Prosecution Insights
Last updated: August 17, 2026
Application No. 19/416,321

MODELING PERMISSION RISK IN THE CLOUD

Final Rejection §103
Filed
Dec 11, 2025
Priority
Dec 12, 2024 — provisional 63/733,339 +1 more
Examiner
RAHIM, MONJUR
Art Unit
2436
Tech Center
2400 — Computer Networks
Assignee
Andromeda Security
OA Round
2 (Final)
84%
Grant Probability
Favorable
3-4
OA Rounds
2y 3m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 84% — above average
84%
Career Allowance Rate
756 granted / 895 resolved
+26.5% vs TC avg
Strong +16% interview lift
Without
With
+16.4%
Interview Lift
resolved cases with interview
Typical timeline
2y 11m
Avg Prosecution
40 currently pending
Career history
924
Total Applications
across all art units

Statute-Specific Performance

§101
15.1%
-24.9% vs TC avg
§103
57.4%
+17.4% vs TC avg
§102
7.2%
-32.8% vs TC avg
§112
4.5%
-35.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 895 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION 1. This action is in response to the amendment and argument field on 2 June 2026. 2. Claims 1, 16 and 20 have been amended. 3. Claims 1-20 remain Pending and Rejected. Responses to the Argument 4. The applicant’s arguments filed on 2 June 2026 are moot in view of new ground of rejection rendered. Claim Rejections - 35 USC § 103 5. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-20 are rejected under 35 U.S.C §103 as being unpatentable over Sapir et al. (US Publication No. 20250126145), hereinafter Sapir and in view of Applegate-Swanson (US Publication No. 20210281610), hereinafter Applegate-Swanson. Regarding claim 1: determining a plurality of permissions associated with a user (Sapir, abstract), wherein IHS to: obtain a plurality of resource risk weights of a respective plurality of resources, and a plurality of access permissions of a user for the respective plurality of resources and generate based, at least in part, on the plurality of resource risk weights and the plurality of access permissions of the user. determining a corresponding risk associated with each of the plurality of permissions (Sapir, ¶9-10, FIG.2), wherein, IHS to: determine a plurality of access risks for the user with respect to the respective plurality of resources; and generate the risk score for the user based, at least in part, on the mean or median of the plurality of access risks for the user. determining an aggregate risk associated with the plurality of permissions associated with the user as a whole to generate an identity risk based on the determined corresponding risk associated with each of the plurality of permissions (Sapir, ¶12, ¶71), wherein generating the risk score for the user further includes: generating based, at least in part, on the plurality of access permissions of the user, a plurality of permission factors, where an individual permission factor includes an integer number representing a type of access permission of the user for a respective resource of the plurality of resources; determining a plurality of access risks for the user with respect to the respective plurality of resources, where an individual access risk of the plurality of access risks is determined by multiplying a resource risk weight determining which of the plurality of permissions are used by the user to generate a determined use (Sapir, ¶62), wherein RBAC is designed to simplify access control administration, improve security, and support least privilege principles. For RBAC, users are typically assigned permissions based on their role or job function within an organization. These permissions determine what actions a user can take within the system, such as reading, writing, or executing certain files. Sapir explicitly suggest, and configuring one or more roles for the user based on the identity risk generated based on the determined corresponding risk associated with each of the plurality of permissions associated with the user and the determined use; however, in a same field of endeavor Applegate-Swanson discloses this limitation (Applegate-Swanson, ¶53, ¶56, ¶68-72), updating the plurality of permissions associated with the user based on the one or more roles configured for the user; and storing the one or more roles configured for the user in a memory (Sapir, ¶88) It would have been obvious to one of ordinary skill in the art at the time the invention was filed to include the method of role-based identity risk determination of Sapir with the combining risk score generation disclosed in Applegate-Swanson to improve security by modifying existing policies, stated by Applegate-Swanson at ¶9. Regarding claim 2: wherein determining the plurality of permissions associated with user includes identifying the one or more roles associated with user (Sapir, ¶62). Regarding claim 3: wherein determining the corresponding risk associated with each of the plurality of permissions includes determining a corresponding blast impact (Sapir, ¶10). Regarding claim 4: wherein determining the corresponding blast impact includes evaluating a set of attributes associated with a permission of the plurality of permissions (Sapir, ¶65). Regarding claim 5: wherein the set of attributes includes a type of access granted by the permission, a sensitive of the data or resources accessible through the permission, a potential for privilege escalation, and/or a breadth of resource exposure