Prosecution Insights
Last updated: October 02, 2026
Application No. 19/394,234

Systems and Method for Securing Agent Communications through Input/Output Transformation

Final Rejection §103
Filed
Nov 19, 2025
Priority
May 04, 2023 — provisional 63/463,913 +13 more
Examiner
NAJI, YOUNES
Art Unit
2445
Tech Center
2400 — Computer Networks
Assignee
Vijay Madisetti
OA Round
2 (Final)
75%
Grant Probability
Favorable
3-4
OA Rounds
2y 0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 75% — above average
75%
Career Allowance Rate
342 granted / 455 resolved
+17.2% vs TC avg
Strong +73% interview lift
Without
With
+73.4%
Interview Lift
resolved cases with interview
Typical timeline
2y 11m
Avg Prosecution
31 currently pending
Career history
497
Total Applications
across all art units

Statute-Specific Performance

§101
9.4%
-30.6% vs TC avg
§103
52.2%
+12.2% vs TC avg
§102
12.4%
-27.6% vs TC avg
§112
19.0%
-21.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 455 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Applicant's submission filed on 08/06/2026 has been entered. Claims 1-21 have been examined. Response to Arguments Applicant’s arguments, see Remarks – Pages 12-15 , filed on 08/06/2025 with respect to the rejections of claims 1,8,15 under 102 have been fully considered and are persuasive. Therefore, the rejection has been withdrawn. However, upon further consideration, a new ground of rejection is made in view of Palanki . Applicant’s arguments, see Remarks – Pages 15-17 , filed on 08/06/2025 with respect to the rejections of claims 2,9,16 under 103 have been fully considered and are persuasive. Therefore, the rejection has been withdrawn. However, upon further consideration, a new ground of rejection is made in view of Majmudar. With regards to Claim objection , Applicant’s amendment overcomes the objection. Therefore, the objection is withdrawn. With regards to 112 2nd rejection, Applicant’s amendments/arguments overcome the rejections. Therefore, the rejections are withdrawn. Priority Applicant’s claim for the benefit of a prior-filed application under 35 U.S.C. 119(e) or under 35 U.S.C. 120, 121, or 365(c) is acknowledged. Applicant has not complied with one or more conditions for receiving the benefit of an earlier filing date under 35 U.S.C. 119 (e) as follows: The later-filed application must be an application for a patent for an invention which is also disclosed in the prior application (the parent or original non- provisional application or provisional application). The disclosure of the invention in the parent application and in the later-filed application must be sufficient to comply with the requirements of 35 U.S.C. 112(a) or the first paragraph of pre-AIA 35 U.S.C. 112, except for the best mode requirement. See Transco Products, Inc. v. Performance Contracting, Inc., 38 F.3d 551, 32 USPQ2d 1077 (Fed. Cir. 1994) The disclosure of the prior-filed application, Applications No. 18/812,707 18/470,487, 18/348,692 and provisional applications No. 63/463,913, 63/469,571, 63/529,177, 63/534,974, 63/535,118, 63/607,112, 63/607,647, 63/647,092, 63/693,351 fail to provide adequate support or enablement in the manner provided by 35 U.S.C. 112(a) or pre-AIA 35 U.S.C. 112, first paragraph for one or more claims of this application. The limitations (e.g. receiving an input at an input adapter; generating a secured input by the input adapter by performing a security check to detect and remove one or more of potential malware, phishing attempts, or other security threats ….etc.) in the instant application are not supported by the specification of application Applications No. 18/812,707, 18/470,487, 18/348,692, and provisional applications No. 63/463,913, 63/469,571, 63/529,177, 63/534,974, 63/535,118, 63/607,112, 63/607,647, 63/647,092, 63/693,351 . Therefore, the priority date for these applications are not granted. The Examiner will consider the priority date back to application No. 18/921,852 dated 10-21-2024. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1,8,15 are rejected under 35 U.S.C. 103 as being unpatentable over Gerea et al. Publication No. US 2011/0093631 A1 ( Gerea hereinafter) in view of Palanki et al. Publication No. US 2025/0156527 A1 ( Palanki hereinafter) Regarding claim 1, Gerea teaches a method for securing agent communications through input/output transformation comprising: receiving an input at an input adapter (¶ 0012 -The CEP input adapter is configured to store event objects received from a source at an input queue); generating a secured input by the input adapter [..] (¶ 0003 -adapters may provide data transformation and handling functionality for data flowing into and out of an event processing system. Because such input and output adapters are based on a common vendor-provided adapter framework, users may define conversion logic for the input and output adapters while relying on the vendor-provided framework to provide handling of different stream conditions -The adapters may further be configured to execute declarative queries or portions thereof ( e.g., for filtering purposes), thereby simplifying processing at a query engine coupled to the adapters – ¶ 0014 -first interface 106 and the second interface 118 are part of a communications stack that includes logic ( e.g., in the form of an input adapter and an output adapter, respectively) to convert event objects and result objects to and from an object format that is native to the computer system 100 – ¶ 0023 -The CEP input adapter 210 may enqueue event objects 214 to an input queue 212); routing the secured input to one or more [..] agents; generating an agent output by processing the secured input by the one or more agents (Abstract, ¶ 0012 -The system also includes a query engine configured to remove event objects from the input queue, to perform a query with respect to the removed event objects to generate result objects, and to insert result objects into an output queue – ¶ 0024 - When event objects 214 are dequeued at the CEP query engine 220, the logic 224 may execute one or more declarative CEP queries with respect to the event objects 214 to produce CEP result objects 228. For example, each of the one or more declarative CEP queries may include any number of relational algebra operators that operate on one or more of event payloads, event validity start times, and event validity end times of the CEP event objects 214); routing the agent output to an output adapter; generating a formatted output by processing the agent output by the output adapter; and transmitting the formatted output to one or more external systems (Abstract, ¶ 0012-The system also includes an output adapter configured to remove result objects from the output queue and to transmit the result objects to a sink – ¶ 0025 -The CEP output adapter 230 may dequeue the CEP result objects 228 from the output queue 234. In a particular embodiment, the CEP output adapter 230 may convert the dequeued CEP result objects 228 from the second data format native to the CEP system 200 to a third data format (e.g., another proprietary format) native to the sink 240. The CEP output adapter 230 may transmit the CEP result objects 228 to the sink 240 via the output stream 238 – ¶ 0032 -the CEP output adapter 230 may execute a running state during which result objects are transmitted to the sink 240). However, Gerea does not explicitly teach generating a secured input by performing a security check to detect and remove one or more of potential malware, phishing attempts, or other security threats and the one or more agents is a Large language model (LLM) agent. Palanki teaches generating a secured input by performing a security check to detect and remove one or more of potential malware, phishing attempts, or other security threats and routing the secured input to one or more LLM agents input (Abstract - A client device can execute an LLM security sandbox that includes at least one LLM communications sanitization process. The LLM security sandbox can perform the at least one LLM communications sanitization process on the LLM message to generate an approved LLM message. The client device can provide access to the approved LLM message by at least generating a user interface that includes the approved LLM message, or transmitting the approved LLM message from the client device to the LLM service - ¶0011 - The mechanisms described in the present disclosure provide a sandboxed environment for sanitizing LLM interactions including messages provided as inputs to an LLM, and messages provided as responses from the LLM. The input sanitation can include checking for SDEs, harmful content, biases, malicious prompt injections, and so on. The output sanitation can include checking for harmful content, biases, malicious prompt injections, and LLM hallucinations. The input and output sanitation services can then forward an approved message that can include an original message or a sanitized message. The sanitized message can be a modified version of the original message – ¶0044 - the LLM input sanitization process can include a security process utilized by an enterprise to ensure predetermined information including, SDEs, harmful content, biases, malicious prompt injections, and so on are not allowed to be transmitted from the client device – ¶0058 - The moderator comment can be provided in the LLM user interface so the user understands that the original message was modified. In some cases, the LLM user interface can prompt the user to accept the modified message before forwarding the modified message to the LLM service. See Also ¶ 0075,Fig.3). