DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Status
Claims 1-15 are pending and examined herein.
Claims 1-15 are rejected.
Claims 2-8 and 14 are objected to.
Priority
Claims 1-15 are granted the claim to the benefit of priority to U.S. Provisional application 63/088061 filed 06 October 2020. Thus, the effective filling date of claims 1-15 is 06 October 2020.
Information Disclosure Statement
The information disclosure statements (IDS) were received on 28 March 2023 and 07 August 2026. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statements have been considered by the examiner.
Drawings
The drawings received 28 March 2023 are accepted.
Claim Objections
Claims 2-8 and 14 are objected to because of the following informalities:
Claims 2-4 recite “further comprising the step of…” in line 1 of the claims but should read “further comprising a step of…” or “further comprising…”.
Claim 5 recites “further comprising the steps of…” in line 1 of the claim but should read “further comprising steps of…” or “further comprising…”.
Claim 6 recites “further comprising the steps for data integrity verification…” in lines 1-2 of the claim, claim 7 recites “further comprising the steps for data retrieval…” in lines 1-2 of the claim, and claim 8 recites “further comprising the steps for data update…” in lines 1-2 of the claim but should read “further comprising steps for data integrity verification of…” (in claim 6), “further comprising steps for data retrieval of…” (in claim 7), and “further comprising steps for data update of…” (in claim 8).
Claims 7 and 14 recite “an annotation able” in line 3 of claim 7 and line 2 of claim 14 but should read “an annotation table”.
Appropriate correction is required.
Claim Interpretation
Claim 7 recites “checking whether the user has sufficient access privilege if any part of the selected data components and/or regions is encrypted, and retrieving, if authenticating determines that the user has sufficient access privilege, a decryption key and decrypting each of the encrypted data components and/or regions, optionally performing data integrity verification, and presenting the retrieved data and any associated signature and/or verification results” which are contingent limitations because the step of “checking…” is contingent on the condition of “any part of the selected data components and/or regions is encrypted” being met and the steps of “retrieving…”, “optionally performing data integrity verification”, and “presenting the retrieved data and…” are contingent on the condition of “the user has sufficient access privilege” being met . The MPEP states at 2111.04(II) “The broadest reasonable interpretation of a method (or process) claim having contingent limitations requires only those steps that must be performed and does not include steps that are not required to be performed because the condition(s) precedent are not met.” The BRI of method claim 7 only requires the steps of “identifying any selected data components and/or regions in an annotation table on which encryption has been applied” and “authenticating a user that requested data retrieval”.
Claim 14 recites “checking whether the user has sufficient access privilege if any part of the selected data components and/or regions is encrypted and retrieve, if authenticating determines that the user has sufficient access privilege, a decryption key and decrypting each of the encrypted data components and/or regions, optionally perform data integrity verification, and present the retrieved data and any associated signature and/or verification results” which are contingent limitations for the reasons discussed above with regard to method claim 7. The MPEP states at 2111.04(II) “The broadest reasonable interpretation of a system (or apparatus or product) claim having structure that performs a function, which only needs to occur if a condition precedent is met, requires structure for performing the function should the condition occur. The system claim interpretation differs from a method claim interpretation because the claimed structure must be present in the system regardless of whether the condition is met and the function is actually performed.” The BRI of system claim 14 requires a system having structure to perform these functions should the condition occur (i.e., the system claim requires structure for performing the functions of “checking…”, “retrieve…”, “optionally perform data integrity verification”, and “present the retrieved data…”.
Claim Rejections - 35 USC § 112
112/b
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 6, 8, 9, 11, and 13-15 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claims 6 and 13 recite “the signature information” in line 7 of claim 6 and lines 4 in claim 13. There is insufficient antecedent basis for this limitation in the claim. The indefiniteness arises because the claim does not make clear what “the signature information” is referring to in the claims. For the sake of furthering examination, this limitation in claims 6 and 13 will be interpreted as “presenting signature information”.
Claims 8 and 15 recites the limitation “the obsolete ones” in line 6 of claim 8 and lines 4-5 in claim 15. There is insufficient antecedent basis for this limitation in the claim. The indefiniteness arises because the claim does not make clear what “the obsolete ones” is referring to in the claims. Further, the limitation of “the obsolete ones” is relative and the instant disclosure does not provide an objective standard for measuring the scope of obsolete digital signatures (i.e., standards or conditions that are met for a digital signature to become obsolete). Dependent claim 9 is rejected by virtue of its dependency on a rejected claim without alleviating the indefiniteness. For the sake of furthering examination, claims 8 and 15 will be interpreted as “generating new digital signatures on the updated data”.
