Prosecution Insights
Last updated: October 02, 2026
Application No. 19/367,261

IOT SECURITY KNOWLEDGE-BASED CHATBOT SYSTEM

Non-Final OA §103§DOUBLEPATENT
Filed
Oct 23, 2025
Priority
Aug 31, 2023 — continuation of 12/475,115
Examiner
PHILLIPS, III, ALBERT M
Art Unit
2159
Tech Center
2100 — Computer Architecture & Software
Assignee
Palo Alto Networks Inc.
OA Round
1 (Non-Final)
82%
Grant Probability
Favorable
1-2
OA Rounds
2y 0m
Est. Remaining
94%
With Interview

Examiner Intelligence

Grants 82% — above average
82%
Career Allowance Rate
595 granted / 730 resolved
+26.5% vs TC avg
Moderate +13% lift
Without
With
+12.7%
Interview Lift
resolved cases with interview
Typical timeline
2y 11m
Avg Prosecution
15 currently pending
Career history
749
Total Applications
across all art units

Statute-Specific Performance

§101
14.3%
-25.7% vs TC avg
§103
41.6%
+1.6% vs TC avg
§102
19.2%
-20.8% vs TC avg
§112
16.4%
-23.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 730 resolved cases

Office Action

§103 §DOUBLEPATENT
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer. Claims 1, 4-8, 10, 13, 14, and 17-20 rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1 3-5 of US 12475115 B2. Although the claims at issue are not identical, they are not patentably distinct from each other because the bolded portions of claims 1 and 3-5 of ‘115 teach or suggest the bolded portions of instant claims 1 and 4-8. See chart below. US 12475115 B2 Instant 1. A method comprising: receiving, from input originating from a user, a first query comprising natural language text, (Examiner finds it would have been obvious to one skilled in the art before the effective filing date of the invention modify this element to include a conventional, well known “chatbot.” The motivation would have been to assist a user in quickly finding information without expert knowledge of the schema of a database. ) 1. A method comprising: obtaining a first query comprising natural language text during a chatbot conversation with a user, wherein the user is associated with a first tenant of one or more tenants of a security provider; wherein the user is associated with a first tenant of a plurality of tenants of a security provider; determining if the first query corresponds to at least one of a vulnerability database and a database managed by the security provider that maintains Internet of things (IoT) information for the one or more tenants; based on determining that the first query corresponds to the database of IoT information, based on determining that the first query corresponds to a first knowledge source of a plurality of knowledge sources, prompting a large language model (LLM) to generate a database query representing the first query that is compatible with the database of IoT information, generating a second query representative of the first query, wherein prompting the LLM to generate the database query comprises generating a prompt comprising an instruction to generate a database query representation of the first query based, at least in part, on a schema of the database of IoT information and providing the prompt to the LLM, wherein the first knowledge source comprises a database of Internet of Things (IoT) security information maintained for the plurality of tenants, wherein the second query is a database query representative of the natural language text, wherein generating the second query comprises prompting a first language model with the first query; wherein an output of the LLM indicates the database query representing the first query; and submitting the database query to the database of IoT information to obtain a first query result comprising at least one of data and metadata maintained in the database that satisfy the database query; based on determining that the first query corresponds to the vulnerability database, submitting the second query to the database of IoT security information to retrieve a first result that satisfies the first query; querying the vulnerability database with a vulnerability database query determined based on the first query to obtain a second query result, wherein the second query result comprises at least one of data and metadata maintained in the vulnerability database that satisfy the vulnerability database query; masking sensitive information of the first tenant that is included in the first query result or the second query result; based on determining that the first result comprises sensitive information of the first tenant, masking the sensitive information of the first tenant that is included in the first result; and generating a summary of the first query result or the second query result having sensitive information masked; and providing the first or second query result providing a first response to the first query comprising the first result. Instant claims 10 and 14 are rejected for the reasons given above for instant claim 1. [CLAIM 1] generating a summary of the first