Prosecution Insights
Last updated: October 02, 2026
Application No. 19/275,873

Zero Trust Policy Engine for Controlling Access to Network Applications

Non-Final OA §DP
Filed
Jul 21, 2025
Priority
Feb 22, 2023 — provisional 63/447,393 +1 more
Examiner
MCNALLY, MICHAEL S
Art Unit
Tech Center
Assignee
Zscaler Inc.
OA Round
1 (Non-Final)
90%
Grant Probability
Favorable
1-2
OA Rounds
1y 4m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 90% — above average
90%
Career Allowance Rate
975 granted / 1085 resolved
+29.9% vs TC avg
Moderate +9% lift
Without
With
+8.7%
Interview Lift
resolved cases with interview
Typical timeline
2y 6m
Avg Prosecution
14 currently pending
Career history
1101
Total Applications
across all art units

Statute-Specific Performance

§101
11.7%
-28.3% vs TC avg
§103
38.0%
-2.0% vs TC avg
§102
21.7%
-18.3% vs TC avg
§112
13.9%
-26.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 1085 resolved cases

Office Action

§DP
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Priority Applicant’s claim for the benefit of a prior-filed application under 35 U.S.C. 119(e) or under 35 U.S.C. 120, 121, 365(c), or 386(c) is acknowledged. Information Disclosure Statement The information disclosure statement (IDS) submitted on 21 July 2025 has been considered by the examiner. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer. Claims 1, 3-8, 10-11, 14-16 and 18 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-20 of U.S. Patent No. 12,381,916. Although the claims at issue are not identical, they are not patentably distinct from each other because the claims of the instant application are a rearrangement and obvious variation of the claims of the ‘916 Patent. As to claim 1, the ‘916 Patent discloses a method for implementing a zero trust architecture (ZTA), comprising (Claim 1: A method comprising the steps of): receiving, at a zero trust policy engine located inline between user devices and network resources, an access request from a user device for a specified network resource (Claim 1: monitoring and controlling access between a user device and a network application using a zero trust policy engine having a Zero Trust Architecture (ZTA) in which no user, user device, or network application is inherently trusted); verifying, by the zero trust policy engine, identity and context information associated with the user device and a user (Claim 1: and granting trust by allowing the user device to access the network application when identity and context information associated with a user of the user device is verified and when policy checks of the zero trust policy engine are enforced); dynamically calculating a risk score based on the verified identity and context information; enforcing, by the zero trust policy engine, a least-privileged access policy based on the dynamic risk score to selectively allow or deny connection between the user device and only the specified network resource (Claim 6: The method of claim 5, further comprising the steps of: measuring and controlling risk based on a dynamic risk score calculated in response to verifying the identity information and context information; and enforcing the policy checks of the zero trust policy engine based on the dynamic risk score to determine whether to block or allow the user device to access the network application.), wherein the user device is prevented from accessing or identifying other network resources, thereby eliminating lateral threat movement and minimizing an attack surface (Claim 3: The method of claim 2, wherein the zero trust policy engine is configured to control access of the user device by limiting visibility of a network in which the user device and network application are operating). As to claim 3, the ‘916 Patent discloses the method of claim 1, wherein verifying context information comprises assessing attributes of the user device including management status, location, and connection history (Claim 5: The method of claim 1, wherein verifying the identity and context information associated with the user further includes verifying identity information about the user and the user device and verifying context information about how the user device is being used to connect to the network application.). As to claim 4, the ‘916 Patent discloses the method of claim 1, further comprising: terminating all network connections at the zero trust policy engine (Claim 2: The method of claim 1, wherein the zero trust policy engine is configured to act as an inline switchboard controller for monitoring and controlling the access from an inline perspective communicatively positioned between the user device and the network application.); and selectively re-establishing a secure proxy connection to the specified network resource only if the access request meets the access policy conditions (Claim 12: The method of claim 1, wherein the zero trust policy engine includes a proxy architecture independent of pass-through functionality associated with firewalls and Virtual Private Networks (VPNs).). As to claim 5, the ‘916 Patent discloses the method of claim 4, further comprising continuously inspecting all traffic between the user device and the specified network resource for malware and data loss prevention (Claim 10: The method of claim 9, wherein the step of controlling risk includes one or more of a) inspecting inbound and outbound traffic to prevent malware execution and data loss, and b) using adaptive controls based on changes in behavior or context.). As to claim 6, the ‘916 Patent discloses the method of