Remarks
Claims 1, 3, 8, 10, 11, and 17-20 are pending.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
Applicant's arguments filed 6/6/2025 have been fully considered but they are not persuasive.
Applicant appears to discuss the instant application on page 8 and the first paragraph on page 9. Applicant then provides a brief explanation of Applicant’s understanding of Brown, notes that the rejection cites Brown for subject matter in the claims, and provides a modified version of the statement found on page 13 of the office action dated 8/28/2024 regarding what Brown does not explicitly disclose.
At no point does Applicant provide any argument against what Brown is cited as disclosing.
Applicant then alleges “The Examiner cites Peterson [sic] as disclosing appending information to log data. In this regards, Peterson discloses that certain fields of a log may be correlated to related information, such as location information or associated information concerning and identified machine. Fields concerning the correlated information may be added to the log message to provide an enriched log message. However, Peterson does not disclose generating identity profiles for a person or people, detecting that a log message includes an object of a first data type that distinguishes between unique identities, identifying a first identity profile, and enriching the log message data by appending a first key associated with the first identity profile thereby enabling identification of a larger range of log message data for analysis.” However, most of the limitations being argued here were rejected using Brown, and not argued by Applicant. For example, Brown discloses the following:
Regarding Claim 1,
Brown discloses …
Generating, for each unique identity of the first plurality of unique identities, an identity profile with individual ones of the respective obtained objects of the first and second object classifications corresponding to each unique identity, wherein a first plurality of identity profiles are generated for the organization from the first objects of the first IAM platform (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38, 46, 47, 49-53, 56-61, and associated figures; generating a profile, which could be explicitly called a profile, or some other data, such as any data/information stored regarding a certain identity, including relationships/associations between entities, for example);
…
Detecting that at least one of the log objects present in the received first log message data is of the first object type (Exemplary Citations: for example, Abstract, Paragraphs 5, 12-16, 18, 20, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; each profile is associated with keys, such as any of the data/information that is stored therein or could be stored therein, and historical, transaction, account, etc. data that may be added to with any of the data/information, accessing of the profiles described above, transmitting of fraud related messaging, including fraud warning, no fraud warnings, etc., as examples. For example, objects related to a secondary ID, objects related to a primary ID, objects related to a certain transaction, fraud related messages, etc., as examples);
Identifying at least a first identity profile of the first plurality of identity profiles in which the at least one of the objects of the first object type is located (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; each profile is associated with keys, such as any of the data/information that is stored therein or could be stored therein, and historical, transaction, account, etc. data that may be added to with any of the data/information, accessing of the profiles described above, transmitting of fraud related messaging, including fraud warning, no fraud warnings, etc., as examples. For example, profile as described above including objects as described above);
Enriching the received first log message data with a first respective key associated with the first identity profile by adding the first respective key to the received first log message data, wherein the first identity profile includes a first respective obtained object of the second classification (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; each profile is associated with keys, such as any of the data/information that is stored therein or could be stored therein, and historical, transaction, account, etc. data that may be added to with any of the data/information, accessing of the profiles described above, transmitting of fraud related messaging, including fraud warning, no fraud warnings, etc., as examples. For example, adding key, as described above, to the first log message data, described above); and
…
Therefore, Brown discloses the majority of what Applicant is arguing and no argument has been provided against Brown. In response to applicant's arguments against the references individually, one cannot show nonobviousness by attacking references individually where the rejections are based on combinations of references. See In re Keller, 642 F.2d 413, 208 USPQ 871 (CCPA 1981); In re Merck & Co., 800 F.2d 1091, 231 USPQ 375 (Fed. Cir. 1986).