query result or the second query result having sensitive information masked; v and providing the first or second query result 4. The method of claim 1, further comprising summarizing the first result based prompting the first language model or another language model with the first result to obtain a summary of the first result, wherein providing the first response to the first query comprises providing the first response to the first query comprising the first result and the summary of the first result. Instant claim 19 is rejected for the reasons given above for instant claim 4 above. [CLAIM 1]. . . .determining if the first query corresponds to at least one of a vulnerability database and a database managed by the security provider that maintains Internet of things (IoT) information for the one or more tenants 5. The method of claim 1, further comprising determining to which of the plurality of knowledge sources the first query corresponds, wherein a second knowledge source of the plurality of knowledge sources comprises a vulnerability database. Instant claim 17 is rejected for the reasons given above for instant claim 5 4. The method of claim 1 further comprising determining one or more parameters for the vulnerability database query based on the first query, wherein determining that the first query corresponds to the vulnerability database comprises determining that the first query relates to a known vulnerability, wherein the vulnerability database comprises at least one of an external vulnerability database and an internal vulnerability database. 6. The method of claim 5 further comprising: based on determining that the first query corresponds to the vulnerability database, determining one or more parameters for querying the vulnerability database based on the first query; querying the vulnerability database with the one or more parameters; Instant claim 13 is rejected for the reasons given above for instant claims 5-6. Instant claim 18 is rejected for the reasons given above for claim 6. [CLAIM 1] . . . to obtain a second query result, wherein the second query result comprises at least one of data and metadata maintained in the vulnerability database that satisfy the vulnerability database query; . . . and providing the first or second query result and the summary of the first or second query result as a response to the first query. obtaining a second result of querying the vulnerability database comprising at least one of data and metadata from the vulnerability database; and providing a second response to the first query comprising the second result. 5. The method of claim 4, wherein the external vulnerability database comprises the National Vulnerability Database (NVD), wherein querying the vulnerability database comprises querying the NVD via an application programming interface (API) of the NVD. 7. The method of claim 5, wherein the vulnerability database comprises the National Vulnerability Database. 3. The method of claim 1, wherein the LLM comprises a pre-trained transformer-based LLM. 8. The method of claim 1, wherein the first language model comprises a pre-trained transformer-based large language model (LLM). Instant claim 20 is rejected for the reason given for instant claim 8 above. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1, 4-6, 8, 10, 13, 14, and 17-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Subramanian US 20240061835 A1 in view of Reddy US 20240045893 A1 and further in view of Ghatage US 20230267227 A1. With respect to claim 1, Subramanian teaches the following: Claim Subramanian; US 20240061835 A1 1. A method comprising: obtaining a first query comprising natural language text during a chatbot conversation with a user, Para. 32 (chatbot); para. 124 and para. 125 (Examiner finds “<s>What are the invoices for Invoice </s>” teaches the obtained, NL text); wherein the user is associated with a first tenant of a plurality of tenants of a security provider; based on determining that the first query corresponds to a first knowledge source of a plurality of knowledge sources, Para. 124 (first knowledge source is the knowledge source (database) specified by the schema): generating a second query representative of the first query, Para. 131 (second query representative of first query is a translated SQL query, for example); wherein the first knowledge source comprises a database of Internet of Things (IoT) security information maintained for the plurality of tenants, wherein the second query is a database query representative of the natural language text, Para. 131 (second query representative of first query is a translated SQL query, for example); wherein generating the second query comprises prompting a first language model with the first query; Paras. 