Prosecution Insights
Last updated: October 04, 2026
Application No. 19/368,070

FIRM CLOUD SERVICE COORDINATES SECURITY ACROSS SERVERS AND EDGE DEVICES

Final Rejection §103
Filed
Oct 24, 2025
Priority
Dec 31, 2024 — provisional 63/740,820 +1 more
Examiner
CHOUDHURY, AZIZUL Q
Art Unit
2455
Tech Center
2400 — Computer Networks
Assignee
Cato Networks Ltd.
OA Round
2 (Final)
77%
Grant Probability
Favorable
3-4
OA Rounds
2y 8m
Est. Remaining
90%
With Interview

Examiner Intelligence

Grants 77% — above average
77%
Career Allowance Rate
530 granted / 685 resolved
+19.4% vs TC avg
Moderate +12% lift
Without
With
+12.5%
Interview Lift
resolved cases with interview
Typical timeline
3y 7m
Avg Prosecution
13 currently pending
Career history
699
Total Applications
across all art units

Statute-Specific Performance

§101
13.0%
-27.0% vs TC avg
§103
58.1%
+18.1% vs TC avg
§102
7.1%
-32.9% vs TC avg
§112
11.8%
-28.2% vs TC avg
Black line = Tech Center average estimate • Based on career data from 685 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Detailed Action This office action is in response to the amendment filed on August 6, 2026. Claims 1-77 and 98-254 are cancelled. Claims 78-97 are currently pending, of which claims 78-90 are currently amended. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 78-97 are rejected under 35 U.S.C. 103 as being unpatentable over Kalapatapu et al (US PGPub No: 2024/0430305) in view of Jain et al (US PGPub No: 2019/0349404), hereafter referred to as Kalapatapu and Jain, respectively. With regard to claims 78, 91, and 97, Kalapatapu teaches through Jain, a computer readable medium containing instructions that when executed by at least one processor cause the at least one processor to perform unified network security management operations, comprising: maintaining in a cloud service management application, a unified policy for controlling network security across a plurality of servers and edge devices, wherein the plurality of servers and edge devices are configured to perform differing and complementary security actions (Kalapatapu teaches establishing a unified security policy in a distributed cloud environment; see paragraph 16, Kalapatapu. The distributed cloud allows for the combination and subsequent management of cloud, local, and edge datacenters, as a unified system; see paragraph 16 and Figure 1A, Kalapatapu. A unified portal (e.g. cloud service management application) applies the security policy (unified policy for controlling network security) to the edge and other devices within the network; see paragraphs 39 and 41 and Figure 1A, Kalapatapu. The unified portal includes a (1) shift-rotate defense module (used to monitor edge devices to enable the sending of security policy to edge devices via the unified portal; see paragraph 40, Kalapatapu) and a (2) cloud security posture management (CSPM) (used to monitor other devices to enable the sending of security policy via the unified portal) to enable the unified portal to manage the security policy across the edge and other devices; see paragraphs 35, 38, and 40, Kalapatapu); instructing, consistent with the unified policy, each edge device to perform first subsets of the security actions (Kalapatapu teaches the unified portal includes a (1) shift-rotate defense module (used to monitor edge devices (first subset of security actions) to enable the sending of security policy to edge devices via the unified portal); see paragraphs 39-40, Kalapatapu. The security policy changes ensure only certain paths and assets are used by devices, such as edge devices, to meet the desired security policy; see paragraph 21, Kalapatapu); and instructing, consistent with the unified policy, each server to perform second subsets of the security actions (Kalapatapu teaches a cloud security posture management (CSPM) that is used to monitor other devices, that is non-edge local and cloud devices (second subset of security actions), to enable the sending of security policy via the unified portal to enable the unified portal to manage the security policy across the edge and other devices; see paragraphs 35, 38-39, and 40, Kalapatapu. The security policy changes ensure only certain paths and assets are used by devices such as, cloud and local devices, to meet the desired security policy; see paragraph 21, Kalapatapu), wherein the first subsets of security actions and the second subsets of security actions are coordinated to achieve an overall security state defined by the unified policy (Kalapatapu teaches the unified portal via the CSPM and the CWPP, implement new security policies automatically (coordinated) across the edge or cloud devices so that they are consistent across devices (e.g. achieve the unified policy); see paragraph 47, Kalapatapu. See Jain below for security state being achieved). While Kalapatapu teaches applying a unified security policy across devices of a network, Kalapatapu does not explicitly cite an overall security state being achieved. In the same field of endeavor, Jain also teaches a network that has a unified security policy applied to its devices; see paragraph 6, Jain. In particular, Jain teaches an approach allowing for central configuration and management of a plurality of discrete yet coordinate security systems and subsystems in a cloud; see paragraph 