Claims 8 and 15 recites “compressing the updated data components and/or payload blocks as needed” which renders the metes and bounds of the claim indefinite. The indefiniteness arises because it is unclear if “compressing the updated data components and/or payload blocks” is required by the claims. The phrase “as needed” is subjective/relative and the instant disclosure does not provide an objective standard for measuring the scope of “as needed”. Dependent claim 9 is rejected by virtue of its dependency on a rejected claim without alleviating the indefiniteness. For the sake of furthering examination, claims 8 and 15 will be interpreted as being an optional limitation and not requiring compressing the updated data components and/or payload blocks.
Claim 11 recites “and optionally compress or decompress, individual data components and payload blocks of the genomic data…”, claim 13 recites “optionally providing scope of applicability, signer ID and signing data and time, together with the signature information” and claim 14 recites “optionally perform data integrity verification” which renders the metes and bounds of the claim indefinite. The indefiniteness arises because it is unclear if the system of claims 11, 13 and 14 requires the structure to perform these functions recited in the claims (i.e., the structure to perform these functions is required by the system but the performance of the function is optional) or if the structure itself is meant to be an alternative/optional embodiment of the system (i.e., the structure to perform these functions are an optional structure of the system and is not required). For the sake of furthering examination, “optionally…” in claims 11, 13, and 14 will be interpreted as the structure to perform these functions are an optional structure of the system and are not required.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-15 are rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception (i.e., a law of nature, a natural phenomenon, or an abstract idea) without significantly more.
(Step 1)
Claims 1-9 fall under the statutory category of a process and claims 10-15 fall under the statutory category of a machine.
(Step 2A Prong 1)
Under the BRI, the instant claims recite judicial exceptions that are an abstract idea of the type that is in the grouping of a “mental process”, such as procedures for evaluating, analyzing or organizing information, and forming judgement or an opinion. The instant claims further recite judicial exceptions that are an abstract idea of the type that is in the grouping of certain methods for organizing human activity.
Independent claims 1 and 10 recite mental processes of generating a protection metadata structure for the genomic dataset comprising one or more of: (i) specifications for selective encryption of one or more data components and regions of genomic data in an annotation table, (ii) specifications for selective signing of one or more data components and regions of genomic data in the annotation table, and (ii) user key information and compressing the genomic data and the protection metadata structure using one or more compression algorithms to generate a compressed genomic dataset and compressed protection metadata structure. It is noted for claim 10, that the genomic dataset comprising genomic data of one or more of a plurality of fields or attributes of different data types and the data compression algorithm falls under the abstract idea.
Dependent claims 2 and 11 recite a mental process of encrypting or decrypting, and optionally compressing or decompressing, individual data components and payload blocks of the genomic data. Dependent claim 3 recites a mental process of selecting one or more data components or payload blocks of specific regions of the genomic data in an annotation table, comprising an identification of one or more data component ID, range of row and column index, range of genomic coordinates, and sample ID for the application of encryption and/or digital signature. Dependent claim 4 recites mental processes of detecting any overlap among the selected data components or regions in the annotation table, automatically removing, detected overlap from the selected data components or regions to ensure each data component or payload block is encrypted not more than once. Dependent claim 5 recites mental processes of ordering, concatenating, and serializing the selected data components and payload blocks in the annotation table for the generation/verification of digital signature. Dependent claims 6 and 13 recite mental processes of extracting all digital signatures generated for the selected data components and/or regions in the annotation table, retrieving a verification key and verifying each of the extracted digital signatures. Dependent claims 7 and 14 recite mental processes of identifying any selected data components and/or regions in an annotation table on which encryption has been applied, authenticating a user that requested data retrieval, and checking whether the user has sufficient access privilege if any part of the selected data components and/or regions is encrypted, retrieving, if authenticating determines that the user has sufficient access privilege, a decryption key and decrypting each of the encrypted data components and/or regions, optionally performing data integrity verification. Dependent claims 8 and 15 recite mental process of identifying any data components and/or regions being updated that were previously encrypted and/or signed, reapplying encryption on the updated data that were previously encrypted, generating new digital signatures on the updated data, and compressing the updated data components and/or payload blocks. Dependent claim 9 recites an abstract idea of certain methods for organizing human activity of locking of selected data components and payload blocks protected by digital signatures to allow only authenticated users with sufficient access privileges to update the protected data.