associated with the permission (Sapir, ¶74-75). Regarding claim 6: wherein determining a corresponding risk associated with each of the plurality of permissions includes determining a corresponding scope of access for each of the plurality of permissions (Sapir, ¶12). Regarding claim 7: wherein the determined corresponding risk associated with each of the plurality of permissions is a contextualized permission risk (Sapir, ¶78). Regarding claim 8: wherein the contextualized permission risk is a value that is normalized with respect to a scale (Sapir, ¶90). Regarding claim 9: wherein configuring the one or more roles for the user includes applying a least standing privilege (Sapir, ¶78, ¶62). Regarding claim 10: wherein configuring the one or more roles for the user includes configuring at least one permission associated with the one or more roles for just-in-time access (Sapir, ¶66). Regarding claim 11: further comprising aggregating corresponding identity risk scores associated with a plurality of users into an account-level risk (Sapir, ¶64). Regarding claim 12: further comprising, for a plurality of accounts, aggregating corresponding account-level risk into a provider risk (Sapir, ¶77, ¶91). Regarding claim 13: further comprising, for a plurality of providers, aggregating corresponding provider risk into a tenant risk (Sapir, ¶83). Regarding claim 14: further comprising generating outputs for prioritization and remediation based on one or more of the identity risk, the account-level risk, the provider risk, and/or the tenant risk (Sapir, ¶67). Regarding claim 15: Sapir does not explicitly suggest, wherein determining the aggregate risk associated with the plurality of permissions includes: deduplicating permission that are accessible to the user through multiple roles within a same scope such that a duplicate permission does not increase the aggregate risk; and treating permissions available across different scopes as separate contributions to the aggregate risk; however, in a same field of endeavor Applegate-Swanson teaches this limitation (Applegate-Swanson, ¶67-68). Same motivation for combining the respective features of Sapir and Applegate-Swanson applies herein, as discussed in the rejection of claim 1. Regarding claim 16: determine a plurality of permissions associated with a user (Sapir, abstract), wherein IHS to: obtain a plurality of resource risk weights of a respective plurality of resources, and a plurality of access permissions of a user for the respective plurality of resources and generate based, at least in part, on the plurality of resource risk weights and the plurality of access permissions of the user. determine a corresponding risk associated with each of the plurality of permissions (Sapir, ¶9-10, FIG.2), wherein, IHS to: determine a plurality of access risks for the user with respect to the respective plurality of resources; and generate the risk score for the user based, at least in part, on the mean or median of the plurality of access risks for the user. determine an aggregate risk associated with the plurality of permissions associated with the user as a whole to generate an identity risk based on the determined corresponding risk associated with each of the plurality of permissions (Sapir, ¶12, ¶71), wherein generating the risk score for the user further includes: generating based, at least in part, on the plurality of access permissions of the user, a plurality of permission factors, where an individual permission factor includes an integer number representing a type of access permission of the user for a respective resource of the plurality of resources; determining a plurality of access risks for the user with respect to the respective plurality of resources, where an individual access risk of the plurality of access risks is determined by multiplying a resource risk weight determining which of the plurality of permissions are used by the user to generate a determined use (Sapir, ¶62), wherein RBAC is designed to simplify access control administration, improve security, and support least privilege principles. For RBAC, users are typically assigned permissions based on their role or job function within an organization. These permissions determine what actions a user can take within the system, such as reading, writing, or executing certain files. Sapir explicitly suggest, and configuring one or more roles for the user based on the identity risk generated based on the determined corresponding risk associated with each of the plurality of permissions associated with the user and the determined use; however, in a same field of endeavor Applegate-Swanson discloses this limitation (Applegate-Swanson, ¶53, ¶56, ¶68-72), updating the plurality of permissions associated with the user based on the one or more roles configured for the user; and storing the one or more roles configured for the user in a memory (Sapir, ¶88). and a memory coupled to the processor and configured to provide the processor with instructions (Sapir, ¶6). It would have been obvious to one of ordinary skill in the art at the time the invention was filed to include the method of role-based identity risk determination of Sapir with the combining risk score generation disclosed in Applegate-Swanson to improve security by modifying existing policies, stated by Applegate-Swanson at ¶9. Regarding claim 