37, Jain. It allows customers to define their security policy in a single location at the level of their business requirements without having to understand the architecture and underlying enforcement systems (overall security state to achieve); see paragraphs 36-37, Jain. Therefore, it would have been obvious to one skilled in the art, before the effective filing date, to have combined the teachings of Jain with those of Kalapatapu, to allow users to ease the defining of a security policy for an entire network without needing to know the details of the architecture or underlying enforcement systems; see paragraph 36, Jain. With regard to claims 79 and 92, Kalapatapu teaches through Jain, the computer readable medium wherein the unified policy for controlling network security includes at least an implementation of a common firewall at each edge device and at each server While Kalapatapu teaches applying a unified security policy across devices of a network, Kalapatapu does not explicitly cite the unified policy controlling a firewall. In the same field of endeavor, Jain also teaches a network that has a unified security policy applied to its devices; see paragraph 6, Jain. In particular, Jain teaches providing a unified security policy and allowing users to define a single security policy without having to explicitly determine where each rule in the policy should be enforced or what technology should do the enforcement; see paragraph 36, Jain. The security policies can be incorporated into policy digests; see paragraph 83, Jain. Jain further explains how the policy includes controlling firewalls; see paragraphs 36 and 55, Jain. Jain teaches an approach allowing for central configuration and management of a plurality of discrete yet coordinate security systems and subsystems in a cloud; see paragraph 37, Jain. It allows customers to define their security policy in a single location at the level of their business requirements without having to understand the architecture and underlying enforcement systems; again see paragraph 37, Jain. Therefore it would have been obvious to one skilled in the art, before the effective filing date, to have combined the teachings of Jain with those of Kalapatapu, to allow users to ease the defining of a security policy for an entire network without needing to know the details of the architecture or underlying enforcement systems; see paragraph 36, Jain. With regard to claims 80 and 93, Kalapatapu teaches through Jain, the computer readable medium wherein the unified policy for controlling network security includes at least an implementation of a coordinated encryption protocol at each edge device and at each server While Kalapatapu teaches applying a unified security policy across devices (including edge devices) of a network, Kalapatapu does not explicitly cite the unified policy controlling an encrypted protocol. In the same field of endeavor, Jain also teaches a network that has a unified security policy applied to its devices; see paragraph 6, Jain. In particular, Jain teaches providing a unified security policy and allowing users to define a single security policy without having to explicitly determine where each rule in the policy should be enforced or what technology should do the enforcement; see paragraph 36, Jain. The security policies can be incorporated into policy digests; see paragraph 83, Jain. Jain further explains how the policy includes controlling encrypted protocols such as communication and tunnels; see paragraphs 68, 70, Jain. Jain teaches an approach allowing for central configuration and management of a plurality of discrete yet coordinate security systems and subsystems in a cloud; see paragraph 37, Jain. It allows customers to define their security policy in a single location at the level of their business requirements without having to understand the architecture and underlying enforcement systems; again see paragraph 37, Jain. Therefore it would have been obvious to one skilled in the art, before the effective filing date, to have combined the teachings of Jain with those of Kalapatapu, to allow users to ease the defining of a security policy for an entire network without needing to know the details of the architecture or underlying enforcement systems; see paragraph 36, Jain. With regard to claims 81 and 94, Kalapatapu teaches through Jain, the computer readable medium wherein the unified policy for controlling network security includes at least a connectivity portion (Kalapatapu teaches the security policy restricting or choosing a path as being complying with the security policy; see paragraphs 11-13 and 21, Kalapatapu). With regard to claims 82 and 95, Kalapatapu teaches through Jain, the computer readable medium wherein the connectivity portion includes restricting incoming and outgoing data associated with at least one application running on the edge devices (Kalapatapu teaches the security policy restricting or choosing paths, including for edge devices, as being complying with the security policy; see paragraphs 21-22 and 40, Kalapatapu). With regard to claims 83 and 96, Kalapatapu teaches through Jain, the computer readable medium wherein the connectivity portion includes assigning different priorities for allocating bandwidth to different applications running on the edge devices (Kalapatapu teaches the policy restricting or choosing paths, including for edge devices. The path selections can take into account throughputs (allocating bandwidth); see paragraphs 21-22, 40 and 45, Kalapatapu). With regards to claim 84, Kalapatapu teaches through Jain, the computer readable medium wherein the connectivity portion includes assigning different priorities for allocating bandwidth to different edge devices associated with different users (Kalapatapu teaches the policy restricting or choosing paths, including for edge devices, and taking into account their closeness to end users and user configuration; see paragraphs 21-22, 30, and 59, Kalapatapu. The path selections can take into account throughputs (allocating bandwidth); see paragraphs 40 and 45, Kalapatapu). With regards to claim 85, Kalapatapu teaches through Jain, the computer readable medium wherein the instructing includes transmitting a common configuration file defining at least a portion of the unified policy to each edge device and to each server (Kalapatapu teaches the policy restricting or choosing paths, including for edge devices and other devices, and taking into account their closeness to end users and user configuration; see paragraphs 21-22, 30, and 59, Kalapatapu). With regards to claim 86, Kalapatapu teaches through Jain, the computer readable medium wherein the instructing includes transmitting a first configuration file defining the unified policy to each edge device and transmitting a second configuration file defining the unified policy to each server While Kalapatapu teaches applying a unified security policy across devices (including edge devices) of a network, Kalapatapu does not explicitly cite sending configuration files based on device type. In the same field of endeavor, Jain also teaches a network that has a unified security policy applied to its devices; see paragraph 6, Jain. In particular, Jain teaches providing a unified security policy and allowing users to define a single security policy without having to explicitly determine where each rule in the policy should be enforced or what technology should do the enforcement; see paragraph 36, Jain. The security policies can be incorporated into policy digests; see paragraph 83, Jain. Jain further explains the policy digest being formatted according to a predefined format and determining if the digest is consistent with the related system/device (i.e. configuration file for edge or server device type); see paragraphs 14 and 118, Jain. Jain teaches an approach allowing for central configuration and management of a plurality of discrete yet coordinate security systems and subsystems in a cloud; see paragraph 37, Jain. It allows customers to define their security policy in a single location at the level of their business requirements without having to understand the architecture and underlying enforcement systems; again see paragraph 37, Jain. Therefore it would have been obvious to one skilled in the art, before the effective filing date, to have combined the teachings of Jain with those of Kalapatapu, to allow users to ease the defining of a security policy for an entire network without needing to know the details of the architecture or underlying enforcement systems; see paragraph 36, Jain. With regards to claim 87, Kalapatapu teaches through Jain, the computer readable medium wherein the first configuration file is formatted according to first file format and wherein the second configuration file is formatted according to a second file format While Kalapatapu teaches applying a unified security policy across devices (including edge devices) of a network, Kalapatapu does not explicitly cite configuration files being formatted based on device type. In the same field of endeavor, Jain also teaches a network that has a unified security policy applied to its devices; see paragraph 6, Jain. In particular, Jain teaches providing a unified security policy and allowing users to define a single security policy without having to explicitly determine where each rule in the policy should be enforced or what technology should do the enforcement; see paragraph 36, Jain. The security policies can be incorporated into policy digests; see paragraph 83, Jain. Jain further explains the policy digest being formatted according to a predefined format and determining if the digest is consistent with the related system/device (i.e. configuration file for edge or server device type); see paragraphs 14 and 118, Jain. Jain teaches an approach allowing for central configuration and management of a plurality of discrete yet coordinate security systems and subsystems in a cloud; see paragraph 37, Jain. It allows customers to define their security policy in a single location at the level of their business requirements without having to understand the architecture and underlying enforcement systems; again see paragraph 37, Jain. Therefore it would have been obvious to one skilled in the art, before the effective filing date, to have combined the teachings of Jain with those of Kalapatapu, to allow users to ease the defining of a security policy for an entire network without needing to know the details of the architecture or underlying enforcement systems; see paragraph 36, Jain. With regards to claim 88, Kalapatapu teaches through