With respect to Petersen, Applicant fails to provide any reasons as to why Applicant believes Petersen fails to disclose the limitations being argued. Instead, Applicant appears to have only a general allegation here. Applicant's arguments fail to comply with 37 CFR 1.111(b) because they amount to a general allegation that the claims define a patentable invention without specifically pointing out how the language of the claims patentably distinguishes them from the references. Petersen discloses the following:
Petersen, however, discloses that adding comprises appending, the first respective key thereby enabling identification of the first identity profile including the first respective obtained object and enabling identifications of a larger range of log message data for analysis, wherein the first respective obtained object is not associated with the first log message data prior to enriching the received first log message data (For example, Exemplary Citations: for example, Paragraphs 12, 13, 225, 241-250, and associated figures; enriching logs by appending data to the logs, where the appended data will be used in the operating step (thus making the operating step data base larger than before), for example);
Enriching the received first log message data with a first respective key associated with the first identity profile by appending the first respective key to the received first log message data, wherein the first identity profile includes a first respective obtained object of the second classification, the first respective key thereby enabling identification of the first identity profile including the first respective obtained object and enabling identifications of a larger range of log message data for analysis, wherein the first respective obtained object is not associated with the first log message data prior to enriching the received first log message, wherein different respective keys are distinct from data of the first plurality of identity profiles (For example, Exemplary Citations: for example, Paragraphs 12, 13, 225, 241-250, and associated figures; enriching logs by appending data to the logs/messages, where the appended data will be used in the operating step (thus making the operating step data base larger than before), for example. The appended information is distinct from profile data).
Therefore, Petersen certainly discloses the portion of what Applicant is arguing in a general allegation that Petersen is cited as disclosing.
Claim Interpretation
Applicant explicitly disclaims all claim interpretations that are not performed by a physical computer machine in pages 10-12 of the response dated 11/14/2022.
The claims include subject matter that does not affect claim scope, such as anywhere “enabling” or similar language is used. This is intended use and does not need to be performed.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 3, 8, 10, 11, and 17-20 are rejected under 35 U.S.C. 103 as being unpatentable over Brown (U.S. Patent Application Publication 2020/0145436) in view of Petersen (U.S. Patent Application Publication 2012/0246303).
Regarding Claim 1,
Brown discloses a computer implemented method performed by one or more processors in a data network monitoring system, the data network monitoring system monitoring one or more data platforms of one or more data systems, comprising:
(Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, 62-69, and associated figures; this is the system of Brown that implements Brown’s invention, perhaps as a fraud detection computing system, portion thereof, or the like, as examples);
Obtaining, from a first database of a first IAM platform, first objects of at least a first object classification of a plurality of object classifications, wherein the first database has a first plurality of unique identities of an organization and a first plurality of objects, each one of the unique identities of the first plurality of unique identities comprising one of a person and a group of people, wherein one or more objects of the first plurality of objects is associated with each of the unique identities of the first plurality of unique identities, wherein the first plurality of objects corresponds to respective ones of the plurality of object classifications (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 46, 47, 49-53, 56-61, and associated figures; objects from various entities including databases, each associated with an identity (e.g., an account, user, identity, or the like), classified in any of many classifications (e.g., synthetic, primary, secondary, fraud facilitating, associated, presence of transactions, absence of transactions, flagged, credit, financial, account, contributor, ID, client, sensitive data, transaction, data from certain entity, legal name, company name, social insurance number, credit card number, date, email address, and many other classifications), for example);
Obtaining, from the first IAM platform, second objects of at least a second object classification of the plurality of object classifications, the first and second object classifications being different (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 46, 47, 49-53, 56-61, and associated figures; get objects of a second of the above, for example);
Generating, for each unique identity of the first plurality of unique identities, an identity profile with individual ones of the respective obtained objects of the first and second object classifications corresponding to each unique identity, wherein a first plurality of identity profiles are generated for the organization from the first objects of the first IAM platform (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38, 46, 47, 49-53, 56-61, and associated figures; generating a profile, which could be explicitly called a profile, or some other data, such as any data/information stored regarding a certain identity, including relationships/associations between entities, for example);
Assigning, based upon a respective object classification corresponding to each object, an object type of a plurality of object types to each object in each of the first plurality of identity profiles, wherein the plurality of object types comprises a first object type and a different second object type, wherein objects of the first object type distinguish between the unique identities of the first plurality of unique identities (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 29, 30, 33-36, 38, 46, 47, 49-53, 56-61, and associated figures; assigning an object type, such as one of the ones described above, for example);
Storing the first plurality of identity profiles in a second database (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38, 46, 47, 49-53, 56-61, and associated figures; storing the above described profiles, for example);
