DETAILED ACTION
Office Action Summary
Claims 1-20 are pending in the instant application.
Claims 1-20 are rejected under 35 USC § 102.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale or otherwise available to the public before the effective filing date of the claimed invention.
Claims 1-20 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Biasse et al. (US Pre-Grant Publication No: 2021/0303728 A1) hereinafter referred to as Biasse.
As per claims 1, 8 and 15, Biasse teaches … deploy public key enumeration code to a plurality of endpoint devices for execution on the endpoint devices; (Biasse, figures 1 and 2, teach public key and private key and [0006], teaches receiving key)
deploy private key enumeration code to the plurality of endpoint devices for execution on the endpoint devices; (Biasse, figures 1 and 2, teach public key and private key and [0006], teaches receiving key)
collect public keys and associated public key metadata from the endpoint devices, the public keys and associated public key metadata generated by the public key enumeration code; (Biasse, figures 1 and 2, teach gathering and generating data and indicators i.e. metadata)
collect private key metadata from the endpoint devices, the private key metadata generated by the private key enumeration code; and (Biasse, figures 1 and 2, teach gathering and generating data and indicators i.e. metadata)
generate a graph illustrating trust relationships between user accounts on the endpoint devices, the graph based on the collected public keys, the collected public key metadata, and the collected private key metadata. (Biasse, figures 1 and 2, and [0006] teach generating a graph of the relationship)
As per claims 2, 9 and 16, Biasse teaches … wherein the public key enumeration code is configured to: identify user accounts on the endpoint device; locate public keys associated with each of the user accounts; and calculate a fingerprint of each of the located public keys for inclusion in the associated public key metadata. (Biasse, figure 2, teaches providing key for each device)
As per claims 3, 10 and 17, Biasse teaches … wherein the private key enumeration code is configured to: identify user accounts on the endpoint device; locate private keys associated with each of the user accounts; calculate a fingerprint of each of the located private keys for inclusion in the associated private key metadata; and determine password protection status of the located private keys for inclusion in the associated private key metadata. (Biasse, figures 1 and 2, teach gathering and generating data and indicators i.e. metadata)
As per claims 4, 11 and 18, Biasse teaches … wherein the graph comprises a plurality of nodes, each of the nodes representing one of a user account, a machine, a sub-network, or a pairing of public key and private key. (Biasse, [0020])
As per claims 5, 12 and 19, Biasse teaches … wherein the graph comprises a plurality of edges, each of the edges connecting two or more of the nodes, each of the edges representing one or more of an authorization relationship between the two or more nodes, an ownership relationship between the two or more nodes, or a presence relationship between the two or more nodes. (Biasse, figures 1 and 2, and [0006] teach generating a graph of the relationship)
As per claims 6 and 13, Biasse teaches … wherein the at least one processor is further configured to: store the plurality of nodes and the plurality of edges in a graph database; and provide access to the graph database using a graph query language. (Biasse, figures 1 and 2, and [0006] and [0008])
As per claims 7, 14 and 20, Biasse teaches … wherein the at least one processor is further configured to: provide a user interface to enable entry of a request using the graph query language; and display a requested graph, the requested graph comprising a subset of the plurality of nodes and a subset of the plurality of edges, the subset of the plurality of nodes and the subset of the plurality of edges specified by the request. (Biasse, figures 1 and 2, and [0006] and [0008] and [0054])
Other Art of Record
Agrawal et al. (US 2006/0023887 A1) teaches The figure shows a graph explaining the relationship between average private key generation (PKG) service time and new joining mobile node for different threshold values.
Mao et al. (US 20060294192 A1) teaches [0033] FIG. 3 is a network graph illustrating trust relationships among users.
Muddu et al. (US 9516053 B1) teaches (498) FIG. 46E provides additional boxes that may be associated with the “Unusual AD Activity Sequence,” in Anomaly Details view 4650. This includes “User Activities Baseline” box 4661, which illustrates the typical activities for the user that do not trigger an anomaly and the “Compare Unusual Activity with the Account's Profile” box 4662. Finally, the Anomaly Details view 4650 may include a box for “Additional Information” 4663 and an “Anomaly Graph” box 4664 illustrating the relationship between the user and the anomaly.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SIMON P KANAAN whose telephone number is (571)270-3906. The examiner can normally be reached on M-F (7AM-4PM).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Catherine Thiaw can be reached on (571) 272-1183. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/SIMON P KANAAN/Primary Examiner, Art Unit 2407