The claims recite mental processes of analyzing/evaluating information and organizing information as generating a protection metadata structure for the genomic dataset with specifications for selective encryption, specifications for selective signing and user key information (which encompasses organizing these specifications and user key information in a particular data structure to hold this information), compressing genomic data and protection metadata using one or more compression algorithms (which encompasses any compression algorithm to reduce the data into a compressed form through encoding a representation of the data in a shorter form), encrypting or decrypting information (which encompasses representing the data in a scrambled form through a process reorganizing the data with a set of rules and decoding the data through a process which reverses the scrambled form of the data), selecting data through identification for the process of encryption and signing (which encompasses an observation and judgment of selecting certain data to apply encryption or signing to), detecting overlap and removing the detected overlap (which encompasses organizing data through splitting data into regions and observing overlaps in the splits and removing these overlaps), ordering, concatenating, and serializing the selected data components and payload blocks (which encompasses organizing this data by ordering and concatenation while manipulating the data into a particular representation of a stream of text information), extracting all digital signatures generated for the selected data components and/or regions in the annotation table (which encompasses making observations on the data to extract relevant information), retrieving a verification key and verifying each of the extracted digital signatures (which encompasses making observations and judgments through retrieving relevant information for verification and making a judgment of verifying digital signatures), identifying any selected data components and/or regions in an annotation table on which encryption (which encompasses making an observation and judgment on data), authenticating a user that requested data retrieval and checking whether the user has sufficient access privilege if any part of the selected data components and/or regions is encrypted (which encompasses making a judgment on relevant information), retrieving, if authenticating determines that the user has sufficient access privilege, a decryption key and decrypting each of the encrypted data components and/or regions (which encompasses making an observation/judgment to retrieve relevant information of a description key and analyzing/evaluating the data to perform decryption), optionally performing data integrity verification (which encompasses making a judgment on the data to verify the integrity of the data), identifying any data components and/or regions being updated that were previously encrypted and/or signed (which encompasses an observation and judgment of the data components), reapplying encryption on the updated data that were previously encrypted (which encompasses representing the data in a scrambled form through a process reorganizing the data with a set of rules), generating new digital signatures on the updated data (which encompasses making a judgment to generate new digital signatures on the data), and compressing the updated data components and/or payload blocks (which encompasses representing the data in a compact form).
The claims recite an abstract idea of certain methods for organizing human activity of locking of selected data components and payload blocks protected by digital signatures to allow only authenticated users with sufficient access privileges to update the protected data (which encompasses managing personal behavior by restricting access to certain data to only be accessible to a certain group of authenticated users with sufficient access privileges).
Thus, claims 1-15 recite abstract ideas.
(Step 2A Prong 2)
Claims found to recite a judicial exception under Step 2A, Prong 1 are then further analyzed to determine if the claims as a whole integrate the recited judicial exception into a practical application or not (Step 2A, Prong 2). Integration into a practical application is evaluated by identifying whether there are any additional elements recited in the claim and evaluating those additional elements to determine whether they integrate the exception into a practical application.
The additional elements in claim 1 of receiving a genomic dataset comprising genomic data of one or more of a plurality of fields or attributes of different data does not integrate the judicial exceptions into a practical application because this additional element constitutes as insignificant extra solution activity of data gathering. This additional element constitutes as data gathering because it only interacts with the judicial exceptions by providing data to the judicial exceptions to process. It is noted that the claim encompasses receiving data in a computer environment and the content of the data being received does not change the active step of receiving data in a computer environment.
The additional element in claim 4 of notifying a user does not integrate the judicial exceptions into a practical application because this constitutes as insignificant extra solution activity of outputting data. Further, this additional element does not integrate the judicial expectations into a practical application because this limitation encompasses being recited in the alternative form and thus is not required by the claim.
The additional element in claims 6 and 13 of presenting the signature information, optionally providing scope of applicability, signer ID and signing data and time, together with the signature information and the additional element in claims 7 and 14 of presenting the retrieved data and any associated signature and/or verification results does not integrate the judicial exceptions into a practical application because these steps constitute as insignificant extra solution activity of outputting data. These additional elements constitutes as data gathering because it only interacts with the judicial exceptions by outputting the data of the judicial exceptions. It is noted that the claim encompasses outputting data in a computer environment and the content of the data being outputted does not change the active step of outputting data in a computer environment.