claim 4, further comprising: detecting anomalous behavior during an established connection; and adaptively terminating or restricting the established connection based on the detected anomalous behavior (Claim 6: The method of claim 5, further comprising the steps of: measuring and controlling risk based on a dynamic risk score calculated in response to verifying the identity information and context information; and enforcing the policy checks of the zero trust policy engine based on the dynamic risk score to determine whether to block or allow the user device to access the network application.). As to claim 7, the ‘916 Patent discloses the method of claim 1, wherein enforcing the least-privileged access policy comprises granting access by pixel streaming sensitive data from the specified network resource to the user device, thereby preventing data downloads (Claim 14: The method of claim 1, wherein, upon detection of a request by the user device to download sensitive data from a network resource, the method further comprises the steps of: pixelating the sensitive data; and streaming the pixelated sensitive data from the network resource to the user device). As to claim 8, the ‘916 Patent discloses the method of claim 1, wherein the zero trust policy engine is integrated into a Security Service Edge (SSE) platform comprising at least one of Secure Web Gateway (SWG), Zero Trust Network Access (ZTNA), and Cloud Access Security Broker (CASB) functionalities (Claim 1: wherein the zero trust policy engine is incorporated in a Security Service Edge (SSE) framework which includes one or more of Secure Web Gateway (SWG), Zero Trust Network Access (ZTNA), Cloud Access Security Broker (CASB), firewall as a service (FWaaS), browser isolation, sandboxing, Secure Sockets Layer (SSL) inspection, and threat protection.). As to claim 10, the ‘916 Patent discloses the method of claim 1, wherein the zero trust policy engine conceals network resource locations by acting as a secure switchboard that connects validated users and devices directly to authorized network resources without exposing their addresses (Claim 2: The method of claim 1, wherein the zero trust policy engine is configured to act as an inline switchboard controller for monitoring and controlling the access from an inline perspective communicatively positioned between the user device and the network application.). As to claim 11, the ‘916 Patent discloses the method of claim 1, further comprising :establishing an inside-out secure connection initiated from the specified network resource to the zero trust policy engine to ensure that the network resource is inaccessible directly from external networks (Claim 2: The method of claim 1, wherein the zero trust policy engine is configured to act as an inline switchboard controller for monitoring and controlling the access from an inline perspective communicatively positioned between the user device and the network application.). As to claim 14, the ‘916 Patent discloses the method of claim 1, further comprising: applying adaptive access controls that dynamically adjust access permissions in real-time based on changing user context or evolving threat intelligence (Claim 6: The method of claim 5, further comprising the steps of: measuring and controlling risk based on a dynamic risk score calculated in response to verifying the identity information and context information; and enforcing the policy checks of the zero trust policy engine based on the dynamic risk score to determine whether to block or allow the user device to access the network application.). As to claim 15, the ‘916 Patent discloses the method of claim 1, further comprising: generating a graphical user interface (GUI) dashboard displaying real-time insights related to user access requests, detected threats, and applied security policies (Claim 16: The method of claim 1, further comprising the steps of: obtaining security-related information associated with one or more of a) operations and results of the zero trust policy engine, b) applicable networks, c) applicable users, d) applicable user devices, e) accessed network applications, and f) accessed data; and displaying the security-related information on one or more dashboards or user interfaces associated with a network administrator.). As to claim 16, the ‘916 Patent discloses the method of claim 1, wherein the enforcing the least-privileged access policy comprises isolating high-risk access requests by using browser isolation technology to stream content as pixels without allowing direct content interaction (Claim 14: The method of claim 1, wherein, upon detection of a request by the user device to download sensitive data from a network resource, the method further comprises the steps of: pixelating the sensitive data; and streaming the pixelated sensitive data from the network resource to the user device.). As to claim 18, the ‘916 Patent discloses the method of claim 1, further comprising: providing seamless integration and secure access for third-party or external entities without merging distinct network infrastructures by leveraging application-level segmentation (Claim 15: The method of claim 1, wherein, in response to receiving a merge request related to a merging event associated with two or more companies each having a heterogeneous network, the method further comprises the step of seamlessly integrating the heterogeneous networks using application-based or connection-based segmentation to enable users associated with any of the two or more companies to access network