125, 131, 132; para. 192 (Examiner finds “providing as input to the customized machine learning model” teaches prompting the model with the first query); submitting the second query to the database Para. 192 of IoT security information to retrieve a first result that satisfies the first query; Para. 192 based on determining that the first result comprises sensitive information of the first tenant, masking the sensitive information of the first tenant that is included in the first result; and providing a first response to the first query comprising the first result. Para. 192 It appears Subramanian fails to explicitly teach: wherein the user is associated with a first tenant of a plurality of tenants of a security provider; wherein the first knowledge source comprises a database of Internet of Things (IoT) security information maintained for the plurality of tenants, of IoT security information based on determining that the first result comprises sensitive information of the first tenant, masking the sensitive information However, Reddy US 20240045893 A1 teaches “wherein the user is associated with a first tenant of a plurality of tenants of a security provider” in Para. 105 (site engineer is a tenant of a security provider ); “wherein the first knowledge source comprises a database of Internet of Things (IoT) security information maintained for the plurality of tenants” in Paras. 105-107 (Examiner finds vulnerability database teaches IoT security information); “of IoT security information” in paras. 105-107 (Examiner finds vulnerability database teaches IoT security information). Subramanian and Reddy are analogous art because they are from the same field of endeavor as the claimed invention. It would have been obvious to one skilled in the art before the effective filing date of the invention to modify “obtaining a first query comprising natural language text during a chatbot conversation with a user” in Subramanian to include “wherein the user is associated with a first tenant of a plurality of tenants of a security provider” as taught by Reddy; to modify generating a second query representative of the first query as taught by Subramanian to include wherein the first knowledge source comprises a database of Internet of Things (IoT) security information maintained for the plurality of tenants as taught by Reddy; and to modify “submitting the second query to the database” as taught by Subramanian to include “of IoT security information” as taught by Reddy. The motivation for all combinations would have been to “access[] insights about []network infrastructure, eliminating the need for complex database queries, domain-specific languages, or other cumbersome methods.” Reddy ¶119. It appears Subramanian et al. fails to explicitly teach “based on determining that the first result comprises sensitive information of the first tenant, masking the sensitive information of the first tenant that is included in the first result; and.” However, Ghatage teaches this element in [0027] Upon completing the necessary processing for the request 154, the applications access system 100 may or may not return any data from the corresponding backend application depending on the request 154 being validated. If any data is to be returned, the response provider 106 receives the data from the applications communicator 104 and may enable the display of such data on the social media UI 152. For example, if an invoice is submitted for processing by the request 154 via the social media UI 152, the applications access system 100 may return an acknowledgment without any specific data. However, if the request 154 pertains to specific information regarding updating account information, the applications access system 100 may be required to return the updated information. In providing sensitive data such as account information, the applications access system 100 ensures protection of the sensitive data by implementing various procedures to occlude or prevent transmission of the sensitive data via the social media application 150. The response provider 106 enables AI-based masked communications thereby masking sensitive information while providing representative data in a response 156 to the request 154. The response 156 with the sensitive data occluded can be displayed on the social media UI 152. Ghatage and Subramanian et al. are analogous art because they are from the same field of endeavor as the claimed invention. It would have been obvious to one skilled in the art before the effective filing date of the invention to modify to retrieve a first result that satisfies the first query as taught by Subramanian et al. to include “based on determining that the first result comprises sensitive information of the first tenant, masking the sensitive information of the first tenant that is included in the first result; and” as taught by Ghatage. The motivation would have been to maintain user privacy. See Ghatage ¶ 27. Claim 10 and claim 14 are rejected for the reason given above for claim 1. With respect to claim 4, Reddy teaches “4. The method of claim 1, further comprising summarizing the first result based prompting