The additional element in claim 1 of storing the compressed genomic dataset and the compressed protection in a container data structure in memory, the additional element in claim 8 of storing the updated data and/or digital signatures in the annotation table, the additional element in claim 10 of a data structure configured to store genomic data and store the compressed genomic dataset and the compressed protection metadata structure in the data structure do not integrate the judicial exceptions into a practical application because these additional elements constitute as insignificant extra solution activity of outputting/storing data (see MPEP 2106.05(g)). These additional elements only interact with the judicial exceptions in a manner which outputs/stores the processed data produced by the judicial exceptions. It is noted that the content of the data falls under the abstract idea itself and does not change the active step of storing information in a computer environment.
The additional element in claim 10 of using a generic computer (i.e., a processor and memory) to perform judicial exceptions does not integrate the judicial exceptions into a practical application because this is applying the judicial exceptions to a generic computer without an improvement to computer technology (see MPEP 2106.04(d)(1)).
Thus, the additional elements do not integrate the judicial exceptions into a practical application and claims 1-15 are directed to the abstract idea.
(Step 2B)
Claims found to be directed to a judicial exception are then further evaluated to determine if the claims recite an inventive concept that provides significantly more than the judicial exception itself (Step 2B). The claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception because:
The additional elements in claims 1 of receiving data and the additional elements in claims 6, 7, 13, and 14 of outputting data are conventional as shown by MPEP 2106.05(b) and 2106.05(d)(II).
The additional element in claim 4 of notifying a user does not amount to significantly more than the judicial exception because this limitation encompasses being recited in the alternative form and thus is not required by the claim.
The additional elements in claims 1, 8, and 10 of storing data in a container data structure, storing in a table, and a data structure configured to store genomic data is conventional as shown on page 4 of Alberti et al. (bioRxiv (2018): 426353), page 77 of Delgado et al. (STC 2019: Special Topic Conference: ICT for Health Science Research, Studies in Health Technology and Informatics: proceedings of the EFMI 2019 Special Topic Conference. IOS Press, 2019), and page 3 Figure 2 and page 6 Figure 3 of Chandak et al. (MPEG Meeting; 20200113-20200117; Brussels, no. m52159 08 January 2020; cited in IDS received 28 March 2023).
The additional element in claim 10 of using a generic computer (i.e., processor and memory) to perform judicial exceptions (i.e., a processor) is conventional as shown by MPEP 2106.05(b) and MPEP 2106.05(d)(II).
Thus, the additional elements are not sufficient to amount to significantly more than the judicial exception because they are conventional.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless – (a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claims 1-3, 5, and 10-12 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Cheung et al. (MPEG meeting; 20200420-20200424; Alpbach, no. m533818 April 2020; cited in IDS received 28 March 2023).
Independent claim 1 is directed to method for storing genomic data within a data structure comprising a file structure, the method comprising: receiving a genomic dataset comprising genomic data of one or more of a plurality of fields or attributes of different data,
Cheung et al. shows storing genomic data (such as genomic annotation data, gene expressions, and genomic functional annotation data) within a data structure of a file structure (Cheung et al. page 2 first paragraph).
generating a protection metadata structure for the genomic dataset, comprising one or more of: (i) specifications for selective encryption of one or more data components and regions of genomic data in an annotation table, (ii) specifications for selective signing of one or more data components and regions of genomic data in the annotation table, and (iii) user key information
Cheung et al. shows a table protection box containing protection information associated with a table to support confidentiality (encryption), integrity verification (digital signature) and access control policy enforcement on selected regions of the Table required by the user (Cheung et al. section 6.4.2.4.1). Cheung et al. shows a protection metadata structure for a genomic dataset as TB_protection_value() which contains compressed protection metadata that includes encryption parameters and digital signatures which is interpreted as specifications of selective encryption and selective signing (Cheung et al. page 25 section 6.4.2.4.3). Cheung et al. shows users may define the attributes and chunks on which a privacy rule is applied and that any number of XML signature elements can be present in the table protection box and shall use a URI to specify attributes and chunks associated with each signature (Cheung et al. page 25 section 6.4.2.4.3).
compressing the genomic data and the protection metadata structure using one or more compression algorithms to generate a compressed genomic dataset and compressed protection metadata structure
Cheung et al. shows compressing the genomic data as independently compressing attributes of data in an annotation table (Cheung et al. page 8 para. 1-3, page 8 Figure 2, and page 8 Figure 3). Cheung et al. shows the protection metadata is compressed (Cheung et al. page 25 section 6.4.2.4.3).