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Gerea to include the teachings of Palanki. The motivation for doing so is to allow the system to ensure predetermined information including, SDEs, harmful content, biases, malicious prompt injections, and so on are not allowed to be transmitted from the client device (Palanki – ¶ 0045). Regarding claim 8, Gerea teaches a secure agent communication system comprising: a processor; a communication device positioned in communication with the processor and operable to communicate with an external system; and a non-transitory computer-readable storage medium positioned in communication with the processor and having stored thereon instructions that, when executed by the processor, are operable to establish: an input adapter configured to: receive an input (¶ 0012 -The CEP input adapter is configured to store event objects received from a source at an input queue); generate a secured input by the input adapter [..] (¶ 0003 -adapters may provide data transformation and handling functionality for data flowing into and out of an event processing system. Because such input and output adapters are based on a common vendor-provided adapter framework, users may define conversion logic for the input and output adapters while relying on the vendor-provided framework to provide handling of different stream conditions -The adapters may further be configured to execute declarative queries or portions thereof ( e.g., for filtering purposes), thereby simplifying processing at a query engine coupled to the adapters – ¶ 0014 -first interface 106 and the second interface 118 are part of a communications stack that includes logic ( e.g., in the form of an input adapter and an output adapter, respectively) to convert event objects and result objects to and from an object format that is native to the computer system 100 – ¶ 0023 -The CEP input adapter 210 may enqueue event objects 214 to an input queue 212); one or more [..] agents configured to generate an agent output by processing the secured input (Abstract, ¶ 0012 -The system also includes a query engine configured to remove event objects from the input queue, to perform a query with respect to the removed event objects to generate result objects, and to insert result objects into an output queue – ¶ 0024 - When event objects 214 are dequeued at the CEP query engine 220, the logic 224 may execute one or more declarative CEP queries with respect to the event objects 214 to produce CEP result objects 228. For example, each of the one or more declarative CEP queries may include any number of relational algebra operators that operate on one or more of event payloads, event validity start times, and event validity end times of the CEP event objects 214); an output adapter configured to: generate a formatted output by processing the agent output; and transmit the formatted output to one or more external systems. (Abstract, ¶ 0012-The system also includes an output adapter configured to remove result objects from the output queue and to transmit the result objects to a sink – ¶ 0025 -The CEP output adapter 230 may dequeue the CEP result objects 228 from the output queue 234. In a particular embodiment, the CEP output adapter 230 may convert the dequeued CEP result objects 228 from the second data format native to the CEP system 200 to a third data format (e.g., another proprietary format) native to the sink 240. The CEP output adapter 230 may transmit the CEP result objects 228 to the sink 240 via the output stream 238 – ¶ 0032 -the CEP output adapter 230 may execute a running state during which result objects are transmitted to the sink 240). However, Gerea does not explicitly teach that generate a secured input by performing a security check to detect and remove one or more of potential malware, phishing attempts, or other security threats and the one or more agents is a Large language model (LLM) agent ;. Palanki teaches generating a secured input by performing a security check to detect and remove one or more of potential malware, phishing attempts, or other security threats and one or more LLM agents configured to generate an agent output by processing the secured input (Abstract - A client device can execute an LLM security sandbox that includes at least one LLM communications sanitization process. The LLM security sandbox can perform the at least one LLM communications sanitization process on the LLM message to generate an approved LLM message. The client device can provide access to the approved LLM message by at least generating a user interface that includes the approved LLM message, or transmitting the approved LLM message from the client device to the LLM service - ¶0011 - The mechanisms described in the present disclosure provide a sandboxed environment for sanitizing LLM interactions including messages provided as inputs to an LLM, and messages provided as responses from the LLM. The input sanitation can include checking for SDEs, harmful content, biases, malicious prompt injections, and so on. The output sanitation can include checking for harmful content, biases, malicious prompt injections, and LLM hallucinations. The input and output sanitation services can then forward an approved message that can include an original message or a sanitized message. The sanitized message can be a modified version of the original message – ¶0044 - the LLM input sanitization process can include a security process utilized by an enterprise to ensure predetermined information including, SDEs, harmful content, biases, malicious prompt injections, and so on are not allowed to be transmitted from the client device – ¶0058 - The moderator comment can be provided in the LLM user interface so the user understands that the original message was modified. In some cases, the LLM user interface can prompt the user to accept the modified message before forwarding the modified message to the LLM service. See Also ¶0075,Fig.3). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Gerea to include the teachings of Palanki. The motivation for doing so is to allow the system to ensure predetermined information including, SDEs, harmful content, biases, malicious prompt injections, and so on are not allowed to be transmitted from the client device (Palanki – ¶ 0045). Regarding claim 15, Gerea teaches A secure agent communication system comprising: means for receiving an input; (¶ 0012 -The CEP input adapter is configured to store event objects received from a source at an input queue); means for generating a secured input [..] (¶ 0003 -adapters may provide data transformation and handling functionality for data flowing into and out of an event processing system. Because such input and output adapters are based on a common vendor-provided adapter framework, users may define conversion logic for the input and output adapters while relying on the vendor-provided framework to provide handling of different stream conditions -The adapters may further be configured to execute declarative queries or portions thereof ( e.g., for filtering purposes), thereby simplifying processing at a query engine coupled to the adapters – ¶ 0014 -first interface 106 and the second interface 118 are part of a communications stack that includes logic ( e.g., in the form of an input adapter and an output adapter, respectively) to convert event objects and result objects to and from an object format that is native to the computer system 100 – ¶ 0023 -The CEP input adapter 210 may enqueue event objects 214 to an input queue 212); means for generating an agent output by processing the secured input by one or more [..] agents (Abstract, ¶ 0012 -The system also includes a query engine configured to remove event objects from the input queue, to perform a query with respect to the removed event objects to generate result objects, and to insert result objects into an output queue – ¶ 0024 - When event objects 214 are dequeued at the CEP query engine 220, the logic 224 may execute one or more declarative CEP queries with respect to the event objects 214 to produce CEP result objects 228. For example, each of the one or more declarative CEP queries may include any number of relational algebra operators that operate on one or more of event payloads, event validity start times, and event validity end times of the CEP event objects 214); means for generating a formatted output by processing the agent output by the output adapter; and means for transmitting the formatted output to one or more external systems (Abstract, ¶ 0012-The system also includes an output adapter configured to remove result objects from the output queue and to transmit the result objects to a sink – ¶ 0025 -The CEP output adapter 230 may dequeue the CEP result objects 228 from the output queue 234. In