Jain, the computer readable medium wherein capabilities of the unified policy differ between the edge devices and the servers (Kalapatapu teaches recognizing non-homogenous capabilities and having policies for edge devices and other devices; ass paragraphs 39 and 41, Kalapatapu). With regards to claim 89, Kalapatapu teaches through Jain, the computer readable medium further comprising providing an administrative view of the differences in capabilities (Kalapatapu supports a GUI displaying paths and policies associated with each node and security policy compliance; see paragraphs 48-49, Kalapatapu). With regards to claim 90, Kalapatapu teaches through Jain, the computer readable medium wherein the first subsets of the security actions and the second subsets of the security actions include at least partial enforcement of the unified policy (A unified portal (e.g. cloud service management application) applies the security policy (unified policy for controlling network security) to the edge and other devices within the network; see paragraphs 39 and 41 and Figure 1A, Kalapatapu. The unified portal includes a (1) shift-rotate defense module (used to monitor edge devices to enable the sending of security policy to edge devices via the unified portal; see paragraph 40, Kalapatapu) and a (2) cloud security posture management (CSPM) (used to monitor other devices to enable the sending of security policy via the unified portal) to enable the unified portal to manage the security policy across the edge and other devices; see paragraphs 35, 38, and 40, Kalapatapu). The obviousness motivation applied to independent claims 78, 91, and 97 are applicable to their respective dependent claims. Response to Arguments Applicant's arguments filed August 6, 2026 have been considered but they are not deemed fully persuasive. The following are the examiner’s responses to the applicant’s arguments. In light of the latest claim amendments, the 101 rejection is now overcome and the rejection has been withdrawn. The applicant’s next (and principle) argument focuses on the claim limitation of, “…instructing, consistent with the unified policy, each edge device to perform first subsets of the security actions… and instructing, consistent with the unified policy, each server to perform second subsets of the security actions…” Applicant alleges that neither prior art teach this limitation. In particular, applicant contends that Kalapatapu does not disclose or suggest any instruction of edge or server devices to perform any actions, merely monitoring the paths. The examiner respectfully disagrees with this assertion. As explained in the office action, Kalapatapu teaches the unified portal includes a (1) shift-rotate defense module (used to monitor edge devices (first subset of security actions) to enable the sending of security policy to edge devices via the unified portal); see paragraphs 39-40, Kalapatapu. The security policy changes ensure only certain paths and assets are used by devices, such as edge devices, to meet the desired security policy; see paragraph 21, Kalapatapu. So it is evident that the security action of sending a security policy to enable a policy change to edge devices is taught. Kalapatapu also teaches a cloud security posture management (CSPM) that is used to monitor other devices, that is non-edge local and cloud devices (second subset of security actions), to enable the sending of security policy via the unified portal to enable the unified portal to manage the security policy across the edge and other devices; see paragraphs 35, 38-39, and 40, Kalapatapu. The security policy changes ensure only certain paths and assets are used by devices such as, cloud and local devices, to meet the desired security policy; see paragraph 21, Kalapatapu). So here it is evident that non-edge devices are provided the security action of being sent security policies to enable policy changes. As such, applicant’s arguments are not deemed persuasive and the 103 rejections are being maintained. Conclusion THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to AZIZUL Q CHOUDHURY whose telephone number is (571)272-3909. The examiner can normally be reached M-F. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, EMMANUEL MOISE can be reached at (571) 272-3865. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /AZIZUL CHOUDHURY/Primary Examiner, Art Unit 2455
Read full office action

Prosecution Timeline

Oct 24, 2025
Application Filed
May 06, 2026
Non-Final Rejection mailed — §103
Aug 06, 2026
Response Filed
Aug 27, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12744769
DATA AUTHENTICATION IN DISTRIBUTED NETWORKS
2y 10m to grant Granted Sep 22, 2026
Patent 12739221
MESSAGE NOTIFICATION METHOD OF ONLINE MESSENGER, AND COMPUTING DEVICE USING SAME
2y 3m to grant Granted Sep 15, 2026
Patent 12719781
DOWNSHIFT FOR BASE-T1L ETHERNET
1y 10m to grant Granted Aug 25, 2026
Patent 12706766
SYSTEM AND METHOD FOR PRESENTING DOCUMENTS IN ONLINE MEETINGS
1y 7m to grant Granted Aug 11, 2026
Patent 12689535
REMOTE CONFIGURATION OF VIDEOCONFERENCE SETTINGS
3y 8m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
77%
Grant Probability
90%
With Interview (+12.5%)
3y 7m (~2y 8m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 685 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month