and storing the compressed genomic dataset and the compressed protection metadata structure in a container data structure in memory
Cheung et al. shows storing the compressed genomic dataset as table data blocks which groups and organizes the compressed payloads (which is genomic data from the attribute table) and the compressed protection metadata structure in a container data structure in memory as shown the table container structure which holds compressed genomic annotation data and compressed protection metadata inside the table protection box (Cheung et al. page 10 Figure 6, page 11 full page, page 11 Figure 7, page 14 Figure 9, and page 25 section 6.4.2.4.3).
Claim 10 is directed to a system for storing genomic data within a data structure comprising a file structure, the system comprising: a genomic dataset comprising genomic data of one or more of a plurality of fields or attributes of different data types, a data structure configured to store genomic data, a data compression algorithm,
Cheung et al. shows storing genomic data (such as genomic annotation data, gene expressions, and genomic functional annotation data) within a data structure of a file structure (Cheung et al. page 2 first paragraph). Cheung et al. shows a data structure configured to store the genomic data (Cheung et al. page 14 Figure 9). Cheung et al. shows a data compression algorithm (Cheung et al. page 22).
and a processor configured to: (i) generate a protection metadata structure for the genomic dataset, comprising one or more of: (1) specifications for selective encryption of one or more data components and regions of genomic data in an annotation table; (2) specifications for selective signing of one or more data components and regions of genomic data in the annotation table; and (3) user key information;
Cheung et al. shows a table protection box containing protection information associated with a table to support confidentiality (encryption), integrity verification (digital signature) and access control policy enforcement on selected regions of the Table required by the user (Cheung et al. section 6.4.2.4.1). Cheung et al. shows a protection metadata structure for a genomic dataset as TB_protection_value() which contains compressed protection metadata that includes encryption parameters and digital signatures which is interpreted as specifications of selective encryption and selective signing (Cheung et al. page 25 section 6.4.2.4.3). Cheung et al. shows users may define the attributes and chunks on which a privacy rule is applied and that any number of XML signature elements can be present in the table protection box and shall use a URI to specify attributes and chunks associated with each signature (Cheung et al. page 25 section 6.4.2.4.3).
(ii) compress, using the data compression algorithm, the genomic data and the protection metadata structure to generate a compressed genomic dataset and compressed protection metadata structure;
Cheung et al. shows compressing the genomic data as independently compressing attributes of data in an annotation table (Cheung et al. page 8 para. 1-3, page 8 Figure 2, and page 8 Figure 3). Cheung et al. shows the protection metadata is compressed (Cheung et al. page 25 section 6.4.2.4.3).
and (iii) store the compressed genomic dataset and the compressed protection metadata structure in the data structure.
Cheung et al. shows storing the compressed genomic dataset as table data blocks which groups and organizes the compressed payloads (which is genomic data from the attribute table) and the compressed protection metadata structure in a container data structure in memory as shown the table container structure which holds compressed genomic annotation data and compressed protection metadata inside the table protection box (Cheung et al. page 10 Figure 6, page 11 full page, page 11 Figure 7, page 14 Figure 9, and page 25 section 6.4.2.4.3).
Claims 2 and 11 are directed to encrypting or decrypting, and optionally compressing or decompressing, individual data components and payload blocks of the genomic data to facilitate random access.
Cheung et al. shows users may define the attributes on which a privacy rule is applied (Cheung et al. page 25 section 6.4.2.4.3). It is interpreted that the when applying a privacy rule to individual data components (attributes) that the payload blocks of the attributes also have the privacy rule applied. Cheung et al. shows the chunk structure allows for optimum random-access performance (Cheung et al. page 41 section 7.8).
Claims 3 and 12 are directed to selecting one or more data components or payload blocks of specific regions of the genomic data in an annotation table, comprising an identification of one or more of data component ID, range of row and column index, range of genomic coordinates, and sample ID for the application of encryption and/or digital signature.
Cheung et al. shows selecting one or more data components of specific regions of the genomic data in an annotation table as dividing the data into chucks with an identification of range of row and column index (Cheung et al. page 8 para 1-3, and page 9 Figure 4). Cheung et al. shows users may define the chucks on which a privacy rule is applied (Cheung et al. page 25 section 6.4.2.4.3). It is noted that the limitation of for the application of encryption and/or digital signature is interpreted as being an intended use of the process of selecting data components.