applications from any of the heterogeneous networks of the merged companies.). Claim 2 is rejected on the ground of nonstatutory double patenting as being unpatentable over claim1-20 of U.S. Patent No. 12,381,916 in view of U.S. Patent Application Publication No. 2023/0113325 by Nagaraja et al. As to claim 2, the ‘916 Patent discloses all recited elements of claim 1 from which claim 2 depends. The ‘916 Patent does not expressly disclose wherein verifying identity information comprises authenticating the user and the user device via integrated identity and access management (IAM) services. Nagaraja discloses wherein verifying identity information comprises authenticating the user and the user device via integrated identity and access management (IAM) services (Nagaraja: Page 1, Sec 8; “An aspect of the present disclosure provides for a method comprising: generating an integrated identity and access management (IAM) system from a first IAM system and a second IAM system that is different than the first IAM system by: (i) creating a domain in a customer tenancy associated with the first IAM system, and (ii) embedding an identity provider of the second IAM system within the domain; receiving, by the integrated IAM system, a request from a user to perform an operation with respect to resource associated with the second IAM system; and executing the request in response to the user being successfully authenticated by the integrated IAM system.”). The ‘916 Patent and Nagaraja are analogous art because they are from the common area of user authentication. It would have been obvious to one of ordinary skill in the art, at or before the effective filing date of the instant application to use the IAM authentication of Nagaraja in the system of the ‘916 Patent. The rationale would have been to encourage identity federation (Nagaraja: Page 1, Sec 5). Claim 9 is rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-20 of U.S. Patent No. 12,381,916 in view of U.S. Patent Application Publication No. 2022/0353244 by Khan et al. As to claim 9, the ‘916 Patent discloses all recited elements of claim 1 from which claim 9 depends. The ‘916 Patent does not expressly disclose implementing zero trust connectivity for workloads by enforcing identity-based policies for workload-to-workload communication across hybrid and multi-cloud environments. Khan discloses implementing zero trust connectivity for workloads by enforcing identity-based policies for workload-to-workload communication across hybrid and multi-cloud environments (Khan: Page 4, Sec 46; “For example, workloads are blocked from communicating until they are validated by a set of attributes, such as a fingerprint or identity. Identity-based validation policies result in stronger security that travels with the workload wherever it communicates—in a public cloud, a hybrid environment, a container, or an on-premises network architecture.”). The ‘916 Patent and Khan are analogous art because they are from the common area of user authentication. It would have been obvious to one of ordinary skill in the art, at or before the effective filing date of the instant application to use the identity policy of Khan in the system of the ‘916 Patent. The rationale would have been to control workloads across networks using identity policy (Khan: Page 4, Sec 46). Claims 12-13 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-20 of U.S. Patent No. 12,381,916 in view of U.S. Patent Application Publication No. 2012/0150773 by DiCorpo et al. As to claim 12, the ‘916 Patent discloses all recited elements of claim 1 from which claim 12 depends. The ‘916 Patent does not expressly disclose further comprising: automatically classifying sensitive data accessed from the specified network resource using artificial intelligence (AI) and machine learning (ML) techniques. DiCorpo discloses further comprising: automatically classifying sensitive data accessed from the specified network resource using artificial intelligence (AI) and machine learning (ML) techniques (DiCorpo: Fig 11; Page 8, Sec 81-82; “[0081] FIG. 11 is a flow diagram illustrating one embodiment for a method 1100 of protecting a computing device from data loss using a DLP policy that includes a MLD profile. The method 1100 is performed by processing logic that may comprise hardware (circuitry, dedicated logic, etc.), software (such as is run on a general purpose computer system or a dedicated machine), or a combination of both. Method 1100 may be performed by a DLP agent such as DLP agent 106 running on endpoint device 102A of FIG. 1. Method 1100 may also be performed by a global DLP detection engine such as global DLP detection engine 122 running on endpoint server 115 of FIG. 1. [0082] Referring to FIG. 11, at block 1105 processing logic receives a request to perform an operation on a document. At block 1110, a ML module analyzes the document using a MLD profile to classify the document. At block 1125, processing logic determines whether the document was classified as sensitive or non-sensitive. If the document was classified as sensitive, the method continues to block 1130, and an action specified by a DLP response rule is performed, and an incident report is generated. This may include preventing the operation, generating an incident response report, etc. If the document was classified as non-sensitive, the method proceeds to block 1135, and the operation is performed.”). The ‘916 Patent and DiCorpo are analogous art because they are from the common area of data protection. It would have been obvious to