Associating each identity profile of the first plurality of identity profiles with a different respective key such that each of the different respective keys distinguishes an associated identity profile from all other identity profiles of the first plurality of identity profiles, wherein different respective keys are distinct from data of the first plurality of identity profiles (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; each profile is associated with keys, such as any of the data/information that is stored therein or could be stored therein, and historical, transaction, account, etc. data that may be added to with any of the data/information, accessing of the profiles described above, transmitting of fraud related messaging, including fraud warning, no fraud warnings, etc., as examples. Each of these keys noted above are distinct from other data in this profile as well as distinct from all data in all other profiles);
Receiving first log message data, the first log message data including log objects including a first log object corresponding to the first object classification and being free of any log object corresponding to the second object classification (Exemplary Citations: for example, Abstract, Paragraphs 5, 12-16, 18, 20, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; each profile is associated with keys, such as any of the data/information that is stored therein or could be stored therein, and historical, transaction, account, etc. data that may be added to with any of the data/information, accessing of the profiles described above, transmitting of fraud related messaging, including fraud warning, no fraud warnings, etc., as examples. For example, receiving any data, such as transaction data, account data, ID data, or any other data used in the below detection);
Detecting that at least one of the log objects present in the received first log message data is of the first object type (Exemplary Citations: for example, Abstract, Paragraphs 5, 12-16, 18, 20, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; each profile is associated with keys, such as any of the data/information that is stored therein or could be stored therein, and historical, transaction, account, etc. data that may be added to with any of the data/information, accessing of the profiles described above, transmitting of fraud related messaging, including fraud warning, no fraud warnings, etc., as examples. For example, objects related to a secondary ID, objects related to a primary ID, objects related to a certain transaction, fraud related messages, etc., as examples);
Identifying at least a first identity profile of the first plurality of identity profiles in which the at least one of the objects of the first object type is located (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; each profile is associated with keys, such as any of the data/information that is stored therein or could be stored therein, and historical, transaction, account, etc. data that may be added to with any of the data/information, accessing of the profiles described above, transmitting of fraud related messaging, including fraud warning, no fraud warnings, etc., as examples. For example, profile as described above including objects as described above);
Enriching the received first log message data with a first respective key associated with the first identity profile by adding the first respective key to the received first log message data, wherein the first identity profile includes a first respective obtained object of the second classification (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; each profile is associated with keys, such as any of the data/information that is stored therein or could be stored therein, and historical, transaction, account, etc. data that may be added to with any of the data/information, accessing of the profiles described above, transmitting of fraud related messaging, including fraud warning, no fraud warnings, etc., as examples. For example, adding key, as described above, to the first log message data, described above); and
Using the enriched first log message data to monitor the one or more data systems and generate monitoring information based at least in part on the first identity profile (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; detecting fraud or the like with the above, for example);
But does not appear to explicitly disclose that adding comprises appending, the first respective key thereby enabling identification of the first identity profile including the first respective obtained object and enabling identifications of a larger range of log message data for analysis, wherein the first respective obtained object is not associated with the first log message data prior to enriching the received first log message data.
Petersen, however, discloses that adding comprises appending, the first respective key thereby enabling identification of the first identity profile including the first respective obtained object and enabling identifications of a larger range of log message data for analysis, wherein the first respective obtained object is not associated with the first log message data prior to enriching the received first log message data (For example, Exemplary Citations: for example, Paragraphs 12, 13, 225, 241-250, and associated figures; enriching logs by appending data to the logs, where the appended data will be used in the operating step (thus making the operating step data base larger than before), for example);
Enriching the received first log message data with a first respective key associated with the first identity profile by appending the first respective key to the received first log message data, wherein the first identity profile includes a first respective obtained object of the second classification, the first respective key thereby enabling identification of the first identity profile including the first respective obtained object and enabling identifications of a larger range of log message data for analysis, wherein the first respective obtained object is not associated with the first log message data prior to enriching the received first log message, wherein different respective keys are distinct from data of the first plurality of identity profiles (For example, Exemplary Citations: for example, Paragraphs 12, 13, 225, 241-250, and associated figures; enriching logs by appending data to the logs/messages, where the appended data will be used in the operating step (thus making the operating step data base larger than before), for example. The appended information is distinct from profile data). It would have been obvious to one of ordinary skill in the art at the time of applicant’s invention, which is before any effective filing date of the claimed invention, to incorporate the log collection, structuring, and processing techniques of Petersen into the synthetic online entity detection system of Brown in order to allow the system to deal with additional kinds of logs, to allow for processing of additional forms of data, to provide for usage of well-known identifiers, to detect additional forms of normal/abnormal data, and/or to increase security in the system.