Claim 5 is directed to ordering, concatenating, and serializing the selected data components and payload blocks in the annotation table for the generation/verification of digital signature.
Cheung et al. shows table data blocks which groups and organizes compressed payloads and for attribute contiguity a block contains payloads of the same attribute ordered by their chunk indices (Cheung et al. page 11 para. 5). Cheung et al. shows the concatenating the payload blocks which are grouped by data components (i.e., attributes to which the payloads belong) (Cheung et al. page 12 section 5.2.4). Cheung et al. shows that the payloads which represent the attributes are represented as bytes which is produced by serializing the data in the date structure (i.e., representing an object in a data structure in the form of bytes or strings) (Cheung et al. page 34 last paragraph). It is noted that the limitation of for the generation/verification of digital signature is interpreted as being an intended use of the process of ordering, concatenating and serializing.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim 4 is rejected under 35 U.S.C. 103 as being unpatentable over Cheung et al. as applied to claims 3 under 35 U.S.C. 102 above, and further in view of Chandak et al. (MPEG Meeting; 20200113-20200117; Brussels, no. m52159 08 January 2020; cited in IDS received 28 March 2023).
Claim 4 is directed to detecting any overlap among the selected data components or regions in the annotation table, and notifying a user of, and/or automatically removing, detected overlap from the selected data components or regions to ensure each data component or payload block is encrypted not more than once.
Cheung et al. shows for supporting selective data access the data is divided into rectangular regions known as chunks, each of which with independent compressor configurations for optimum performance (Cheung et al. page 8 para. 1-3).
Cheung et al. does not show detecting any overlap among the selected data components or regions in the annotation table, and notifying a user of, and/or automatically removing, detected overlap.
Like Cheung et al., Chandak et al. shows dividing attributes of an annotation table into chunks. Chandak et al. shows a requirement that chunks must cover the entire range of indices without overlapping which implicitly shows the removal of detected overlap due to requiring chunks to not overlap (Chandak et al. page 11 para. 3).
It would have been obvious to one of ordinary skill in the art before the effective filling date of the invention to have substituted the generation of chucks of Cheung et al. with the generation of chunks which require non-overlapping chunks of Chandak et al. because both Cheung et al. and Chandak et al. shows generating chunks of attributes that are independently compressed and would lead to predictable results of generating chunks of attributes which require the chunks to not contain overlaps in attribute data.
Claims 6 and 13 are rejected under 35 U.S.C. 103 as being unpatentable over Cheung et al. as applied to claims 3 and 10 under 35 U.S.C. 102 above, and further in view of Pooja et al. (International Journal of Scientific Research in Computer Science, Engineering and Information Technology (IJSRCSEIT) 3.6 (2018): 71-75).
Claims 6 and 13 are directed to data integrity verification of: extracting all digital signatures generated for the selected data components and/or regions in the annotation table;
Cheung et al. shows using digital signatures for integrity verification (Cheung et al. page 25 section 6.4.2.4.1). Cheung et al. shows that any number of signature elements can be present in in the table protection box and shall use a URI to specify the attributes and chunks associated with each signature (Cheung et al. page 25 section 6.4.2.4.3).
Cheung et al. does not explicitly show retrieving a verification key and verifying each of the extracted digital signatures and presenting signature information, optionally providing scope of applicability, signer ID and signing date and time, together with the signature information.
Like Cheung et al., Pooja et al. shows digital signatures for data integrity verification. Pooja et al. shows retrieving a verification key and verifying digital signatures (Pooja et al. page 72 left col.- right col.). Pooja et al. further shows presenting information of whether the verification process was successful or unsuccessful based on a comparison of values produced by the verification process (Pooja et al. page 72 right col.). The BRI of the claims does not require providing scope of applicability, signer ID and signing data and time, together with the signature information because it is recited as an optional limitation.
It would have been obvious to one of ordinary skill in the art before the effective filling date of the invention to have combined the data structure which relies on digital signatures for data integrity verification of Cheung et al. with the process of verifying digital signatures of Pooja et al. because this would allow for a process which utilizes the digital signatures associated data to check/verify the integrity of the data which is signed by the digital signatures (Pooja et al. page 72 right col.). One would have a reasonable expectation of success because Cheung et al. shows digital signatures associated with different parts of the data stored in the container data structure while Pooja et al. shows the ability to user digital signatures for verify data integrity.