the first language model or another language model with the first result to obtain a summary of the first result, wherein providing the first response to the first query comprises providing the first response to the first query comprising the first result and the summary of the first result” in [0118] The converted responses are then presented in the UI of the query module 104 for the site engineer to view. The engineer sees the following user-friendly response displayed in the UI: “The login credentials need to be changed immediately to avoid vulnerability on system x.” (“The login credentials need to be changed immediately to avoid vulnerability on system x.” is a summary of results). The motivation to combine this element with claim 1 is given above in claim 1 (i.e. to access[] insights about []network infrastructure, eliminating the need for complex database queries, domain-specific languages, or other cumbersome methods.). Claim 19 is rejected for the reason given above for claim 4. With respect to claim 5, Reddy US 20240045893 A1 teaches “5. The method of claim 1, further comprising determining to which of the plurality of knowledge sources the first query corresponds, wherein a second knowledge source of the plurality of knowledge sources comprises a vulnerability database. [0118] The converted responses are then presented in the UI of the query module 104 for the site engineer to view. The engineer sees the following user-friendly response displayed in the UI: “The login credentials need to be changed immediately to avoid vulnerability on system x.” The motivation to combine this element with claim 1 is given above in claim 1 (i.e. to access[] insights about []network infrastructure, eliminating the need for complex database queries, domain-specific languages, or other cumbersome methods.). Claim 17 is rejected for the reason given above for claim 5. With respect to claim 6, Reddy teaches “6. The method of claim 5 further comprising: based on determining that the first query corresponds to the vulnerability database, determining one or more parameters for querying the vulnerability database based on the first query” in [0107] Based on the analyzed query, the QE engine 216 predicts the infrastructure-specific commands required to be executed on the heterogeneous infrastructure 108. The predicted query could be: “Find vulnerability conditions from a central vulnerability database.” [0109] Some examples of subsequent questions formulated by the QE 216 include: [0110] “Find all systems deployed in AWS using ec2 instances types that are launched on a particular date.” [0111] “Retrieve security group information to find what ports are exposed to the internet and accept incoming connections.” [0112] “Is any python-based process running, which listens on a port exposed to the internet?” [0113] “What python packages may be loaded in memory by that process?” [0114] “What GitHub credentials are present on the system?” [0115] “Which GitHub user do those credentials belong to?” (parameters include ec2 instances, dates, security group information, etc. as taught by ¶¶ 109—115 above); “querying the vulnerability database with the one or more parameters” [0107] Based on the analyzed query, the QE engine 216 predicts the infrastructure-specific commands required to be executed on the heterogeneous infrastructure 108. The predicted query could be: “Find vulnerability conditions from a central vulnerability database.” [0109] Some examples of subsequent questions formulated by the QE 216 include: [0110] “Find all systems deployed in AWS using ec2 instances types that are launched on a particular date.” [0111] “Retrieve security group information to find what ports are exposed to the internet and accept incoming connections.” [0112] “Is any python-based process running, which listens on a port exposed to the internet?” [0113] “What python packages may be loaded in memory by that process?” [0114] “What GitHub credentials are present on the system?” [0115] “Which GitHub user do those credentials belong to?” “obtaining a second result of querying the vulnerability database “comprising at least one of data and metadata from the vulnerability database; and” [0105] Consider another exemplary scenario where a site engineer utilizes the query module 104 to obtain information about system vulnerabilities. The engineer inputs a natural language query through the UI of the query module 104, asking, “What entity may be affected with a particular vulnerability?” [0106] The NLP engine 214 processes the query and extracts the intent, which is to identify entities that could potentially be impacted by a specific vulnerability. [0107] Based on the analyzed query, the QE engine 216 predicts the infrastructure-specific commands required to be executed on the heterogeneous infrastructure 108. The predicted query could be: “Find vulnerability conditions from a central vulnerability database.” (“What entity may be