art teaches techniques for accessing web resources. Silverstein et al.- US Patent Pub. 2023/0026368 - the prior art teaches techniques for rendering websites through a virtual browser application environment. Goradia et al.- US Patent Pub. 2024/0012904 - the prior art teaches techniques for realizing RBI protected browsing in a computer system. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to ANTHONY D BROWN whose telephone number is (571)270-1472. The examiner can normally be reached 730-330pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Linglan Edwards can be reached at 5712705440. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /ANTHONY D BROWN/Primary Examiner, Art Unit 2408
Read full office action

Prosecution Timeline

Jun 11, 2025
Application Filed
Aug 17, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12731200
DATA MANAGEMENT METHOD AND APPARATUS
2y 2m to grant Granted Sep 08, 2026
Patent 12712917
ENFORCING SECURITY POLICIES AND ATTESTATION ON EDGE INFRASTRUCTURE
2y 4m to grant Granted Aug 18, 2026
Patent 12706955
POLICY ENFORCEMENT AND CONTINOUS POLICY MONITORING ON RECONFIGURABLE HARDWARE DEVICE
2y 5m to grant Granted Aug 11, 2026
Patent 12689658
ACCESS BRIDGE FOR ACCESS CONTROL METHODOLOGY MIGRATION
2y 10m to grant Granted Jul 21, 2026
Patent 12689659
ZERO TRUST POLICY MANAGER
2y 7m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
85%
Grant Probability
99%
With Interview (+15.1%)
2y 8m (~1y 5m remaining)
Median Time to Grant
Low
PTA Risk
Based on 871 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month