Prosecution Insights
Last updated: October 04, 2026
Application No. 17/426,617

SYSTEM, METHOD AND COMPUTER READABLE MEDIUM FOR PERFORMING A TRANSACTION IN RELATION TO AN IDENTITY CENTRIC DATASET

Final Rejection §103§112
Filed
Jul 28, 2021
Priority
Feb 01, 2019 — AU 2019900309 +3 more
Examiner
FARROW, FELICIA
Art Unit
2437
Tech Center
2400 — Computer Networks
Assignee
Tgrid Technologies Pty Ltd.
OA Round
6 (Final)
59%
Grant Probability
Moderate
7-8
OA Rounds
0m
Est. Remaining
94%
With Interview

Examiner Intelligence

Grants 59% of resolved cases
59%
Career Allowance Rate
160 granted / 273 resolved
+0.6% vs TC avg
Strong +36% interview lift
Without
With
+35.6%
Interview Lift
resolved cases with interview
Typical timeline
2y 11m
Avg Prosecution
34 currently pending
Career history
308
Total Applications
across all art units

Statute-Specific Performance

§101
7.5%
-32.5% vs TC avg
§103
61.0%
+21.0% vs TC avg
§102
7.8%
-32.2% vs TC avg
§112
18.6%
-21.4% vs TC avg
Black line = Tech Center average estimate • Based on career data from 273 resolved cases

Office Action

§103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Amendment The amendment filed 20 July 2026 has been entered. Applicant amended claims 1, 4-6, 10, 14, 18-19, 23; cancelled claims 3, 9, 13, 16, 22, and 26-54. Accordingly, claims 1, 2, 4-8, 10-12, 14-15, 17-21, 23-25 remain pending. Applicant’s amendment to the abstract overcomes the abstract objection of 20 January 2026. Therefore, the abstract objection of 20 January 2026 is withdrawn. Applicant’s amendment to the drawing overcomes the drawing objections of 20 January 2026. Therefore, the drawing objection of 20 January 2026 is withdrawn. Applicant’s amendment to the drawing overcomes the 35 USC 101 rejection of 20 January 2026. Therefore, the 35 USC 101 rejection of 20 January 2026 is withdrawn. Response to Arguments Abstract and Drawing objections: Applicant’s remarks, filed 20 July 2026, with respect to abstract and drawing objections of 20 January 2026 have been fully considered and are persuasive. The abstract and drawing objections of 20 January 2026 have been withdrawn. 35 USC 112(a) rejection: Applicant’s remarks, filed 20 July 2026, with respect to the 35 USC 112(a) rejection of 20 January 2026 have been fully considered and are persuasive. The 35 USC 112(a) rejection of 20 January 2026 has been withdrawn. 35 USC 112(b) rejection: Applicant’s remarks, filed 20 July 2026, with respect to the 35 USC 112(b) rejection of 20 January 2026 have been fully considered and are persuasive. The 35 USC 112(b) rejection of 20 January 2026 has been withdrawn. 35 USC 101 rejection: Applicant’s remarks, filed 20 July 2026, with respect to the 35 USC 101 rejection of 20 January 2026 have been fully considered and are persuasive. The 35 USC 101 rejection of 20 January 2026 has been withdrawn. 35 USC 103 Rejection: Applicant’s remarks on pages 22-23, filed 20 July 2026, has been fully considered, but they are not persuasive. Applicant’s remarks 1: Bohrer fails to teach or suggest: "performing the transaction by executing, in a trusted execution environment of the service network, one or more data operations from the set of permitted data operations...as permitted by the identified privacy schema thereby generating a manipulated dataset and transaction metadata" Examiner’s remarks: The examiner maintains that the generality of the claim limitations do not prevent the teachings of the prior art of record. Therefore, Bohrer in view of Shadmon teaches the limitations as presented in the office action below. A TEE is not a physical processor by itself, it is a secure isolated area inside a main processor. Therefore, it is unclear how the TEE comprises a privacy and consent broker processor because a TEE is not a physical processor by itself it is a secure isolated area inside a main processor. It is unclear whether to interpret the privacy and consent broker processor as a main processor or the TEE is merely a trusted environment, see 35 USC 112b rejection. Bohrer teaches utilizing trusted agents/ third parties for processing requests/transactions, these trusted agents/third parties which can be a trusted environment. Applicant’s arguments filed 20 July 2026 with respect to the amended limitations pertaining to “the consortium network …each of the plurality of system nodes includes a processing unit with a TEE…the TEE has a privacy and consent broker that comprises a privacy and consent broker API, a privacy and consent broker processor, a plurality of privacy schemas, and performing the transaction by executing, in the privacy and consent broker processor of the TEE…, one or more data operations” that are presented in the independent claims claim(s) have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. Applicant’s remarks: Shadmon does not disclose or suggest utilizing a TEE-bound security and consent broker running smart contracts to perform identity data tokenization or data anonymization on an active dataset prior to committing metadata to an untrusted ledger. Instead, Shadmon uses the term token to define cryptographic unit value or digital asset-essentially a utility coin used to pay for decentralized storage hosting or to verify resource allocation access a network block. Examiner’s remarks: Claim 1 states the processor in the TEE performs one or more data operations. Data operations can encompass a wide range of concepts/areas. Shadmon teaches the concepts of processing data operation in the TEE. TEE is a hardware enforced isolated area within a main processor that provides confidentiality/secure area within a main processor. Therefore, Shadmon utilizes a processor which can be privacy and consent broker processor. A TEE is not a physical processor by itself, it is a secure isolated area inside the main processor. Therefore, the examiner has interpreted the privacy and consent broker as merely a main processor and the TEE as a trusted environment since a TEE cannot be a processor by itself. The current office action has been updated to include additional references for the limitations which Bohrer in view of Shadmon are deficient. Applicant’s remarks: Bohrer and Shadmon use incompatible architectural layers, specifically, Bohrer describes a high-level application/session layer policy engine built on early-2000s web/browser standards and Shadmon describes a low-level, bare-metal secure hardware data-storage framework; 2) combining Bohrer and Shadmon together merely yields Shadmon's static, encrypted storage vault with Bohrer's standard web access control list sitting in front of it; and 3) even if combined, the resulting system completely fails to produce the claimed privacy and consent broker, because it lacks any mechanism to dynamically execute runtime transformations on an active data stream inside a trusted execution environment and it cannot split transactional states between an isolated trusted execution environment processor and an untrusted distributed ledger, as recited in claim 1. As a result, the Examiner is using impermissible hindsight-using the applicant's own patent application as a blueprint to force these disparate references together, which, even if combined, fails to teach or suggest the method of amended claim 1. Accordingly, the Examiner has failed to meet the burden to establish a prima facie case of obviousness of amended claim 1. Therefore, Applicant believes that amended claim 1, as well as amended claim 14 that contains similar amendments, are allowable over the combination of Bohrer and Shadmon. Examiner’s remarks: Applicant’s statement that the examiner has used the applicant’s own patent application as a blueprint is not clear. The examiner has read the Applicant’s application, has interpreted the Applicant’s claims as best understood, applied the broadest reasonable interpretation to the claims, and applied the prior art as disclosed in the office action. In response to applicant's argument on page 24 that the examiner's conclusion of obviousness is based upon improper hindsight reasoning, it must be recognized that any judgment on obviousness is in a sense necessarily a reconstruction based upon hindsight reasoning. But so long as it takes into account only knowledge which was within the level of ordinary skill at the time the claimed invention was made, and does not include knowledge gleaned only from the applicant's disclosure, such a reconstruction is proper. See In re McLaughlin, 443 F.2d 1392, 170 USPQ 209 (CCPA 1971). In response to applicant’s argument that there is no teaching, suggestion, or motivation to combine the references, the examiner recognizes that obviousness may be established by combining or modifying the teachings of the prior art to produce the claimed invention where there is some teaching, suggestion, or motivation to do so found either in the references themselves or in the knowledge generally available to one of ordinary skill in the art. See In re Fine, 837 F.2d 1071, 5 USPQ2d 1596 (Fed. Cir. 1988), In re Jones, 958 F.2d 347, 21 USPQ2d 1941 (Fed. Cir. 1992), and KSR International Co. v. Teleflex, Inc., 550 U.S. 398, 82 USPQ2d 1385 (2007). The examiner maintains that the generality of the claim limitations do not prevent the teachings of the prior art of record. Therefore, Bohrer in view of Shadmon teaches the limitations as presented in the office action below. The current office action has been updated to include additional references for the limitations which Bohrer in view of Shadmon are deficient. Examiner’s further remarks: As indicated in the examiner’s remarks above and in the current office action, the argued limitations in the independent claims do not overcome the prior art applied in the current 35 USC 103 rejection. Thus, the independent claims are not allowable over the prior art of record and their dependent claims are not allowed based on their dependencies. Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. Claims 1, 2, 4-8, 10-12, 14-15, 17-21, 23-25 are rejected under 35 U.S.C. 112(b) as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor regards as the invention. Claims 1 and 14 recite “the trusted execution environment has a privacy and consent broker that comprises…a privacy and consent broker processor”. A Trusted Execution Environment (TEE) is not a physical processor by itself, it is a secure isolated area inside a main processor. Therefore, it is unclear how the TEE comprises a privacy and consent broker processor because a TEE is not a physical processor by itself, it is a secure isolated area inside a main processor. Therefore, it is unclear how to interpreted TEE, such as whether the privacy and consent broker is the main processor or the TEE is merely a trusted environment. The examiner has interpreted the claims as best understood. Claims 2, 4-8, and 10-12 are rejected as being dependent on, and failing to cure the deficiencies of, rejected independent claim 1. Claims 15, 17-21, and 23-25 are rejected as being dependent on, and failing to cure the deficiencies of, rejected independent claim 14. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-2, 4-8, 10-12, 14-15, 17-21, and 23-25 is/are rejected under 35 U.S.C. 103 as being unpatentable over Bohrer et al US 20030088520 (hereinafter Bohrer), in view of Shadmon et al US 20190158594 (hereinafter Shadmon), in further view of Wooden US 20180309567 (hereinafter Wooden), and in further view of Lenz et al US 20190132295 (hereinafter Lenz). As to claim 1, Bohrer teaches a method of performing a transaction in relation to an identity centric dataset (abstract discloses a method to enforce privacy preferences on exchanges/transaction of personal data in relation to data subject (identity centric) rules having one or more subject constraints on one or more private data releases. Paragraph 12 reveals different business transactions that include requested information), wherein the method comprises: executing via at least one processor a plurality of instructions stored in tangible, non-transient memory communicatively coupled to the at least one processor to perform the method by (claim 38 discloses computer having one or more memories and one or more central processing units, to perform instructions such as host subject data and policies, receive and process requests for such data and release as well as authorize release of such data): establishing, by a consortium network that includes at least one service network where each of the at least one service network includes a plurality of system nodes (claim 42 discloses one or more third-parties owning and holding data about the data-subject on one or more computers connected to one or more networks through one or more network interfaces, each computer having one or more memories and one or more central processing units. Claim 38 reveals the third party is a trusted third party acting as a personal data service), each one of the plurality of system nodes includes a processing unit (claim 42 discloses one or more third-parties owning and holding data about the data-subject on one or more computers connected to one or more networks through one or more network interfaces, each computer having one or more memories and one or more central processing units. Claim 38 reveals the third party is a trusted third party acting as a personal data service), and the consortium network further comprises a set of permitted data operations for a service network using a plurality of privacy schemas (paragraph 33 discloses establishing authorization rules and data privacy policies/controls for requested data and requestors. The system provides functionalities of define authorization rules and privacy controls, send and handle requests for data, authenticate requesters, authorize release of data based on authorization rules and privacy policy matching and release data. Paragraph 16 and Claim 1 disclose the system comprises one or more computers connected to one or more networks providing service of enforcing privacy preferences on exchanges of personal data that is owned by the subject itself or held/owned by third parties such as enterprises. Thus the system utilizes a consortium/service enterprise network. Paragraph 49 further discloses permitted set of data operations for requested data such as specifying privacy preference rule for data requestors in the access list to access the data in the authorization dataset. The Privacy Preference Rule in an Authorization Rule contains two declarations: data subject's privacy preferences and access actions allowed by the data subject. The Privacy Preference also specifies why and how the data can be accessed in terms of the P3P standards. The privacy preferences rules, the access list and the authorization rules are the plurality of privacy schemas); receiving, by the service application programming interface (API) in an untrusted execution environment in one of the plurality of system nodes in the service network (claim 1 reveals network interface receives request message from a data requestor. The data requestor is one of the nodes), a transaction request to perform the transaction in relation to the identity centric dataset associated with a data owner (paragraphs 32-33 disclose a data requestor uses a web browser of the system/service network or some other computer programs to send requests/transaction for data from a data subject. Each request for data is also accompanied by the data requestor’s privacy policies describing the intended usages of the requested data. Paragraphs 33, 79-80 and 82 reveal the request is in relation to the data of the data subject, thus it is identity centric dataset. Paragraph 12 reveals different business transactions include requestion information. See also paragraphs 21, 33, 44-45, 78-82); identifying, by the service network from the plurality of schemas and based on the transaction request, a privacy schema from the plurality of privacy schemas for use in performing the transaction (paragraph 42 discloses the request is handled by the Profile Responder of the system/service network which uses the Authentication engine to verify the identity of the requester and the Policy Authorization engine to identify/check the authority of the requester to access the requested data by using/identifying authorization rules and privacy policies (plurality of privacy schemas). See also paragraphs 44-49, 82, and 84); performing the transaction … using one or more data operations from the set of permitted data operations upon the identity centric dataset of the data owner as permitted by the identified privacy schema thereby generating a manipulated dataset and transaction metadata (Figure 7 discloses the steps involves in performing the transaction of the requested data. Paragraph 82, 84-88 further describe performing the transaction using one or more privacy level/identified schema from the permitted authorization rules of the data subject. Paragraph 86 reveals the different privacy levels/data label assignment operations that is performed in performing the data transaction request. Paragraph 87 further discloses checking the corresponding Boolean tag (generated transaction metadata) of a specific action in the preference settings (paragraph 77 discloses Boolean values are used to represent the access requirement flag). Paragraph 88 provides additional details of the