one of ordinary skill in the art, at or before the effective filing date of the instant application to use the data filtering of DiCorpo in the system of the ‘916 Patent. The rationale would have been to prevent the spread of sensitive data (DiCorpo: Fig 11; Page 8, Sec 81-82). As to claim 13, the ‘916 Patent as modified by DiCorpo further discloses further comprising enforcing data loss prevention (DLP) policies based on the automatic classification of sensitive data to prevent unauthorized sharing, downloading, or copying of such data (DiCorpo: Fig 11; Page 8, Sec 81-82; “[0081] FIG. 11 is a flow diagram illustrating one embodiment for a method 1100 of protecting a computing device from data loss using a DLP policy that includes a MLD profile. The method 1100 is performed by processing logic that may comprise hardware (circuitry, dedicated logic, etc.), software (such as is run on a general purpose computer system or a dedicated machine), or a combination of both. Method 1100 may be performed by a DLP agent such as DLP agent 106 running on endpoint device 102A of FIG. 1. Method 1100 may also be performed by a global DLP detection engine such as global DLP detection engine 122 running on endpoint server 115 of FIG. 1. [0082] Referring to FIG. 11, at block 1105 processing logic receives a request to perform an operation on a document. At block 1110, a ML module analyzes the document using a MLD profile to classify the document. At block 1125, processing logic determines whether the document was classified as sensitive or non-sensitive. If the document was classified as sensitive, the method continues to block 1130, and an action specified by a DLP response rule is performed, and an incident report is generated. This may include preventing the operation, generating an incident response report, etc. If the document was classified as non-sensitive, the method proceeds to block 1135, and the operation is performed.”). Claim 17 is rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-20 of U.S. Patent No. 12,381,916 in view of U.S. Patent Application Publication No. 2020/0404365 by Phillips. As to claim 17, the ‘916 Patent discloses all recited elements of claim 1 from which claim 17 depends. The ‘916 Patent does not expressly disclose wherein the identity verification is enhanced by continuously validating user and device trust posture throughout an active session. Phillips discloses wherein the identity verification is enhanced by continuously validating user and device trust posture throughout an active session (Phillips: Page 1, Sec 3; “The present disclosure provides continuous dual authentication by verifying an authorized user is accessing the media content and verifying an authorized device is generating valid content fingerprints for the duration of presentation of the media content as defined by the content owner. In addition to the validation process, other rules and terms of viewer engagement can also be defined as a result of the sync reference”). The ‘916 Patent and Phillips are analogous art because they are from the common area of user authentication. It would have been obvious to one of ordinary skill in the art, at or before the effective filing date of the instant application to use the continuous authentication of Phillips in the system of the ‘916 Patent. The rationale would have been to ensure that data is being consumed by an authorized user on an authorized device (Phillips: Page 1, Sec 3). Allowable Subject Matter Claims 19-20 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. Prior Art The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. U.S. Patent Application Publication No. 2014/0208418 by Libin discloses protecting sensitive information using pixilation U.S. Patent Application Publication No. 2022/0294828 by Keiser Jr. discloses a zero trust architecture U.S. Patent Application Publication No. 2023/0328063 by Li et al. discloses a zero trust architecture U.S. Patent Application Publication No. 2023/0403282 by Smith et al. discloses a zero trust architecture U.S. Patent No. 11,870,818 by Sutherland et al. discloses a zero trust architecture Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to MICHAEL S MCNALLY whose telephone number is (571)270-1599. The examiner can normally be reached Monday-Friday, 8:30 AM - 5:00 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey L Nickerson can be reached at (469)295-9235. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. MICHAEL S. MCNALLY Primary Examiner Art Unit 2432 /Michael S McNally/Primary Examiner, Art Unit 2432
Read full office action

Prosecution Timeline

Jul 21, 2025
Application Filed
Sep 04, 2026
Non-Final Rejection mailed — §DP (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750350
AUTOMATIC ENCRYPTION FOR CLOUD-NATIVE WORKLOADS
1y 12m to grant Granted Sep 29, 2026
Patent 12744817
SECURE VERIFICATION OF DETECTION RULES ON TEST SENSORS
2y 9m to grant Granted Sep 22, 2026
Patent 12737472
ELECTRONIC DEVICE, METHOD, AND NON-TRANSITORY COMPUTER-READABLE STORAGE MEDIUM FOR PERFORMING MOUNT OPERATION FOR PART OF PARTITION
1y 11m to grant Granted Sep 15, 2026
Patent 12688292
A COMPUTER-IMPLEMENTED METHOD FOR MITIGATING ANOMALOUS ACTIVITY
1y 11m to grant Granted Jul 21, 2026
Patent 12675563
METHOD FOR UNLOCKING AN ELECTRONIC DEVICE
1y 10m to grant Granted Jul 07, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
90%
Grant Probability
99%
With Interview (+8.7%)
2y 6m (~1y 4m remaining)
Median Time to Grant
Low
PTA Risk
Based on 1085 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month