a particular embodiment, the CEP output adapter 230 may convert the dequeued CEP result objects 228 from the second data format native to the CEP system 200 to a third data format (e.g., another proprietary format) native to the sink 240. The CEP output adapter 230 may transmit the CEP result objects 228 to the sink 240 via the output stream 238 – ¶ 0032 -the CEP output adapter 230 may execute a running state during which result objects are transmitted to the sink 240). However, Gerea does not explicitly teach that generate a secured input by performing a security check to detect and remove one or more of potential malware, phishing attempts, or other security threats and the one or more agents is a Large language model (LLM) agent ;. Palanki teaches generating a secured input by performing a security check to detect and remove one or more of potential malware, phishing attempts, or other security threats and means for generating agent output by processing the secured input by one or more LLM agents (Abstract - A client device can execute an LLM security sandbox that includes at least one LLM communications sanitization process. The LLM security sandbox can perform the at least one LLM communications sanitization process on the LLM message to generate an approved LLM message. The client device can provide access to the approved LLM message by at least generating a user interface that includes the approved LLM message, or transmitting the approved LLM message from the client device to the LLM service - ¶0011 - The mechanisms described in the present disclosure provide a sandboxed environment for sanitizing LLM interactions including messages provided as inputs to an LLM, and messages provided as responses from the LLM. The input sanitation can include checking for SDEs, harmful content, biases, malicious prompt injections, and so on. The output sanitation can include checking for harmful content, biases, malicious prompt injections, and LLM hallucinations. The input and output sanitation services can then forward an approved message that can include an original message or a sanitized message. The sanitized message can be a modified version of the original message – ¶0044 - the LLM input sanitization process can include a security process utilized by an enterprise to ensure predetermined information including, SDEs, harmful content, biases, malicious prompt injections, and so on are not allowed to be transmitted from the client device – ¶0058 - The moderator comment can be provided in the LLM user interface so the user understands that the original message was modified. In some cases, the LLM user interface can prompt the user to accept the modified message before forwarding the modified message to the LLM service. See Also ¶0075,Fig.3). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Gerea to include the teachings of Palanki. The motivation for doing so is to allow the system to ensure predetermined information including, SDEs, harmful content, biases, malicious prompt injections, and so on are not allowed to be transmitted from the client device (Palanki – ¶ 0045). Claims 2,9 are rejected under 35 U.S.C. 103 as being unpatentable over Gerea in view of Palanki further in view of Royyuru et al. Publication No. US 2021/0357900 A1 ( Royyuru hereinafter) further in view of Majmudar et al. Patent No. US 12,437,058 B1 ( Majmudar hereinafter) Regarding claim 2, Gerea further teaches wherein the input adapter is configured to: generate a normalized input by processing the input by an input normalizer configured to standardize the input when the input is in non-uniform formats into a consistent secure structure ( ¶ 0003 -adapters may provide data transformation and handling functionality for data flowing into and out of an event processing system. Because such input and output adapters are based on a common vendor-provided adapter framework, users may define conversion logic for the input and output adapters while relying on the vendor-provided framework to provide handling of different stream conditions -The adapters may further be configured to execute declarative queries or portions thereof (e.g., for filtering purposes), thereby simplifying processing at a query engine coupled to the adapters – ¶ 0014 -first interface 106 and the second interface 118 are part of a communications stack that includes logic ( e.g., in the form of an input adapter and an output adapter, respectively) to convert event objects and result objects to and from an object format that is native to the computer system 100 – ¶ 0027 - a particular CEP event object indicating that the stock price for Microsoft Corp. is $20.33 at 9:30 am on Jan. 2, 2009 may be received from the source (e.g., a stock price ticker feed), translated into a data format native to the CEP system, and inserted into the input queue); and generate the secured input by enriching the normalized input (¶ 0003 - The adapters may further be configured to execute declarative queries or portions thereof ( e.g., for filtering purposes), thereby simplifying processing at a query engine coupled to the adapters). However, Gerea does not explicitly teach generate the secured input by enriching the normalized input by a context enricher configured to augment the normalized input with security-validated additional context., wherein the additional context is security validated prior to augmenting the normalized input wherein the additional context is a security validated by performing a security check on the additional context to detect and remove one or more potential malware, phishing attempts or other security threats prior to augmenting the normalized input. Royyuru teaches generate the secured input by enriching the normalized input by a context enricher configured to augment the normalized input with security-validated additional context ( ¶ 0061 – The content enricher(s) may include computer executable instructions that in response to execution by the processor(s) cause operations to be performed including enriching a message prior to storing the parameters received from the mobile device 104, including mobile IP, geolocation information, user agent information, etc. – ¶ 0082 - At exchange 410, the content enricher may receive the request from the controller for mobile application enricher, the content enricher may evaluate the user agent information associated with the web browser to identify any additional information that may be available ( e.g., version, platform associated with the mobile device. ¶ 0083 - the content enricher may enrich the request received form the app registry. In some embodiments, enriching the request may include augmenting or otherwise providing additional information, such as an IP address associated with the mobile device, geolocation information associated with the mobile device, browser user agent information associated with a web browser associated with the mobile device, or the like. ¶ 0084 -] At exchange 420, the content enricher 268 may transmit the enriched message that includes the mobile application information to the controller. ¶ 0085 At exchange 422, the controller, responsive to receiving the enriched message from the content enricher, may transmit a message to the claim check module to generate a claim check – ¶0074 -the gateway server may perform one or more security services. For example, the gateway server 108 may determine whether the URI was not tampered with or otherwise manipulated based at least in part on the tag signature received from the mobile device - ¶0075 -the wallet app server may perform one or more security services on the data received from the gateway server. See Also ¶ 0091 -0092). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Gerea to include the teachings of Royyuru. The motivation for doing so is to allow the system to append missing data to a payload on the fly which solves the data gaps and boosts personalization without requiring the sender to manually process or look up extra details. Majmudar teaches wherein the additional context is security-validated by performing a security check on the additional context to detect and remove one or more of potential malware, phishing attempts, or other security threats prior to augmenting the normalized input (Col.8, lines 55-70 - the prompt data and/or context data associated with the prompt may be sent to a prompt validation component 148 (step 1). The prompt validation component 148 may validate the prompt data by determining whether data in the prompt violates one or more predefined rules , the prompt validation component 148 may use a predefined set of rules (e.g., allow lists, deny lists, etc.) to validate the prompt (step 2) – Col.9, lines 1-10 - the prompt validation component 148 may use a machine learning model trained to detect prompt instructions that violate privacy, security, and/or are associated with impermissible actions – Col.12, lines 25-30 - One example of an invalid action that may be detected by action validation component may be an LLM inference output and/or action plan that attempts to call an untrusted/ non-allow listed API that might inject a malicious prompt - Col. 11, lines 30-35 - since all actions and action results have been validated using the security threat mitigation component 160 – Col.3, lines 10-20 - An indirect prompt injection instruction may be an impermissible instruction to inject data ( e.g., a natural language directive or instruction) into a subsequent prompt that may then be used during LLM-processing). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Gerea to include the teachings of Majmudar. The motivation for doing so is to allow the system to provide security threat mitigation for generative machine learning models (Majmudar – Abstract). Regarding claim 9, Gerea further teaches wherein the input adapter comprises: an input normalizer configured to generate a normalized input by standardizing the input when the input is in non-uniform formats into a consistent secure structure; ( ¶ 0003 -adapters may provide data transformation and handling functionality for data flowing into and out of an event processing system. Because such input and output adapters are based on a common vendor-provided adapter framework, users may define conversion logic for the input and output adapters while relying on the vendor-provided framework to provide handling of different stream conditions -The adapters may further be configured to execute declarative queries or portions thereof ( e.g., for filtering purposes), thereby simplifying processing at a query engine coupled to the adapters – ¶ 0014 -first interface 106 and the second interface 118 are part of a communications stack that includes logic ( e.g., in the form of an input adapter and an output adapter, respectively) to convert event objects and result objects to and from an object format that is native to the computer system 100 – ¶ 0027 - a particular CEP event object indicating that the stock price for Microsoft Corp. is $20.33 at 9:30 am on Jan. 2, 2009 may be received from the source (e.g., a stock price ticker feed), translated into a data format native to the CEP system, and inserted into the input queue); context enricher configured to generate the secured input by enriching the normalized input (¶ 0003 - The adapters may further be configured to execute declarative queries or portions thereof ( e.g., for filtering purposes), thereby simplifying processing at a query engine coupled to the adapters). However, Gerea does not explicitly teach generate the secured input by enriching the normalized input by a context enricher configured to augment the normalized input with security-validated additional context. wherein the additional context is security-validated by performing a security check on the additional context to detect and remove one or more of potential malware, phishing attempts, or other security threats prior to augmenting the normalized input Royyuru teaches generate the secured input by enriching the normalized input by a context enricher configured to augment the normalized input with security-validated additional context ( ¶ 0061 – The content enricher(s) may include computer executable instructions that in response to execution by the processor(s) cause operations to be performed including enriching a message prior to storing the parameters received from the mobile device 104, including mobile IP, geolocation information, user agent information, etc. – ¶ 0082 - At exchange 410, the content enricher may receive the request from the controller for mobile application enricher, the content enricher may evaluate the user agent information associated with the web browser to identify any additional information that may be available ( e.g., version, platform associated with the mobile device. ¶ 0083 - the content enricher may enrich the request received form the app registry. In some embodiments, enriching the request may include augmenting or otherwise providing additional information, such as an IP address associated with the mobile device, geolocation information associated with the mobile device, browser user agent information associated with a web browser associated with the mobile device, or the like. ¶ 0084 -] At exchange 420, the content enricher 268 may transmit the enriched message that includes the mobile application information to the controller. ¶ 0085 At exchange 422, the controller 266, responsive to receiving the enriched message from the content enricher 268, may transmit a message to the claim check module to generate a claim check – ¶0074 -the gateway server may perform one or more security services. For example, the gateway server may determine whether the URI was not tampered with or otherwise manipulated based at least in part on the tag signature received from the mobile device - ¶0075 -the wallet app server may perform one or more security services on the data received from the gateway server. See Also ¶ 0091 -0092). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Gerea to include the teachings of Royyuru. The motivation for doing so is to allow the system to append missing data to a payload on the fly which solves the data gaps and boosts personalization without requiring the sender to manually process or look up extra details. Majmudar teaches wherein the additional context is security-validated by performing a security check on the additional context to detect and remove one or more of potential malware, phishing attempts, or other security threats prior to augmenting the normalized input (Col.8, lines 55-70 - the prompt data and/or context data associated with the prompt may be sent to a prompt validation component 148 (step 1). The prompt validation component 148 may validate the prompt data by determining whether data in the prompt violates one or more predefined rules , the prompt validation component 148 may use a predefined set of rules (e.g., allow lists, deny lists, etc.) to validate the prompt (step 2) – Col.9, lines 1-10 - the prompt validation component 148 may use a machine learning model trained to detect prompt instructions that violate privacy, security, and/or are associated with impermissible actions – Col.12, lines 25-30 - One example of an invalid action that may be detected by action validation component 140 may be an LLM inference output and/or action plan that attempts to call an untrusted/ non-allow listed API that might inject a malicious prompt - Col. 11, lines 30-35 - since all actions and action results have been validated using the security threat mitigation component 160 – Col.3, lines 10-20 - An indirect prompt injection instruction may be an impermissible instruction to inject data ( e.g., a natural language directive or instruction) into a subsequent prompt that may then be used during LLM-processing). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Gerea to include the teachings of Majmudar. The motivation for doing so is to allow the system to provide security threat mitigation for generative machine learning models (Majmudar – Abstract). Claims 3,10 are rejected under 35 U.S.C. 103 as being unpatentable over Gerea in view of Palanki further in in view of Royyuru further in view of Majmudar further in view of Reisman et al. Publication No. US 2012/0204171 A1 ( Reisman hereinafter) Regarding claim 3, Gerea does not explicitly teach wherein the input normalizer is configured to implement content safety screening to prevent inclusion of explicit, violent, or inappropriate material. However, Reisman teaches input normalizer is configured to implement content safety screening to prevent inclusion of explicit, violent, or inappropriate material (¶ 0383 - The link interceptor module, when configured to intercept all or selected external links or Get URL requests enables user activity to be screened so that undesired requests can be denied or filtered out. Such a screening process can be used to prevent users retrieving inappropriate content, for example content judged indecent or obscene, or from competitors Web sites, so long as an address, or URL, for that content is known. If the user attempts to get an URL on the excluded list, "Object Not Available" can be returned It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Gerea to include the teachings of Reisman. The motivation for doing so is to allow the system to provide screening in order to prevent users from retrieving inappropriate content (Reisman – ¶ 0383). Regarding claim 10, Gerea does not explicitly teach wherein the input normalizer is configured to implement content safety screening to prevent inclusion of explicit, violent, or inappropriate material. However, Reisman teaches input normalizer is configured to implement content safety screening to prevent inclusion of explicit, violent, or inappropriate material (¶ 0383 - The link interceptor module, when configured to intercept all or selected external links or Get URL requests enables user activity to be screened so that undesired requests can be denied or filtered out. Such a screening process can be used to prevent users retrieving inappropriate content, for example content judged indecent or obscene, or from competitors Web sites, so long as an address, or URL, for that content is known. If the user attempts to get an URL on the excluded list, "Object Not Available" can be returned It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Gerea