affected with a particular vulnerability?” corresponds to the central vulnerability database); “comprising at least one of data and metadata from the vulnerability database; and” [0109] Some examples of subsequent questions formulated by the QE 216 include 216 include: [0110] “Find all systems deployed in AWS using ec2 instances types that are launched on a particular date.” [0111] “Retrieve security group information to find what ports are exposed to the internet and accept incoming connections.” [0112] “Is any python-based process running, which listens on a port exposed to the internet?” [0113] “What python packages may be loaded in memory by that process?” [0114] “What GitHub credentials are present on the system?” [0115] “Which GitHub user do those credentials belong to?” [0118] The converted responses are then presented in the UI of the query module 104 for the site engineer to view. The engineer sees the following user-friendly response displayed in the UI: “The login credentials need to be changed immediately to avoid vulnerability on system x.” (“System x” is an example of metadata and data; user credentials include metadata and data); “providing a second response to the first query comprising the second result” [0118] The converted responses are then presented in the UI of the query module 104 for the site engineer to view. The engineer sees the following user-friendly response displayed in the UI: “The login credentials need to be changed immediately to avoid vulnerability on system x.” (“The login credentials need to be changed immediately to avoid vulnerability on system x.” teaches a second result and a response to the first natural language query). The motivation to combine this element with claim 5 is given above in claim 1 (i.e. to access[] insights about []network infrastructure, eliminating the need for complex database queries, domain-specific languages, or other cumbersome methods.). Claim 13 is rejected for the reasons given above for claim 5-6. Claim 18 is rejected for the reason given above for claim 6. With respect to claim 8, Subramanian teaches “wherein the first language model comprises a pre-trained transformer-based large language model (LLM)” in ¶ 116 (“This deep learning model (referred to as a “C2OMRL semantic parser” or “C2OMRL model”) is trained with thousands of example pairs (natural language to logical form).”)(Examiner finds “deep learning model would suggest “LLM” to one skilled in the art); para. 112. Claim 20 is rejected for the reason given above for claim 6. Claim(s) 7 is/are rejected under 35 U.S.C. 103 as being unpatentable over Subramanian US 20240061835 A1 in view of Reddy US 20240045893 A1 and further in view of Ghatage US 20230267227 A1 as applied to claim 5 above and further in view of Nhlabatsi US 20200351295 A1. With respect to claim 7, it appears Subramanian et al. fails to explicitly teach “7. The method of claim 5, wherein the vulnerability database comprises the National Vulnerability Database” However, Nhlabatsi teaches “the vulnerability database comprises the National Vulnerability Database” in para. 52. Subramanian et al. and Nhlabatsi are analogous art because they are from the same field of endeavor as the claimed invention. It would have been obvious to one skilled in the art before the effective filing date of the invention to modify the vulnerability database in Subramanian to include “the National Vulnerability Database” as taught by Nhlabatsi. The motivation would have been to provide up-to-date protection for system vulnerabilities. Allowable Subject Matter Claim 2-3, 9, 11-12, and 15-16 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to ALBERT M PHILLIPS, III whose telephone number is (571)270-3256. The examiner can normally be reached 10a-6:30pm EST M-F. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Ann J Lo can be reached at (571) 272-9767. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /ALBERT M PHILLIPS, III/Primary Examiner, Art Unit 2159
Read full office action

Prosecution Timeline

Oct 23, 2025
Application Filed
Jul 29, 2026
Non-Final Rejection mailed — §103, §DOUBLEPATENT (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12748986
SYSTEMS AND METHODS FOR OPTIMIZED TRANSACTION PROCESSING
3y 6m to grant Granted Sep 29, 2026
Patent 12730837
DYNAMIC ACOUSTIC SIGNATURE SYSTEM WITH SENSOR FUSION FOR ILLEGAL LOGGING IN RAINFOREST
3y 3m to grant Granted Sep 08, 2026
Patent 12705234
INSTRUCTION QUERY METHOD, COMPUTER PROGRAM PRODUCT AND ASSOCIATED QUERY SYSTEM
1y 8m to grant Granted Aug 11, 2026
Patent 12699728
DYNAMIC BIN CREATION
2y 3m to grant Granted Aug 04, 2026
Patent 12694041
BILATERAL ASSERTION MODEL AND LEDGER IMPLEMENTATION THEREOF
1y 6m to grant Granted Jul 28, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
82%
Grant Probability
94%
With Interview (+12.7%)
2y 11m (~2y 0m remaining)
Median Time to Grant
Low
PTA Risk
Based on 730 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month