data operation of filtering the data based on the privacy policies and authorization rules of the data subject. The filtered data is a manipulated dataset. Paragraph 9 also discloses manipulating data by transforming data so that it is no longer personally identifiable or to operate on data and produce results that are not personally identifiable); recording the transaction metadata (paragraph 91 discloses storing the data subject privacy preferences governing the data owned/stored by the enterprise (paragraph 77 reveals the privacy preferences includes the action permissions such as the Boolean values (transaction metadata) ). Paragraph 38 also discloses actions are stored in the form of rules or explicit action types which are recorded); and transferring the manipulated dataset from the one of the plurality of system nodes in the service network to a data receiver indicated by the transaction request (paragraph 88 discloses sending the filtered data/manipulated data result to the data requestor as indicated in the transaction request). Bohrer does not teach establishing, by a consortium network that includes at least one service network where each of the at least one service network include a plurality of system nodes, each one of the plurality of system nodes includes a processing unit with a trusted execution environment communicatively connected to an operating memory, the trusted execution environment has a privacy and consent broker that comprises a privacy and consent broker application programming interface (API), a privacy and consent broker processor, a plurality of privacy schemas, and a plurality of smart contracts, and the consortium network further comprises a set of permitted data operations for the service network using the plurality of privacy schemas; identifying, by the privacy and consent broker processor in the one of the plurality of system nodes in the service network a privacy schema for use in performing the transaction; performing the transaction by executing, in the privacy and consent broker processor of a trusted the trusted execution environment of the service network, one or more data operations via the plurality of smart contracts from the set of permitted data operations upon the identity centric dataset of the data owner as permitted by the identified privacy schema thereby generating a manipulated dataset and transaction metadata. Shadmon teaches performing the transaction by executing, in a trusted execution environment of the service network (paragraph 418 discloses processing queries/requests via trusted execution environment), one or more data operations from the set of permitted data operations…as permitted by the identified privacy schema thereby generating a manipulated dataset and transaction metadata (paragraphs 414 and 418-419 disclose processing queries/requests via trusted execution environment on confidential data to obtain a result. A catalog is used in the process, therefore, when a query is processed, the catalog provides the information on the log files that needs to be considered to satisfy the query. The said catalog contains the metadata information such that when a query is processed the metadata provides the list of log files to consider and where each file is stored. The results are aggregated/manipulated to obtain the unified result. Paragraphs 413-414 reveal the data is distributed based on the level of data protection and on the policies regarding access permissions for data consumer/requestor); recording the transaction metadata to a distributed ledger in the untrusted execution environment of the service network (paragraph 271 discloses the metadata is maintained by a blockchain. The metadata may be represented by Accounts and Transactions on the blockchain and the meta information becomes available to a query process as the blockchain data is available. Paragraph 16 further discloses data is organized in log files which are stored on a network of machine (paragraph 18 discloses the service network) and paragraph 49 discloses that the plurality of log files are stored on the distributed server/ledgers). It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify Bohrer’s system performing the transaction and recording the transaction metadata with Shadmon’s teachings of processing the queries in the trusted execution environment and recording the transaction metadata to a distributed ledger to ensure that submitted queries/requests/transactions do not reveal information the data consumer is not authorized to access and that the query results only rely on authenticated data (paragraph 418 of Shadmon). The combination of Bohrer in view of Shadmon does not teach establishing, by a consortium network that includes at least one service network where each of the at least one service network include a plurality of system nodes, each one of the plurality of system nodes includes a processing unit with a trusted execution environment communicatively connected to an operating memory, the trusted execution environment has a privacy and consent broker that comprises a privacy and consent broker application programming interface (API), a privacy and consent broker processor, a plurality of privacy schemas, and a plurality of smart contracts, and the consortium network further comprises a set of permitted data operations for the service network using the plurality of privacy schemas; identifying, by the privacy and consent broker processor in the one of the plurality of system nodes in the service network a privacy schema for use in performing the transaction; performing the transaction by executing, in the privacy and consent broker processor of a trusted the trusted execution environment of the service network, one or more data operations via the plurality of smart contracts from the set of permitted data operations upon the identity centric dataset of the data owner as permitted by the identified privacy schema thereby generating a manipulated dataset and transaction metadata. PNG media_image1.png 512 714 media_image1.png Greyscale Figure 1 of Wooden Wooden teaches establishing, by a consortium network (Figure 1 reveals a network environment, see also paragraph 59 “Establishing a consortium blockchain network”) that includes at least one service network (Figure 1, reference number 130 “Network”) where each of the at least one service network include a plurality of system nodes (Figure 1, reference numbers 120a and 112a represent the a node, reference numbers 120b and 112b represent another node, and reference number 120c and 112c is an additional node, thus a plurality of nodes. See also paragraphs 29-30 which disclose the network environment includes plurality of network nodes that interconnect multiple computing devices 110) , each one of the plurality of system nodes includes a processing unit ( Figures 1-3 and paragraphs 29-30 which disclose the network environment includes plurality of network nodes that interconnect multiple computing devices 110. The computing device diagram is shown in detail in Figure 2, wherein the computing device includes processing circuit 210) with a trusted execution environment communicatively connected to an operating memory (Figure 3 and paragraph 44 reveals the VNs shown include the computing devices shown in Figure 2 which has operating memory 220, each VN includes TEE 362), the trusted execution environment has a privacy and consent broker that comprises a privacy and consent broker application programming interface (API), a privacy and consent broker processor, a plurality of privacy schemas, and a plurality of smart contracts, and the consortium network further comprises a set of permitted data operations for the service network using the plurality of privacy schemas (Figure 4 and paragraphs 52-53, 60 reveal the TEE has a privacy and consent broker processor-COCO core, a privacy and consent broker application programming interface-COCO API, , a plurality of privacy schemas-access/membership/block. The TEE also includes a set of permitted operations for the service network using the privacy schemas-blockchain protocol and consensus protocol). PNG media_image2.png 450 725 media_image2.png Greyscale Figure 3 of Wooden It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify Bohrer’s system performing the transaction and recording the transaction metadata in view of Shadmon’s teachings of processing the queries in the trusted execution environment and recording the transaction metadata to a distributed ledger with Wooden’s teachings of establishing a consortium network such that a blockchain transaction is processed while disallowing access to raw transaction data (paragraph 