to include the teachings of Reisman. The motivation for doing so is to allow the system to provide screening in order to prevent users from retrieving inappropriate content (Reisman – ¶ 0383). Claims 4,7,11,14,18,21 are rejected under 35 U.S.C. 103 as being unpatentable over Gerea in view of Palanki further in view of De Braal et al. Publication No. WO 2024/094777 A1 ( De Braal hereinafter). Regarding claim 4, Gerea does not explicitly teach wherein the output adapter is configured to process the agent output by: generate an abstracted output by an abstraction layer configured to simplify the agent output while maintaining security properties; and generate the formatted output by an output formatter configured to transform the abstracted output into a secure format. However, De Braal teaches output adapter is configured to process the agent output by: generate an abstracted output by an abstraction layer configured to simplify the agent output while maintaining security properties; and (Page 6 - The device 100 comprises an input transformation engine 101, a core 102, and an output transformation engine 103 – Page 7 - the input transformation engine 101 operates to convert the original input data 105 from its first, original format to an intermediate format which is more suitable for allowing respective data types of the input data to be examined, and is unambiguous in its interpretation. the input transformation engine 101 abstracts and transforms the input data 105 into a canonical format which comprises a set of serialized data portions, where each data portion comprises input data of a single data type only – Page 1 - A previous approach for securely transferring rich data between separate computer 25 networks is referred to as "transcoding", in which a document is translated from a rich data format to a relatively simpler, safer format which includes fewer data types (and in some cases only one data type) before it passes from one system to another – Page 2 - The content checking device and method of the present invention may determine whether portions of the input data conform to a specified allowable criteria (defined by the reference data), to protect downstream consumers/parsers of the input data. By checking for conformance to strict specifications, the present invention may reduce the attack surface, and in effect reduce the probability that a vulnerability in a consuming application (that has implemented logic to read and interpret the input data) will be exploited by an attacker trying to craft the input data to trigger such an exploit – Page 8 - the core 102 operates by determining whether the input data 105 is valid or invalid. Specifically, the high assurance core 102 checks the input data 105 for malicious content, malformed data); generate the formatted output by an output formatter configured to transform the abstracted output into a secure format (Page 9 - the output transformation engine 103 converts the input data 105, having been converted into the intermediate format, to a final format which is to be used by the second computer system - The final format can be any format which is suitable for being interpreted and read by the second computer system. However, to maximizes assurance of the device, in this embodiment the final format is the same as the first, original format in which the input data 105 was received by the input transformation engine 1 - if one or more data portions are invalid, then the core 102 determines that the input data 105 is invalid and will control the flow of input data 105 to ensure that invalid data (e.g. data that may pose a security threat) is not transmitted to the second computer system. the invalid data portion(s) remains but its values are modified, e.g. zeroed or set to a desired non-zero value(s), before being forwarded to the output transformation engine 103 for reformatting to the final format – Page 15 - the result collator 501 releases the node data to the output transformation engine 103 via the USP output buffer 109 for conversion into output data 107 having the same or similar format as the original input data 105 received from the first computer system). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Gerea to include the teachings of De Braal. The motivation for doing so is to allow the system to abstract and transform the input data into a canonical format which comprises a set of serialized data portions (De Braal – Page 7). . Regarding claim 7, Gerea does not explicitly teach the input is received as one of a natural language format, a JavaScript Object Notation (JSON) format; or an Extensible Markup Language (XML) format; and the formatted output has a format of one of a natural language format, a JSON format, and an XML format. De Braal teaches the input is received as one of a natural language format, a JavaScript Object Notation (JSON) format; or an Extensible Markup Language (XML) format; and the formatted output has a format of one of a natural language format, a JSON format, and an XML format (Page 7 - The set of input data 105 received by the device 100 at this stage will typically be in the form of rich data, and have one of the following data formats: XML, 10 XMPP messages, DDS, or structured document formats such as Microsoft Word, Microsoft Excel, or Rich Text Format.-Page 9 -The final format can be any format which is suitable for being interpreted and read by the second computer system. However, to maximizes assurance of the device, in this embodiment the final format is the same as the first, original format in which the input data 105 was received by the input transformation engine 101). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Gerea to include the teachings of De Braal. The motivation for doing so is to allow the system to abstract and transform the input data into a canonical format which comprises a set of serialized data portions (De Braal – Page 7). Regarding claim 11, Gerea does not explicitly teach wherein the output adapter comprises: an abstraction layer configured to generate an abstracted output by simplifying the agent output while maintaining security properties; and an output formatter configured to generate the formatted output by transforming the abstracted output into a secure format.. However, De Braal teaches wherein the output adapter comprises: an abstraction layer configured to generate an abstracted output by simplifying the agent output while maintaining security properties; and (Page 6 - The device 100 comprises an input transformation engine 101, a core 102, and an output transformation engine 103 – Page 7 - the input transformation engine 101 operates to convert the original input data 105 from its first, original format to an intermediate format which is more suitable for allowing respective data types of the input data to be examined, and is unambiguous in its interpretation. the input transformation engine 101 abstracts and transforms the input data 105 into a canonical format which comprises a set of serialized data portions, where each data portion comprises input data of a single data type only – Page 1 - A previous approach for securely transferring rich data between separate computer 25 networks is referred to as "transcoding", in which a document is translated from a rich data format to a relatively simpler, safer format which includes fewer data types (and in some cases only one data type) before it passes from one system to another – Page 2 - The content checking device and method of the present invention may determine whether portions of the input data conform to a specified allowable criteria (defined by the reference data), to protect downstream consumers/parsers of the input data. By checking for conformance to strict specifications, the present invention may reduce the attack surface, and in effect reduce the probability that a vulnerability in a consuming application (that has implemented logic to read and interpret the input data) will be exploited by an attacker trying to craft the input data to trigger such an exploit – Page 8 - the core 102 operates by determining whether the input data 105 is valid or invalid. Specifically, the high assurance core 102 checks the input data 105 for malicious content, malformed data), an output formatter configured to generate the formatted output by transforming the abstracted output into a secure format (Page 9 - the output transformation engine 103 converts the input data 105, having been converted into the intermediate format, to a final format which is to be used by the second computer system - The final format can be any format which is suitable for being interpreted and read by the second computer system. However, to maximizes assurance of the device, in this embodiment the final format is the same as the first, original format in which the input data 105 was received by the input transformation engine 1 - if one or more data portions are invalid, then the core 102 determines that the input data 105 is invalid and will control the flow of input data 105 to ensure that invalid data (e.g. data that may pose a security threat) is not transmitted to the second computer system. the invalid data portion(s) remains but its values are modified, e.g. zeroed or set to a desired non-zero value(s), before being forwarded to the output transformation engine 103 for reformatting to the final format – Page 15 - the result collator 501 releases the node data to the output transformation engine 103 via the USP output buffer 109 for conversion into output data 107 having the same or similar format as the original input data 105 received from the first computer system). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Gerea to include the teachings of De Braal. The motivation for doing so is to allow the system to abstract and transform the input data into a canonical format which comprises a set of serialized data portions (De Braal – Page 7). . Regarding claim 14, Gerea does not explicitly teach the input is received as one of a natural language format, a JavaScript Object Notation (JSON) format; or an Extensible Markup Language (XML) format; and the formatted output has a format of one of a natural language format, a JSON format, and an XML format. However, De Braal teaches the input is received as one of a natural language format, a JavaScript Object Notation (JSON) format; or an Extensible Markup Language (XML) format; and the formatted output has a format of one of a natural language format, a JSON format, and an XML format (Page 7 - The set of input data 105 received by the device 100 at this stage will typically be in the form of rich data, and have one of the following data formats: XML, 10 XMPP messages, DDS, or structured document formats such as Microsoft Word, Microsoft Excel, or Rich Text Format.-Page 9 -The final format can be any format which is suitable for being interpreted and read by the second computer system. However, to maximizes assurance of the device, in this embodiment the final format is the same as the first, original format in which the input data 105 was received by the input transformation engine 101) It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Gerea to include the teachings of De Braal. The motivation for doing so is to allow the system to abstract and transform the input data into a canonical format which comprises a set of serialized data portions (De Braal – Page 7). Regarding claim 18, Gerea does not explicitly teach wherein the means for generating a formatted output comprises: means for generating an abstracted output by simplifying the agent output while maintaining security properties; and means for generating the formatted output by transforming the abstracted output into a secure format. However, De Braal teaches wherein the means for generating a formatted output comprises: means for generating an abstracted output by simplifying the agent output while maintaining security properties;(Page 6 - The device 100 comprises an input transformation engine 101, a core 102, and an output transformation engine 103 – Page 7 - the input transformation engine 101 operates to convert the original input data 105 from its first, original format to an intermediate format which is more suitable for allowing respective data types of the input data to be examined, and is unambiguous in its interpretation. the input transformation engine 101 abstracts and transforms the input data 105 into a canonical format which comprises a set of serialized data portions, where each data portion comprises input data of a single data type only – Page 1 - A previous approach for securely transferring rich data between separate computer 25 networks is referred to as "transcoding", in which a document is translated from a rich data format to a relatively simpler, safer format which includes fewer data types (and in some cases only one data type) before it passes from one system to another – Page 2 - The content checking device and method of the present invention may determine whether portions of the input data conform to a specified allowable criteria (defined by the reference data), to protect downstream consumers/parsers of the input data. By checking for conformance to strict specifications, the present invention may reduce the attack surface, and in effect reduce the probability that a vulnerability in a consuming application (that has implemented logic to read and interpret the input data) will be exploited by an attacker trying to craft the input data to trigger such an exploit – Page 8 - the core 102 operates by determining whether the input data 105 is valid or invalid. Specifically, the high assurance core 102 checks the input data 105 for malicious content, malformed data), means for generating the formatted output by transforming the abstracted output into a secure format (Page 9 - the output transformation engine 103 converts the input data 105, having been converted into the intermediate format, to a final format which is to be used by the second computer system - The final format can be any format which is suitable for being interpreted and read by the second computer system. However, to maximizes assurance of the device, in this embodiment the final format is the same as the first, original format in which the input data 105 was received by the input transformation engine 1 - if one or more data portions are invalid, then the core 102 determines that the input data 105 is invalid and will control the flow of input data 105 to ensure that invalid data (e.g. data that may pose a security threat) is not transmitted to the second computer system. the invalid data portion(s) remains but its values are modified, e.g. zeroed or set to a desired non-zero value(s), before being forwarded to the output transformation engine 103 for reformatting to the final format – Page 15 - the result collator 501 releases the node data to the output transformation engine 103 via the USP output buffer 109 for conversion into output data 107 having the same or similar format as the original input data 105 received from the first computer system). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Gerea to include the teachings of De Braal. The motivation for doing so is to allow the system to abstract and transform the input data into a canonical format which comprises a set of serialized data portions (De Braal – Page 7). Regarding claim 21, Gerea does not explicitly teach the input is received as one of a natural language format, a JavaScript Object Notation (JSON) format; or an Extensible Markup Language (XML) format; and the formatted output has a format of one of a natural language format, a JSON format, and an XML format. However, De Braal teaches the input is received as one of a natural language format, a JavaScript Object Notation (JSON) format; or an Extensible Markup Language (XML) format; and the formatted output has a format of one of a natural language format, a JSON format, and an XML format (Page 7 - The set of input data 105 received by the device 100 at this stage will typically be in the form of rich data, and have one of the following data formats: XML, 10 XMPP messages, DDS, or structured document formats such as Microsoft Word, Microsoft Excel, or Rich Text Format.-Page 9 -The final format can be any format which is suitable for being interpreted and read by the second computer system. However, to maximizes assurance of the device, in this embodiment the final format is the same as the first, original format in which the input data 105 was received by the input transformation engine 101) It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Gerea to include the teachings of De Braal. The motivation for doing so is to allow the system to abstract and transform the input data into a canonical format which comprises a set of serialized data portions (De Braal – Page 7). Claims 5,12,19 are rejected under 35 U.S.C. 103 as being unpatentable over Gerea in view of Palanki further in view of De Braal further in view of Laing et al. Publication No.US US 20170301257A1 ( Laing hereinafter). Regarding claim 5, Gerea does not explicitly teach wherein the output formatter is configured to apply differential formatting based on at least one of a user authentication level and a subscription tier. However, Laing teaches output formatter is configured to apply differential formatting based on at least one of a user authentication level and a subscription tier (¶ 0053 the data may be processed into a first format that will allow it to be viewed on e.g., a smart watch and into a second format that will allow it to be viewed on the monitor of a personal computer; that is a compressed or summarized format for the smaller display and a more detailed format for the larger and more powerful display. Processing of health data may also depend on a subscription level the user maintains with the administrator of the health tracking system. If the user has a standard subscription with the administrator of the health tracking system 10, only limited processing may occur, such as an average heart rate for a period of time or a total number of steps for a day. However, if the user has a premium subscription with the administrator of the health tracking system, the processing of heart rate data may further include an analysis of the time the user spent in different heart rate zones during a given period of time, such as times in the fat burning zone, the aerobic zone, and the anaerobic zone. With respect to step data, users with premium subscriptions may receive detailed information about cadence, split times, or other in-depth analysis performed by the processor. While these are but a few examples of how the raw data may be processed by one or more computers of the health tracking system including the display device 30 or any remote servers, those of skill in the art will recognize that nearly countless other possibilities exist for systems and methods to process the data received from the one or more health monitoring devices 20 for subsequent viewing and analysis. After the raw activity data is transmitted and processed, the processed data may then be displayed or otherwise presented on a user interface of the display device). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Gerea to include the teachings of Laing. The motivation for doing so is to allow the system to apply different format based on subscription tier. Regarding claim 12, Gerea does not explicitly teach wherein the output formatter is configured to apply differential formatting based on at least one of a user authentication level and a subscription tier. However, Laing teaches output formatter is configured to apply differential formatting based on at least one of a user authentication level and a subscription tier (¶ 0053 the data may be processed into a first format that will allow it to be viewed on e.g., a smart watch and into a second format that will allow it to be viewed on the monitor of a personal computer; that is a compressed or summarized format for the smaller display and a more detailed format for the larger and more powerful display. Processing of health data may also depend on a subscription level the user maintains with the administrator of the health tracking system. If the user has a standard subscription with the administrator of the health tracking system 10, only limited processing may occur, such as an average heart rate for a period of time or a total number of steps for a day. However, if the user has a premium subscription with the administrator of the health tracking system, the processing of heart rate data may further include an analysis of the time the user spent in different heart rate zones during a given period of time, such as times in the fat burning zone, the aerobic zone, and the anaerobic zone. With respect to step data, users with premium subscriptions may receive detailed information about cadence, split times, or other in-depth analysis performed by the processor. While these are but a few examples of how the raw data may be processed by one or more computers of the health tracking system including the display device 30 or any remote servers, those of skill in the art will recognize that nearly countless other possibilities exist for systems and methods to process the data received from the one or more health monitoring devices 20 for subsequent viewing and analysis. After the raw activity data is transmitted and processed, the processed data may then be displayed or otherwise presented on a user interface of the display device). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Gerea to include the teachings of Laing. The motivation for doing so is to allow the system to apply different format based on subscription tier. Regarding claim 19, Gerea does not explicitly teach wherein the means for generating a formatted output is operable to apply differential formatting based on at least one of a user authentication level and a subscription tier. However, Laing teaches wherein the means for generating a formatted output is operable to apply differential formatting based on at least one of a user authentication level and a subscription tier. (¶ 0053 the data may be processed into a first format that will allow it to be viewed on e.g., a smart watch and into a second format that will allow it to be viewed on the monitor of a personal computer; that is a compressed or summarized format for the smaller display and a more detailed format for the larger and more powerful display. Processing of health data may also depend on a subscription level the user maintains with the administrator of the health tracking system. If the user has a standard subscription with the administrator of the health tracking system 10, only limited processing may occur, such as an average heart rate for a period of time or a total number of steps for a day. However, if the user has a premium subscription with the administrator of the health tracking system, the processing of heart rate data may further include an analysis of the time the user spent in different heart rate zones during a given period of time, such as times in the fat burning zone, the aerobic zone, and the anaerobic zone. With respect to step data, users with premium subscriptions may receive detailed information about cadence, split times, or other in-depth analysis performed by the processor. While these are but a few examples of how the raw data may be processed by one or more computers of the health tracking system including the display device 30 or any remote servers, those of skill in the art will recognize that nearly countless other possibilities exist for systems and methods to process the data received from the one or more health monitoring devices 20 for subsequent viewing and analysis. After the raw activity data is transmitted and processed, the processed data may then be displayed or otherwise presented on a user interface of the display device). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Gerea to include the teachings of Laing. The motivation for doing so is to allow the system to apply different format based on subscription tier. Claims 6,13,20 are rejected under 35 U.S.C. 103 as being unpatentable over Gerea in view of Palanki further in view of De Braal further in view of Baskaran et al. Publication No. US 2010/0146269 A1 ( Baskaran hereinafter). Regarding claim 6, Gerea does not explicitly teach wherein the formatted output is transmitted with embedded security metadata. However, Baskaran teaches wherein the formatted output is transmitted with embedded security metadata (Fig.5, ¶ 0017 - Metadata associated with one or more configurable functionalities is generated by invoking one or more adapters associated with the configurable functionalities. The electronic content, the user information, the usage policy, the encryption information, and the generated metadata are encapsulated and selectively encrypted in the predefined file structure of the proprietary wrapper file. The user action that triggers encapsulation of the electronic content – ¶ 0038 - After the user is authenticated, the wrapper file is decapsulated for granting controlled access to the electronic content encapsulated within the wrapper file. As used herein, "decapsulation" refers to the process of arriving at the raw electronic content and metadata after decryption and disassembly of the wrapper file. The proprietary wrapper file launches a pre-designated native application to grant access to the electronic content according to the content usage policy. The proprietary wrapper file restricts usage of the electronic content within the networked environment by determining whether security client application can contact the policy server when the user attempts to access the electronic content) It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Gerea to include the teachings of Baskaran. The motivation for doing so is to allow the system to restrict usage of the electronic content within the networked environment by determining whether security client application can contact the policy server when the user attempts to access the electronic content (Baskaran – ¶ 0038). Regarding claim 13, Gerea does not explicitly teach wherein the formatted output is transmitted with embedded security metadata. However, Baskaran teaches wherein the formatted output is transmitted with embedded security metadata (Fig.5, ¶ 0017 - Metadata associated with one or more configurable functionalities is generated by invoking one or more adapters associated with the configurable functionalities. The electronic content, the user information, the usage policy, the encryption information, and the generated metadata are encapsulated and selectively encrypted in the predefined file structure of the proprietary wrapper file. The user action that triggers encapsulation of the electronic content – ¶ 0038 - After the user is authenticated, the wrapper file is decapsulated for granting controlled access to the electronic content encapsulated within the wrapper file. As used herein, "decapsulation" refers to the process of arriving at the raw electronic content and metadata after decryption and disassembly of the wrapper file. The proprietary wrapper file launches a pre-designated native application to grant access to the electronic content according to the content usage policy. The proprietary wrapper file restricts usage of the electronic content within the networked environment by determining whether security client application can contact