17: wherein to determine the plurality of permissions associated with user, the processor is further configured to identify the one or more roles associated with user (Sapir, ¶62). Regarding claim 18: wherein to determine the corresponding risk associated with each of the plurality of permissions, the processor is further configured to determine a corresponding blast impact (Sapir, ¶10). Regarding claim 19: wherein to determine the corresponding blast impact, the processor is further configured to evaluate a set of attributes associated with a permission of the plurality of permissions (Sapir, ¶65). Regarding claim 20: determining a plurality of permissions associated with a user (Sapir, abstract), wherein IHS to: obtain a plurality of resource risk weights of a respective plurality of resources, and a plurality of access permissions of a user for the respective plurality of resources and generate based, at least in part, on the plurality of resource risk weights and the plurality of access permissions of the user. determining a corresponding risk associated with each of the plurality of permissions (Sapir, ¶9-10, FIG.2), wherein, IHS to: determine a plurality of access risks for the user with respect to the respective plurality of resources; and generate the risk score for the user based, at least in part, on the mean or median of the plurality of access risks for the user. determining an aggregate risk associated with the plurality of permissions associated with the user as a whole to generate an identity risk based on the determined corresponding risk associated with each of the plurality of permissions (Sapir, ¶12, ¶71), wherein generating the risk score for the user further includes: generating based, at least in part, on the plurality of access permissions of the user, a plurality of permission factors, where an individual permission factor includes an integer number representing a type of access permission of the user for a respective resource of the plurality of resources; determining a plurality of access risks for the user with respect to the respective plurality of resources, where an individual access risk of the plurality of access risks is determined by multiplying a resource risk weight determining which of the plurality of permissions are used by the user to generate a determined use (Sapir, ¶62), wherein RBAC is designed to simplify access control administration, improve security, and support least privilege principles. For RBAC, users are typically assigned permissions based on their role or job function within an organization. These permissions determine what actions a user can take within the system, such as reading, writing, or executing certain files. Sapir explicitly suggest, and configuring one or more roles for the user based on the identity risk generated based on the determined corresponding risk associated with each of the plurality of permissions associated with the user and the determined use; however, in a same field of endeavor Applegate-Swanson discloses this limitation (Applegate-Swanson, ¶53, ¶56, ¶68-72), updating the plurality of permissions associated with the user based on the one or more roles configured for the user; and storing the one or more roles configured for the user in a memory (Sapir, ¶88) It would have been obvious to one of ordinary skill in the art at the time the invention was filed to include the method of role-based identity risk determination of Sapir with the combining risk score generation disclosed in Applegate-Swanson to improve security by modifying existing policies, stated by Applegate-Swanson at ¶9. Conclusion 6. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action. The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure (See form “PTO-892 Notice of reference cited). Any inquiry concerning this communication or earlier communications from the examiner should be directed to MONJUR RAHIM whose telephone number is (571)270-3890. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Shewye Gelagay can be reached on 571-272-4219. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /Monjur Rahim/ Patent Examiner United States Patent and Trademark Office Art Unit: 2436; Phone: 571.270.3890 E-mail: monjur.rahim@uspto.gov Fax: 571.270.4890
Read full office action

Prosecution Timeline

Dec 11, 2025
Application Filed
Mar 06, 2026
Non-Final Rejection mailed — §103
Apr 27, 2026
Interview Requested
May 14, 2026
Applicant Interview (Telephonic)
May 14, 2026
Examiner Interview Summary
Jun 02, 2026
Response Filed
Jun 29, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12694108
Deception-Based Responses to Security Attacks
2y 9m to grant Granted Jul 28, 2026
Patent 12676845
METHOD AND SYSTEM FOR AUTHENTICATING A USER TO ACCESS A WEB APPLICATION HOSTED ON AN APPLICATION SERVER
1y 10m to grant Granted Jul 07, 2026
Patent 12657337
SYSTEMS AND METHODS FOR RUNTIME CONTENT MASKING
2y 2m to grant Granted Jun 16, 2026
Patent 12659140
ENCRYPTED INFORMATION RETRIEVAL
1y 11m to grant Granted Jun 16, 2026
Patent 12652300
PROBABILISTIC EVIDENCE BASED INSIDER THREAT DETECTION AND REASONING
3y 6m to grant Granted Jun 09, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
84%
Grant Probability
99%
With Interview (+16.4%)
2y 11m (~2y 3m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 895 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month