Regarding Claim 3,
Brown as modified by Petersen discloses the method of claim 1, in addition, Brown discloses that each identity profile includes at least one first data structure defined by (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures):
At least one object of the at least first object type (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; the object above, for example);
At least one object classification of the at least one object of the first object type (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; the classification above, for example); and
The at least first object type (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; the type above, for example);
Wherein each identity profile includes at least one second data structure defined by (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures):
At least one object of at least a second object type (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; the object above, for example);
The at least one object classification of the at least one object of the at least the second object type (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; the classification above, for example); and
The at least the second object type (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; the type above, for example); and
Wherein each object comprises a value, wherein each corresponding object classification describes the value, and wherein each corresponding object type describes the at least one object classification (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures).
Regarding Claim 8,
Brown as modified by Petersen discloses the method of claim 1, in addition, Brown discloses accessing a second IAM platform that includes a third database having a second plurality of unique identities of the organization and a second plurality of objects associated with each unique identity of the second plurality of unique identities (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; another source, for example);
Ascertaining that at least one of the unique identities of the second plurality of unique identities corresponds to at least one of the unique identities of the first plurality of unique identities (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; associating identities from multiple sources, for example);
Obtaining, from the second IAM platform, objects of the second plurality of objects for the at least one of the unique identities of the second plurality of unique identities (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; as above, for example); and
Updating at least one identity profile of the first plurality of identity profiles with the objects of the second plurality of objects (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; adding information to profiles above, for example).
Regarding Claim 10,
Brown as modified by Petersen discloses the method of claim 1, in addition, Brown discloses accessing a second IAM platform that includes a third database having a second plurality of unique identities of the organization and a second plurality of objects associated with each unique identity of the second plurality of unique identities (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; as above, for another source, for example);
Obtaining, from the second IAM platform, first objects of the first classification for the second plurality of unique identities (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; as above, for another source, for example);
Obtaining, from the second IAM platform, second objects of the second object classification for the second plurality of unique identities (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; as above, for another source, for example);
Assigning, based upon a respective object classification corresponding to each object of the second plurality of objects, an object type to each object of the second plurality of objects (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; as above, for another source, for example);
Generating, for each unique identity of the second plurality of unique identities, an identity profile with respective obtained objects of at least the first and second object classifications corresponding to each unique identity of the second plurality of unique identities, wherein a second plurality of identity profiles are generated for the organization from the second objects of the second IAM platform (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; as above, for another source, for example);
Storing the second plurality of identity profiles in a fourth database (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; as above, for another source, for example); and
Associating each identity profile of the second plurality of identity profiles with a different respective key (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; as above, for another source, for example).
Regarding Claim 11,
Brown as modified by Petersen discloses the method of claim 10, in addition, Brown discloses ascertaining that at least one unique identity of the second plurality of unique identities corresponds to at least one unique identity of the first plurality of unique identities (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; associating data with respect to multiple entities that are primary/secondary and associated with each other, for example); and
Merging, based on the ascertaining, at least one identity profile of the second plurality of identity profiles with at least one identity profile of the first plurality of identity profiles (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; associating data with respect to multiple entities that are primary/secondary and associated with each other, for example);
Wherein the merging includes (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; associating data with respect to multiple entities that are primary/secondary and associated with each other, for example):
Identifying objects in the at least one identity profile of the second plurality of identity profiles not present in the at least one identity profile of the first plurality of identity profiles (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; associating data with respect to multiple entities that are primary/secondary and associated with each other, for example); and
Updating the at least one identity profile of the first plurality of identity profiles with the identified objects of the at least one identity profile of the second plurality of identity profiles (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; associating data with respect to multiple entities that are primary/secondary and associated with each other, for example).
Regarding Claim 17,
Brown as modified by Petersen discloses the method of claim 1, in addition, Brown discloses processing the enriched first log message data with at least one processing rule using the respective key (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; use of rules with the data described above, for example).