the policy server when the user attempts to access the electronic content) It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Gerea to include the teachings of Baskaran. The motivation for doing so is to allow the system to restrict usage of the electronic content within the networked environment by determining whether security client application can contact the policy server when the user attempts to access the electronic content (Baskaran – ¶ 0038). Regarding claim 20, Gerea does not explicitly teach wherein the formatted output is transmitted with embedded security metadata. However, Baskaran teaches wherein the formatted output is transmitted with embedded security metadata (Fig.5, ¶ 0017 - Metadata associated with one or more configurable functionalities is generated by invoking one or more adapters associated with the configurable functionalities. The electronic content, the user information, the usage policy, the encryption information, and the generated metadata are encapsulated and selectively encrypted in the predefined file structure of the proprietary wrapper file. The user action that triggers encapsulation of the electronic content – ¶ 0038 - After the user is authenticated, the wrapper file is decapsulated for granting controlled access to the electronic content encapsulated within the wrapper file. As used herein, "decapsulation" refers to the process of arriving at the raw electronic content and metadata after decryption and disassembly of the wrapper file. The proprietary wrapper file launches a pre-designated native application to grant access to the electronic content according to the content usage policy. The proprietary wrapper file restricts usage of the electronic content within the networked environment by determining whether security client application can contact the policy server when the user attempts to access the electronic content) It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Gerea to include the teachings of Baskaran. The motivation for doing so is to allow the system to restrict usage of the electronic content within the networked environment by determining whether security client application can contact the policy server when the user attempts to access the electronic content (Baskaran – ¶ 0038). Claim 16 is rejected under 35 U.S.C. 103 as being unpatentable over Gerea in view of Palanki further in view of Majmudar Regarding claim 16, Gerea further teaches wherein the means for generating a secured input comprises: means for generating a normalized input by processing the input to standardize the input when the input is in non-uniform formats into a consistent secure structure ( ¶ 0003 -adapters may provide data transformation and handling functionality for data flowing into and out of an event processing system. Because such input and output adapters are based on a common vendor-provided adapter framework, users may define conversion logic for the input and output adapters while relying on the vendor-provided framework to provide handling of different stream conditions -The adapters may further be configured to execute declarative queries or portions thereof ( e.g., for filtering purposes), thereby simplifying processing at a query engine coupled to the adapters – ¶ 0014 -first interface 106 and the second interface 118 are part of a communications stack that includes logic ( e.g., in the form of an input adapter and an output adapter, respectively) to convert event objects and result objects to and from an object format that is native to the computer system 100 – ¶ 0027 - a particular CEP event object indicating that the stock price for Microsoft Corp. is $20.33 at 9:30 am on Jan. 2, 2009 may be received from the source 202 (e.g., a stock price ticker feed), translated into a data format native to the CEP system 200, and inserted into the input queue 212.; and means for generating the secured input (¶ 0003 - The adapters may further be configured to execute declarative queries or portions thereof ( e.g., for filtering purposes), thereby simplifying processing at a query engine coupled to the adapters). However, Gerea does not explicitly teach augment the normalized input with security-validated additional context. wherein the additional context is security-validated by performing a security check on the additional context to detect and remove one or more of potential malware, phishing attempts, or other security threats prior to augmenting the normalized input Majmudar teaches augment the normalized input with security-validated additional context. wherein the additional context is security-validated by performing a security check on the additional context to detect and remove one or more of potential malware, phishing attempts, or other security threats prior to augmenting the normalized input (Col.8, lines 55-70 - the prompt data and/or context data associated with the prompt may be sent to a prompt validation component 148 (step 1). The prompt validation component 148 may validate the prompt data by determining whether data in the prompt violates one or more predefined rules , the prompt validation component 148 may use a predefined set of rules (e.g., allow lists, deny lists, etc.) to validate the prompt (step 2) – Col.9, lines 1-10 - the prompt validation component 148 may use a machine learning model trained to detect prompt instructions that violate privacy, security, and/or are associated with impermissible actions – Col.12, lines 25-30 - One example of an invalid action that may be detected by action validation component may be an LLM inference output and/or action plan that attempts to call an untrusted/ non-allow listed API that might inject a malicious prompt - Col. 11, lines 30-35 - since all actions and action results have been validated using the security threat mitigation component 160 – Col.3, lines 10-20 - An indirect prompt injection instruction may be an impermissible instruction to inject data ( e.g., a natural language directive or instruction) into a subsequent prompt that may then be used during LLM-processing). It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Gerea to include the teachings of Majmudar. The motivation for doing so is to allow the system to provide security threat mitigation for generative machine learning models (Majmudar – Abstract). Claim 17 are rejected under 35 U.S.C. 103 as being unpatentable over Gerea in view of Palanki further in view of Majmudar further in view of Reisman Regarding claim 17, Gerea does not explicitly teach wherein the means for generating a normalized input is operable to implement content safety screening to prevent inclusion of explicit, violent, or inappropriate material.. However, Reisman teaches wherein the means for generating a normalized input is operable to implement content safety screening to prevent inclusion of explicit, violent, or inappropriate material. (¶ 0383 - The link interceptor module, when configured to intercept all or selected external links or Get URL requests enables user activity to be screened so that undesired requests can be denied or filtered out. Such a screening process can be used to prevent users retrieving inappropriate content, for example content judged indecent or obscene, or from competitors Web sites, so long as an address, or URL, for that content is known. If the user attempts to get an URL on the excluded list, "Object Not Available" can be returned It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Gerea to include the teachings of Reisman. The motivation for doing so is to allow the system provide screening in order to prevent users from retrieving inappropriate content (Reisman – ¶ 0383). Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to YOUNES NAJI whose telephone number is (571)272-2659. The examiner can normally be reached Monday - Friday 8:30 AM -5:30 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Oscar A Louie can be reached at (571) 270-1684. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /YOUNES NAJI/Primary Examiner, Art Unit 2445
Read full office action

Prosecution Timeline

Nov 19, 2025
Application Filed
Jun 03, 2026
Non-Final Rejection mailed — §103
Jun 25, 2026
Interview Requested
Jul 29, 2026
Applicant Interview (Telephonic)
Aug 06, 2026
Response Filed
Aug 08, 2026
Examiner Interview Summary
Aug 28, 2026
Final Rejection mailed — §103
Sep 30, 2026
Interview Requested

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12732490
REDUCING BLUETOOTH CONNECTION LATENCY USING SELECTIVE GATT CACHE REQUESTS
3y 10m to grant Granted Sep 08, 2026
Patent 12706891
TUNNELLED REMOTE INTENT MECHANISM
3y 5m to grant Granted Aug 11, 2026
Patent 12665749
MIGRATING SECRETS FROM A CLOUD ENVIRONMENT TO A LOCAL SYSTEM
3y 3m to grant Granted Jun 23, 2026
Patent 12659322
Systems and methods for identifying legitimate network traffic imitation
2y 2m to grant Granted Jun 16, 2026
Patent 12647495
METHODS AND APPARATUS TO IDENTIFY MAIN PAGE VIEWS
1y 8m to grant Granted Jun 02, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
75%
Grant Probability
99%
With Interview (+73.4%)
2y 11m (~2y 0m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 455 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month