5 of Wooden). The combination of Bohrer in view of Shadmon and Wooden does not teach, yet Lenz teaches identifying, by the privacy and consent broker processor in the one of the plurality of system nodes in the service network a privacy schema for use in performing the transaction (paragraph 47 discloses the transaction processor inside the TEE maintains and enforces the access control policies (privacy schemas)); performing the transaction by executing, in the privacy and consent broker processor of a trusted the trusted execution environment of the service network, one or more data operations via the plurality of smart contracts from the set of permitted data operations upon the identity centric dataset of the data owner as permitted by the identified privacy schema thereby generating a manipulated dataset and transaction metadata (paragraph 47 discloses the running a transaction processor inside the TEE, wherein the transaction processor consist of access control logic which performs a confidential implementation of the blockchain smart contract; and a cryptographic library, which supports cryptographic operations with use of the ledger keys. Paragraph 48 reveals that the ledger keys includes encrypting transaction data and encrypting node request results thus generating a manipulated dataset). It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify Bohrer’s system performing the transaction and recording the transaction metadata in view of Shadmon’s teachings of processing the queries in the trusted execution environment and recording the transaction metadata to a distributed ledger and Wooden’s teachings of establishing a consortium network with Lenz’s teachings of the processor of the TEE performing data operations via smart contracts as permitted by identified privacy schema to provide improved governance of which operations can be done by users and what data can be accessed by the users (paragraph 47 of Lenz). As to claim 2, the combination of Bohrer in view of Shadmon, Wooden, and Lenz teaches wherein the privacy schema is identified from the plurality of privacy schemas based on at least one of the data owner and the data receiver as indicated by the transaction request (Bohrer: Figure 2 and paragraphs 44-47 disclose privacy schema (authorization rule) is identified from plurality of privacy schemas such as authorization dataset, privacy preference rule, access list, or authorization actions that are based on the data receiver and set by the data owner/subject. Paragraph 42 discloses the request/transaction for data describe the data desired along with privacy policies describing the intended usage). As to claim 4, the combination of Bohrer in view of Shadmon, Wooden, and Lenz teaches wherein the one or more data operations comprise at least one of: a data transformation operation; a data encryption operation; a data privacy preservation operation; a data anonymization operation; a data pseudo-anonymization operation; a data tokenization operation; a data enrichment operation; a data label assignment operation; a data classification label assignment operation; and a data dissemination marker assignment operation (Bohrer: paragraph 9 discloses enterprise Privacy-enhancing Data Manipulation tools and technologies are used to eliminate privacy issues by transforming data so it is no longer personally identifiable, or to operate on data and produce results that are not personally identifiable. Paragraph 87 reveals providing data classification label/Boolean tag of a specific action. Shadmon: paragraph 414 reveals data operation may involves anonymity requirements). Motivation similar to the motivation presented in claim 1. As to claim 5, the combination of Bohrer in view of Shadmon, Wooden, and Lenz teaches wherein the transaction metadata comprises one or more identity attribute identifiers (Bohrer: paragraph 87 reveals providing data classification label/Boolean tag of a specific action) ; a transaction context (Shadmon: paragraph 16 discloses metadata provides context to the data); consent of the data owner (Shadmon: paragraph 28 discloses the metadata determines the permissions, by the data owner provided to the user); an identifier of the data owner (Shadmon: paragraph 26 discloses the metadata determines the list of members registered to service data. Paragraph 76 reveals the metadata include the list of authorized users and their permissions); an identifier of the data receiver (Shadmon: paragraph 26 discloses the metadata determines the list of members registered to service data); and an identifier of each identifiers of the one or more data operations (Shadmon: paragraph 21 reveals the metadata determine which members maintain the log files that are needed to be considered in order to satisfy the query. Paragraph 45 discloses when data is distributed to the contractors, the identifiers of the data and the distribution of the data are registered using a registry. The node can maintain a local copy of the metadata/identifiers). Motivation similar to the motivation presented in claim 1. As to claim 6, the combination of Bohrer in view of Shadmon, Wooden, and Lenz teaches wherein the transaction request comprises the consent of the data owner and the transaction context (Bohrer: paragraphs 47 and 82 disclose the request involves identifying the authorization rules /consent of the data subject/owner and the access list/transaction context. Paragraph 12 discloses the context of the request allows the data subject/owner to allow access to different sets of data with different polices on usage and sharing). As to claim 7, the combination of Bohrer in view of Shadmon, Wooden, and Lenz teaches wherein the privacy schema is identified from the plurality of privacy schemas based on at least one of the consent of the data owner and the transaction context (Bohrer: Figure 2 and paragraphs 44-47 disclose privacy schema (authorization rule) is identified from plurality of privacy schemas such as authorization dataset (consent), privacy preference rule (consent), access list, or authorization actions that are based/set by the data owner/subject. Paragraph 42 discloses the request/transaction for data describe the data desired along with privacy policies describing the intended usage. Paragraph 12 discloses the context of the request allows the data subject/owner to allow access to different sets of data with different polices on usage and sharing). As to claim 8, the combination of Bohrer in view of Shadmon, Wooden, and Lenz teaches wherein the manipulated dataset comprises one or more transaction data records and the transaction metadata (Bohrer: paragraph 88 provides additional details of the data operation of filtering the data that was gathered from databases/data record (paragraphs 3, 17, and 91 reveal data subject stores their record in a data repository) based on the privacy policies and authorization rules of the data subject. The filtered data is a manipulated dataset. Paragraph 9 also discloses manipulating data by transforming data so that it is no longer personally identifiable or to operate on data and produce results that are not personally identifiable). As to claim 10, the combination of Bohrer in view of Shadmon, Wooden, and Lenz teaches wherein the transaction request is received from a data owner device via the service API (Bohrer: abstract discloses system receives a request from a data requester over a network interface. Claim 1 discloses the system further comprising receiving process that receives a request message from a data-requester over the network interfaces. Shadmon: paragraphs 22-23 reveal query is sent to a computer from an application using a REST API. Paragraph 395 reveals parties (which can include other data owners) can request data). It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify the network interface in Bohrer’s system performing the transaction and recording the transaction metadata in view of Wooden’s teachings of establishing a consortium network and Lenz’s teachings of the processor of the TEE performing data operations via smart contracts as permitted by identified privacy schema with Shadmon’s teachings of utilizing REST API such that data owners can provide access to third parties in a simple/convenient manner (paragraph 65 of Shadmon). As to claim 11, the combination of Bohrer in view of Shadmon, Wooden, and Lenz teaches wherein at least some of the manipulated dataset is encrypted by the service network based on the one or more data operations (Shadmon: paragraph 341-342 and 418 reveal the data is encrypted and processed in the TEE) , wherein the method further comprises: receiving, via the