Regarding Claim 18,
Brown as modified by Petersen discloses the method of claim 17, in addition, Brown discloses receiving second log message data (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures);
Detecting that at least one other object of the objects of the first object type is present in the received second log message data (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures);
Identifying the first identity profile as including the at least one other object of the objects of the first object type (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures); and
Enriching the received second log message data with the respective key associated with the first identity profile, wherein using the respective key comprises processing the enriched first and second log message data based on the respective key (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures).
Regarding Claim 19,
Brown as modified by Petersen discloses the method of claim 17, in addition, Brown discloses that using the respective key comprises (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures):
Accessing the first identity profile (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures);
Referencing at least one other object of the first object type with a first log message data processing rule (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures); and
Triggering the first log message data processing rule based on the at least one other object of the first object type (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures).
Regarding Claim 20,
Brown as modified by Petersen discloses the method of claim 1, in addition, Brown discloses determining that the first log message data is indicative of a successful authentication onto a network of the organization from a networked device (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; requiring and receiving authentication from a consumer computing system, for example);
Recording the networked device and the respective key of the identified at least one of the identity profiles in an inference database (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; all transaction/account/historical data in the system is recorded, for example);
Receiving second log message data (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; as above, for example);
Detecting that the networked device is present in the received second log message data (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; consumer computing system is in the data, for example);
Identifying the networked device in the inference database (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; finding the consumer computing system, for example); and
Enriching the received second log message data with the respective key based on the respective key being associated with the networked device in the inference database (Exemplary Citations: for example, Abstract, Paragraphs 12-16, 18, 20, 23-25, 29, 30, 33-36, 38-43, 46, 47, 49-53, 56-61, and associated figures; as above, for example); and
Petersen discloses that the networked device is identified with an IP address (Exemplary Citations: for example, Paragraphs 27, 83, 99, 102, 103, 118, 120, 126-128, 132, 135-137, 145, 149, 151, 158, 161, 170, 213, 219, 242, 243, 249, 250, 254, etc., and associated figures, as examples; IP address used in logs, enriched data, etc., for example);
Determining that the first log message data is indicative of a successful authentication onto a network of the organization from an IP address (Exemplary Citations: for example, Paragraphs 12, 13, 27, 83, 99, 102, 103, 118, 120, 126-128, 132, 135-137, 145, 149, 151, 158, 161, 170, 213, 219, 225, 241-250, 254, etc., and associated figures);
Recording the IP address and the respective key of the identified at least one of the identity profiles in an inference database (Exemplary Citations: for example, Paragraphs 12, 13, 27, 83, 99, 102, 103, 118, 120, 126-128, 132, 135-137, 145, 149, 151, 158, 161, 170, 213, 219, 225, 241-250, 254, etc., and associated figures);
Receiving second log message data (Exemplary Citations: for example, Paragraphs 12, 13, 27, 83, 99, 102, 103, 118, 120, 126-128, 132, 135-137, 145, 149, 151, 158, 161, 170, 213, 219, 225, 241-250, 254, etc., and associated figures);
Detecting that the IP address is present in the received second log message data (Exemplary Citations: for example, Paragraphs 12, 13, 27, 83, 99, 102, 103, 118, 120, 126-128, 132, 135-137, 145, 149, 151, 158, 161, 170, 213, 219, 225, 241-250, 254, etc., and associated figures);
Identifying the IP address in the inference database (Exemplary Citations: for example, Paragraphs 12, 13, 27, 83, 99, 102, 103, 118, 120, 126-128, 132, 135-137, 145, 149, 151, 158, 161, 170, 213, 219, 225, 241-250, 254, etc., and associated figures); and
Enriching the received second log message data with the respective key based on the respective key being associated with the IP address in the inference database (Exemplary Citations: for example, Paragraphs 12, 13, 27, 83, 99, 102, 103, 118, 120, 126-128, 132, 135-137, 145, 149, 151, 158, 161, 170, 213, 219, 225, 241-250, 254, etc., and associated figures).
Conclusion
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Jeffrey D Popham whose telephone number is (571)272-7215. The examiner can normally be reached Monday through Friday 9:00-5:30.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey Nickerson can be reached at (469) 295-9235. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/Jeffrey D. Popham/Primary Examiner, Art Unit 2432