service API, a data access request (Bohrer: abstract discloses system receives a request from a data requester over a network interface. Claim 1 discloses the system further comprising receiving process that receives a request message from a data-requester over the network interfaces. Shadmon: paragraphs 22-23 reveal query is sent to a computer from an application using a REST API); determining, based on the data access request, if the data receiver is permitted to perform decryption of the at least some of the manipulated dataset (Shadmon: paragraph 418 reveals that only within the TEE can the encrypted data be decrypted for further processes. Paragraph 428 also disclose that within the TEE and the access permission (permitting the data receiver to obtain the data) the data is decrypted); and if the data receiver is determined to be permitted: generating and transferring, to the data receiver, a decryption key to enable the data receiver to decrypt the at least some of the manipulated dataset (Shadmon: paragraphs 49 and 51 reveal the decryption key is sent for the data from the servers to the permitted clients (thus data receiver is enable to receive the data); and recording, by the service network, further transaction metadata to the distributed ledger (Shadmon: paragraph 271 discloses the metadata is maintained by a blockchain. The metadata may be represented by Accounts and Transactions on the blockchain and the meta information becomes available to a query process as the blockchain data is available. Paragraph 16 further discloses data is organized in log files which are stored on a network of machine (paragraph 18 discloses the service network) and paragraph 49 discloses that the plurality of log files are stored on the distributed server/ledgers). It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify the network interface in Bohrer’s system performing the transaction and recording the transaction metadata in view of Wooden’s teachings of establishing a consortium network and Lenz’s teachings of the processor of the TEE performing data operations via smart contracts as permitted by identified privacy schema with Shadmon’s teachings of processing the queries in the trusted execution environment and recording the transaction metadata to a distributed ledger to ensure that submitted queries/requests/transactions do not reveal information the data consumer is not authorized to access and that the query results only rely on authenticated data (paragraph 418 of Shadmon). As to claim 12, the combination of Bohrer in view of Shadmon, Wooden, and Lenz teaches wherein the method further comprises configuring the service network by initializing one or more system nodes based on a plurality of smart contracts (Shadmon: paragraph 65 reveals the smart contracts document enforce the agreements that are made between peers (nodes) of the network, see also paragraph 120-122 which reveal a smart contract manages payments to the contractor, when the query is issued, the query is provided to a Coordinator node and processed by the Coordinator Node). Paragraph 355 discloses penalty would be enforced by a smart contract that would validate the integrity of the data maintained on the node or the node's response to a query by comparing the data or the query result to a different node that maintains the same data or process the same query over the same data. Or, if the node is not responsive, the smart contract can provide a time from which the penalty is triggered if the node remains unresponsive) and the plurality of privacy schemas distributed via a further distributed ledger (Shadmon: paragraphs 305 reveals the smart contract is stored in the block chain (paragraph 415 disclose the smart contract encodes a decentralized protocol for updating schema and security policies)), wherein the plurality of smart contracts encode the plurality of data operations (Shadmon: paragraph 415 disclose the smart contract encodes a decentralized protocol for updating schema and security policies). It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify the network interface in Bohrer’s system performing the transaction and recording the transaction metadata in view of Wooden’s teachings of establishing a consortium network and Lenz’s teachings of the processor of the TEE performing data operations via smart contracts as permitted by identified privacy schema with Shadmon’s teachings of processing smart contracts to validate the integrity of the data maintained on the node or the node's response to a query (paragraph 355 of Shadmon). As to claim 14, Bohrer teaches a system of performing a transaction on an identity centric dataset (abstract discloses system and method to enforce privacy preferences on exchanges/transaction of personal data in relation to data subject (identity centric) rules having one or more subject constraints on one or more private data releases. Paragraph 12 reveals different business transactions include requestion information), wherein the system comprises one or more processing systems (abstract, paragraph 29, claim 38 disclose the system utilizes one or more computers in a computer network) communicatively connected to a tangible, non-transient memory storing instructions that when executed by the one or more processing systems, cause the system to (claim 38 discloses computer having one or more memories and one or more central processing units, to perform instructions such as host subject data and policies, receive and process requests for such data and release as well as authorize release of such data): establish via a consortium network that includes at least one service network where each of the at least one service network includes a plurality of system nodes (claim 42 discloses one or more third-parties owning and holding data about the data-subject on one or more computers connected to one or more networks through one or more network interfaces, each computer having one or more memories and one or more central processing units. Claim 38 reveals the third party is a trusted third party acting as a personal data service), each one of the plurality of system nodes includes a processing unit (claim 42 discloses one or more third-parties owning and holding data about the data-subject on one or more computers connected to one or more networks through one or more network interfaces, each computer having one or more memories and one or more central processing units. Claim 38 reveals the third party is a trusted third party acting as a personal data service), and the consortium network further comprises a set of permitted data operations for a service network using a plurality of privacy schemas (paragraph 33 discloses establishing authorization rules and data privacy policies/controls for requested data and requestors. The system provides functionalities of define authorization rules and privacy controls, send and handle requests for data, authenticate requesters, authorize release of data based on authorization rules and privacy policy matching and release data. Paragraph 16 and Claim 1 disclose the system comprises one or more computers connected to one or more networks providing service of enforcing privacy preferences on exchanges of personal data that is owned by the subject itself or held/owned by third parties such as enterprises. Thus the system utilizes a consortium/service enterprise network. Paragraph 49 further discloses permitted set of data operations for requested data such as specifying privacy preference rule for data requestors in the access list to access the data in the authorization dataset. The Privacy Preference Rule in an Authorization Rule contains two declarations: data subject's privacy preferences and access actions allowed by the data subject. The Privacy Preference also specifies why and how the data can be accessed in terms of the P3P standards. The privacy preferences rules, the access list and the authorization rules are the plurality of privacy schemas); receive via a service application programming interface (API) in an untrusted execution environment in one of the plurality of system nodes in the service network (claim 1 reveals network interface receives request message from a data requestor), a transaction request to perform the transaction in relation to the identity centric dataset associated with a data owner (paragraphs 32-33 disclose a data requestor uses a web browser of the system/service network or some other computer programs to send requests/transaction for data from a data subject. Each request for data is also accompanied by the data requestor’s privacy policies describing the intended usages of the requested data. Paragraphs 33, 79-80 and 82 reveal the request is in relation to the data of the data subject, thus it is identity centric dataset. Paragraph 12 reveals different business transactions include requestion information. See also paragraphs 21, 33, 44-45, 78-82); identify, by the service network from the plurality of schemas and based on the transaction request, a privacy schema from the plurality of privacy schemas for use in performing the transaction (paragraph 42 discloses the request is handled by the Profile Responder of the system/service network which uses the Authentication engine to verify the identity of the requester and the Policy Authorization engine to identify/check the authority of the requester to access the requested data by using/identifying authorization rules and privacy policies (plurality of privacy schemas). See also paragraphs 44-49, 82, and 84); perform the transaction … using one or more data operations from the set of permitted data operations upon the identity centric dataset of the data owner as permitted by the identified privacy schema thereby generating a manipulated dataset and transaction metadata (Figure 7 discloses the steps involves in performing the transaction of the requested data. Paragraph 82, 84-88 further describe performing the transaction using one or more privacy level/identified schema from the permitted authorization rules of the data subject. Paragraph 86 reveals the different privacy levels/data label assignment operations that is performed in performing the data transaction request. Paragraph 87 further discloses checking the corresponding Boolean tag (generated transaction metadata) of a specific action in the preference settings (paragraph 77 discloses Boolean values are used to represent the access requirement flag). Paragraph 88 provides additional details of the data operation of filtering the data based on the privacy policies and authorization rules of the data subject. The filtered data is a manipulated dataset. Paragraph 9 also discloses manipulating data by transforming data so that it is no longer personally identifiable or to operate on data and produce results that are not personally identifiable); record the transaction metadata (paragraph 91 discloses storing the data subject privacy preferences governing the data owned/stored by the enterprise (paragraph 77 reveals the privacy preferences includes the action permissions such as the Boolean values (transaction metadata) ). Paragraph 38 also discloses actions are stored in the form of rules or explicit action types which are recorded); and transfer the manipulated dataset from the one of the plurality of system nodes in the service network to a data receiver indicated by the transaction request (paragraph 88 discloses sending the filtered data/manipulated data result to the data requestor as indicated in the transaction request). Bohrer does not teach establishing via a consortium network that includes at least one service network where each of the at least one service network include a plurality of system nodes, each one of the plurality of system nodes includes a processing unit with a trusted execution environment communicatively connected to an operating memory, the trusted execution environment has a privacy and consent broker that comprises a privacy and consent broker application programming interface (API), a privacy and consent broker processor, a plurality of privacy schemas, and a plurality of smart contracts, and the consortium network further comprises a set of permitted data operations for the service network using the plurality of privacy schemas; identify, by the privacy and consent broker processor in the one of the plurality of system nodes in the service network, a privacy schema for use in performing the transaction; perform the transaction by executing, in the privacy and consent broker processor of a trusted the trusted execution environment of the service network, one or more data operations via the plurality of smart contracts from the set of permitted data operations upon the identity centric dataset of the data owner as permitted by the identified privacy schema thereby generating a manipulated dataset and transaction metadata. Shadmon teaches perform the transaction by executing, in a trusted execution environment of the service network (paragraph 418 discloses processing queries/requests via trusted execution environment), one or more data operations from the set of permitted data operations…as permitted by the identified privacy schema thereby generating a manipulated dataset and transaction metadata (paragraphs 414 and 418-419 disclose processing queries/requests via trusted execution environment on confidential data to obtain a result. A catalog is used in the process, therefore, when a query is processed, the catalog provides the information on the log files that needs to be considered to satisfy the query. The said catalog contains the metadata information such that when a query is processed the metadata provides the list of log files to consider and where each file is stored. The results are aggregated/manipulated to obtain the unified result. Paragraphs 413-414 reveal the data is distributed based on the level of data protection and on the policies regarding access permissions for data consumer/requestor); recording the transaction metadata to a distributed ledger in the untrusted execution environment of the service network (paragraph 271 discloses the metadata is maintained by a blockchain. The metadata may be represented by Accounts and Transactions on the blockchain and the meta information becomes available to a query process as the blockchain data is available. Paragraph 16 further discloses data is organized in log files which are stored on a network of machine (paragraph 18 discloses the service network) and paragraph 49 discloses that the plurality of log files are stored on the distributed server/ledgers). It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify Bohrer’s system performing the transaction and recording the transaction metadata with Shadmon’s teachings of processing the queries in the trusted execution environment and recording the transaction metadata to a distributed ledger to ensure that submitted queries/requests/transactions do not reveal information the data consumer is not authorized to access and that the query results only rely on authenticated data (paragraph 418 of Shadmon). The combination of Bohrer in view of Shadmon does not teach establish via a consortium network that includes at least one service network where each of the at least one service network include a plurality of system nodes, each one of the plurality of system nodes includes a processing unit with a trusted execution environment communicatively connected to an operating memory, the trusted execution environment has a privacy and consent broker that comprises a privacy and consent broker application programming interface (API), a privacy and consent broker processor, a plurality of privacy schemas, and a plurality of smart contracts, and the consortium network further comprises a set of permitted data operations for the service network using the plurality of privacy schemas; identify, by the privacy and consent broker processor in the one of the plurality of system nodes in the service network, a privacy schema for use in performing the transaction; performing the transaction by executing, in the privacy and consent broker processor of a trusted the trusted execution environment of the service network, one or more data operations via the plurality of smart contracts from the set of permitted data operations upon the identity centric dataset of the data owner as permitted by the identified privacy schema thereby generating a manipulated dataset and transaction metadata. Wooden teaches establish via a consortium network (Figure 1 reveals a network environment, see also paragraph 59 “Establishing a consortium blockchain network”) that includes at least one service network (Figure 1, reference number 130 “Network”) where each of the at least one service network include a plurality of system nodes (Figure 1, reference numbers 120a and 112a represent the a node, reference numbers 120b and 112b represent another node, and reference number 120c and 112c is an additional node, thus a plurality of nodes. See also paragraphs 29-30 which disclose the network environment includes plurality of network nodes that interconnect multiple computing devices 110) , each one of the plurality of system nodes includes a processing unit ( Figures 1-3 and paragraphs 29-30 which disclose the network environment includes plurality of network nodes that interconnect multiple computing devices 110. The computing device diagram is shown in detail in Figure 2, wherein the computing device includes processing circuit 210) with a trusted execution environment communicatively connected to an operating memory (Figure 3 and paragraph 44 reveals the VNs shown include the computing devices shown in Figure 2 which has operating memory 220, each VN includes TEE 362), the trusted execution environment has a privacy and consent broker that comprises a privacy and consent broker application programming interface (API), a privacy and consent broker processor, a plurality of privacy schemas, and a plurality of smart contracts, and the consortium network further comprises a set of permitted data operations for the service network using the plurality of privacy schemas (Figure 4 and paragraphs 52-53, 60 reveal the TEE has a privacy and consent broker processor-COCO core, a privacy and consent broker application programming interface-COCO API, , a plurality of privacy schemas-access/membership/block. The TEE also includes a set of permitted operations for the service network using the privacy schemas-blockchain protocol and consensus protocol). It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify Bohrer’s system performing the transaction and recording the transaction metadata in view of Shadmon’s teachings of processing the queries in the trusted execution environment and recording the transaction metadata to a distributed ledger with Wooden’s teachings of establishing a consortium network such that a blockchain transaction is processed while disallowing access to raw transaction data (paragraph 5 of Wooden). The combination of Bohrer in view of Shadmon and Wooden does not teach, yet Lenz teaches identifying, by the privacy and consent broker processor in the one of the plurality of system nodes in the service network a privacy schema for use in performing the transaction (paragraph 47 discloses the transaction processor inside the TEE maintains and enforces the access control policies (privacy schemas)); performing the transaction by executing, in the privacy and consent broker processor of a trusted the trusted execution environment of the service network, one or more data operations via the plurality of smart contracts from the set of permitted data operations upon the identity centric dataset of the data owner as permitted by the identified privacy schema thereby generating a manipulated dataset and transaction metadata (paragraph 47 discloses the running a transaction processor inside the TEE, wherein the transaction processor consist of access control logic which performs a confidential implementation of the blockchain smart contract; and a cryptographic library, which supports cryptographic operations with use of the ledger keys. Paragraph 48 reveals that the ledger keys includes encrypting transaction data and encrypting node request results thus generating a manipulated dataset). It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify Bohrer’s system performing the transaction and recording the transaction metadata in view of Shadmon’s teachings of processing the queries in the trusted execution environment and recording the transaction metadata to a distributed ledger and Wooden’s teachings of establishing a consortium network with Lenz’s teachings of processor of the TEE performing data operations via smart contracts as permitted by identified privacy schema to provide improve governance of which operations can be done by users and what data can be accessed by the users (paragraph 47 of Lenz). As to claim 15, the combination of Bohrer in view of Shadmon, Wooden, and Lenz teaches wherein the privacy schema is identified from the plurality of privacy schemas based on at least one of the data owner and the data receiver as indicated by the transaction request (Bohrer: Figure 2 and paragraphs 44-47 disclose privacy schema (authorization rule) is identified from plurality of privacy schemas such as authorization dataset, privacy preference rule, access list, or authorization actions that are based on the data receiver and set by the data owner/subject. Paragraph 42 discloses the request/transaction for data describe the data desired along with privacy policies describing the intended usage). As to claim 17, the combination of Bohrer in view of Shadmon, Wooden, and Lenz teaches wherein the one or more data operations comprise at least one of: a data transformation operation; a data encryption operation; a data privacy preservation operation; a data anonymization operation; a data pseudo-anonymization operation; a data tokenization operation; a data enrichment operation; a data label assignment operation; a data classification label assignment operation; and a data dissemination marker assignment operation (Bohrer: paragraph 9 discloses enterprise Privacy-enhancing Data Manipulation tools and technologies are used to eliminate privacy issues by transforming data so it is no longer personally identifiable, or to operate on data and produce results that are not personally identifiable. Paragraph 87 reveals providing data classification label/Boolean tag of a specific action. Shadmon: paragraph 414 reveals data operation may involves anonymity requirements). Motivation similar to the motivation presented in claim 14. As to claim 18, the combination of Bohrer in view of Shadmon, Wooden, and Lenz teaches wherein the transaction metadata comprises one or more identity attribute identifiers (Bohrer: paragraph 87 reveals providing data classification label/Boolean tag of a specific action) ; a transaction context (Shadmon: paragraph 16 discloses metadata provides context to the data); consent of the data owner (Shadmon: paragraph 28 discloses the metadata determines the permissions, by the data owner provided to the user); an identifier of the data owner (Shadmon: paragraph 26 discloses the metadata determines the list of members registered to service data. Paragraph 76 reveals the metadata include the list of authorized users and their permissions); an identifier of the data receiver (Shadmon: paragraph 26 discloses the metadata determines the list of members registered to service data); and an identifier of each identifiers of the one or more data operations (Shadmon: paragraph 21 reveals the metadata determine which members maintain the log files that are needed to be considered in order to satisfy the query. Paragraph 45 discloses when data is distributed to the contractors, the identifiers of the data and the distribution of the data are registered using a registry. The node can maintain a local copy of the metadata/identifiers). Motivation similar to the motivation presented in claim 14. As to claim 19, the combination of Bohrer in view of Shadmon, Wooden, and Lenz teaches wherein the transaction request comprises the consent of the data owner and the transaction context (Bohrer: paragraphs 47 and 82 disclose the request involves identifying the authorization rules /consent of the data subject/owner and the access list/transaction context. Paragraph 12 discloses the context of the request allows the data subject/owner to allow access to different sets of data with different polices on usage and sharing). As to claim 20, the combination of Bohrer in view of Shadmon, Wooden, and Lenz teaches wherein the privacy schema is identified from the plurality of privacy schemas based on at least one of the consent of the data owner and the transaction context (Bohrer: Figure 2 and paragraphs 44-47 disclose privacy schema (authorization rule) is identified from plurality of privacy schemas such as authorization dataset (consent), privacy preference rule (consent), access list, or authorization actions that are based/set by the data owner/subject. Paragraph 42 discloses the request/transaction for data describe the data desired along with privacy policies describing the intended usage. Paragraph 12 discloses the context of the request allows the data subject/owner to allow access to different sets of data with different polices on usage and sharing). As to claim 21, the combination of Bohrer in view of Shadmon, Wooden, and Lenz teaches wherein the manipulated dataset comprises one or more transaction data records and the transaction metadata (Bohrer: paragraph 88 provides additional details of the data operation of filtering the data that was gathered from databases/data record (paragraphs 3, 17, and 91 reveal data subject stores their record in a data repository) based on the privacy policies and authorization rules of the data subject. The filtered data is a manipulated dataset. Paragraph 9 also discloses manipulating data by transforming data so that it is no longer personally identifiable or to operate on data and produce results that are not personally identifiable). As to claim 23, the combination of Bohrer in view of Shadmon, Wooden, and Lenz teaches wherein the transaction request is received from a data owner device via the service API (Bohrer: abstract discloses system receives a request from a data requester over a network interface. Claim 1 discloses the system further comprising receiving process that receives a request message from a data-requester over the network interfaces. Shadmon: paragraphs 22-23 reveal query is sent to a computer from an application using a REST API. Paragraph 395 reveals parties (which can include other data owners) can request data). It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify the network interface in Bohrer’s system performing the transaction and recording the transaction metadata in view of Wooden’s teachings of establishing a consortium network and Lenz’s teachings of the processor of the TEE performing data operations via smart contracts as permitted by identified privacy schema with Shadmon’s teachings of utilizing REST API such that data owners can provide access to third parties in a simple/convenient way (paragraph 65 of Shadmon). As to claim 24, the combination of Bohrer in view of Shadmon, Wooden, and Lenz teaches wherein at least some of the manipulated dataset is encrypted by the service network based on the one or more data operations (Shadmon: paragraph 341-342 and 418 reveal the data is encrypted and processed in the TEE) , wherein the consortium network is further configured to: receive, via the service API, a data access request (Bohrer: abstract discloses system receives a request from a data requester over a network interface. Claim 1 discloses the system further comprising receiving process that receives a request message from a data-requester over the network interfaces. Shadmon: paragraphs 22-23 reveal query is sent to a computer from an application using a REST API); determine, based on the data access request, if the data receiver is permitted to perform decryption of the at least some of the manipulated dataset (Shadmon: paragraph 418 reveals that only within the TEE can the encrypted data be decrypted for further processes. Paragraph 428 also disclose that within the TEE and the access permission (permitting the data receiver to obtain the data) the data is decrypted); and if the data receiver is determined to be permitted: generate and transfer, to the data receiver, a decryption key to enable the data receiver to decrypt the at least some of the manipulated dataset (Shadmon: paragraphs 49 and 51 reveal the decryption key is sent for the data from the servers to the permitted clients (thus data receiver is enable to receive the data); and record, by the service network, further transaction metadata to the distributed ledger (Shadmon: paragraph 271 discloses the metadata is maintained by a blockchain. The metadata may be represented by Accounts and Transactions on the blockchain and the meta information becomes available to a query process as the blockchain data is available. Paragraph 16 further discloses data is organized in log files which are stored on a network of machine (paragraph 18 discloses the service network) and paragraph 49 discloses that the plurality of log files are stored on the distributed server/ledgers). It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify the network interface in Bohrer’s system performing the transaction and recording the transaction metadata in view of Wooden’s teachings of establishing a consortium network and Lenz’s teachings of the processor of the TEE performing data operations via smart contracts as permitted by identified privacy schema with Shadmon’s teachings of processing the queries in the trusted execution environment and recording the transaction metadata to a distributed ledger to ensure that submitted queries/requests/transactions do not reveal information the data consumer is not authorized to access and that the query results only rely on authenticated data (paragraph 418 of Shadmon). As to claim 25, the combination of Bohrer in view of Shadmon, Wooden, and Lenz teaches wherein the one or more processing systems configure the service network by initializing one or more system nodes based on a plurality of smart contracts (Shadmon: paragraph 65 reveals the smart contracts document enforce the agreements that are made between peers (nodes) of the network, see also paragraph 120-122 which reveal a smart contract manages payments to the contractor, when the query is issued, the query is provided to a Coordinator node and processed by the Coordinator Node). Paragraph 355 discloses penalty would be enforced by a smart contract that would validate the integrity of the data maintained on the node or the node's response to a query by comparing the data or the query result to a different node that maintains the same data or process the same query over the same data. Or, if the node is not responsive, the smart contract can provide a time from which the penalty is triggered if the node remains unresponsive) and the plurality of privacy schemas distributed via a further distributed ledger (Shadmon :paragraphs 305 reveals the smart contract is stored in the block chain (paragraph 415 disclose the smart contract encodes a decentralized protocol for updating schema and security policies)), wherein the plurality of smart contracts encode the plurality of data operations (Shadmon: paragraph 415 disclose the smart contract encodes a decentralized protocol for updating schema and security policies). It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify the network interface in Bohrer’s system performing the transaction and recording the transaction metadata in view of Wooden’s teachings of establishing a consortium network and Lenz’s teachings of the processor of the TEE performing data operations via smart contracts as permitted by identified privacy schema with Shadmon’s teachings of processing smart contracts to validate the integrity of the data maintained on the node or the node's response to a query (paragraph 355 of Shadmon). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: Willden et al US 9697371 (hereinafter Willden). Willden teaches a consortium network (Figure 1) that includes at least one service network (Figure 1, reference number 107), where each of the at least one service network includes a plurality of system nodes (the nodes are depicted as reference numbers 100, 104, and 120 of Figure 1), each one of the plurality of system nodes includes a processing unit (Figure 1, reference number 102) with a trusted execution environment (Figure 1, reference number 106) communicatively connected to an operating memory (Figure 1, reference number 105), the trusted execution environment has a privacy and consent broker (Figure 1, reference number 110) as disclosed in claims 1 and 14. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to FELICIA FARROW whose telephone number is (571)272-1856. The examiner can normally be reached M - F 7:30am-4:00pm (EST). Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached at (571)270-5143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /F.F/Examiner, Art Unit 2437 /BENJAMIN E LANIER/Primary Examiner, Art Unit 2437
Read full office action

Prosecution Timeline

Show 5 earlier events
Oct 28, 2024
Response after Non-Final Action
Dec 26, 2024
Non-Final Rejection mailed — §103, §112
Jun 26, 2025
Response Filed
Oct 03, 2025
Final Rejection mailed — §103, §112
Dec 03, 2025
Response after Non-Final Action
Jan 20, 2026
Non-Final Rejection mailed — §103, §112
Jul 20, 2026
Response Filed
Aug 27, 2026
Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12748884
METHOD AND SYSTEM FOR ENSURING PRIVACY PROTECTION FOR DATASETS USING SPACE PARTITIONING TECHNIQUES
3y 3m to grant Granted Sep 29, 2026
Patent 12724865
Continuous Authentication in a Security Environment
3y 7m to grant Granted Sep 01, 2026
Patent 12724917
LOG COMPRESSION AND OBFUSCATION USING EMBEDDINGS
2y 10m to grant Granted Sep 01, 2026
Patent 12694149
SYSTEM AND METHOD FOR REDACTION OF DATA THAT IS INCIDENTALLY RECORDED
4y 7m to grant Granted Jul 28, 2026
Patent 12675579
Secure Systems of Guardrails for Securing the Use of Large Language Models (LLMS)
2y 3m to grant Granted Jul 07, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

7-8
Expected OA Rounds
59%
Grant Probability
94%
With Interview (+35.6%)
2y 11m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 273 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month