Claims 7 and 14 are rejected under 35 U.S.C. 103 as being unpatentable over Cheung et al. as applied to claims 1 and 10 under 35 U.S.C. 102 above, and further in view of Naro et al. (“Security strategies in genomic files”, 11 February 2020; cited in IDS received 28 March 2023).
Claims 7 and 14 are directed to further comprising the steps for data retrieval: identifying any selected data components and/or regions in an annotation table on which encryption has been applied;
Cheung et al. shows a data storage file structure which provides selective encryption on data components and regions of an annotation table (Cheung et al. page 25 section 6.4.2.4.3).
Cheung et al. does not show a data retrieval process which identifies parts of the annotation table which encryption has been applied, authenticating a user that requested data retrieval, and checking whether the user has sufficient access privilege if any part of the selected data components and/or regions is encrypted and retrieving, if authenticating determines that the user has sufficient access privilege, a decryption key and decrypting each of the encrypted data components and/or regions, optionally performing data integrity verification, and presenting the retrieved data and any associated signature and/or verification results.
Naro et al. shows data retrieval which comprises receiving a request determining if the requested information is encrypted (Naro et al. page 83-84 section 8.2). Naro et al. shows authenticating a user by checking whether a particular use of data is permitted in a given situation by authenticating a user by receiving a request data retrieval and checks if the user has access privilege of requested encrypted data (Naro et al. page 94 and page 94 Figure 8.7). Naro et al. shows a process of retrieving a decryption key for authorized recipients (Naro et al. page 56 section 7.2.2.3). Naro et al. shows decrypting of the encrypted requested information (Naro et al. page 84 in section 8.2). The BRI of the claims does not require the step of performing data integrity verification because it is recited as being an optional limitation. Naro et al. shows presenting the information as decoding the requested information (Naro et al. page 84 in section 8.2).
An invention would have been obvious to one or ordinary skill in the art if some motivation in the prior art would have led that person to combine reference teachings to arrive at the claimed invention. It would have been obvious to one of ordinary skill in the art before the effective filling date of the invention to have combined the storage data structure of Cheung et al. with the process of data retrieval which utilizes mechanisms for authenticating users when data is encrypted of Naro et al. because this would allow for a process and system which stores data in a data structure which is encrypted at various levels to provide selective access to certain data and a process of retrieving certain stored data by checking if the user requesting the protected data has sufficient access privileges (Naro et al. page 94 and page 94 Figure 8.7). One would have a reasonable expectation of success because Cheung et al. provides a data structure for protecting data at various levels to provide confidentiality of aspects of data through encryption while Naro et al. shows a data retrieval process for encrypted data which is stored.
Claims 8, 9, and 15 are rejected under 35 U.S.C. 103 as being unpatentable over Cheung et al. as applied to claims 1 and 10 under 35 U.S.C. 102 above, and further in view of Qin et al. (ACM Transactions on Storage (TOS) 13.1 (2017): 1-30).
Claims 8 and 15 are directed to identifying any data components and/or regions being updated that were previously encrypted and/or signed,
Cheung et al. shows the tables include table protection which contains protection information associated with the table to support confidentiality (encryption), integrity verification (digital signatures) (Cheung et al. page 25 section 6.4.2.4.1). Cheung et al. shows users may define the attributes, chunks, genomic regions, and ranges of table indices on which a privacy rule is applied (Cheung et al. page 25 section 6.4.2.4.3 para. 2). Cheung et al. further shows table protection metadata with encryption parameters, privacy policy and digital signatures (Cheung et al. page 25 section 6.4.2.4.3 para. 1). This information present in the table provides the identification of data components and/or regions that are encrypted and/or signed.
Cheung et al. does not show updating data, reapplying encryption on the updated data that were previously encrypted, generating new digital signatures on the updated data, optionally compressing the updated data components and/or payload blocks, and storing the updated data and/or digital signatures in the annotation table
Like Cheung et al., Qin et al. shows a storage system which relies on encryption to provide selective access to certain stored data. Qin et al. shows updating and uploading new files into a storage system (Qin et al. page 7 section 3.3). Qin et al. shows a process of rekeying which prevents revoked users from accessing any new file or update which is a process of re-encrypting (Qin et al. page 7 section 3.3). Qin et al. shows the process of generating keys which includes generating an RSA signature (i.e., digital signature) (Qin et al. page 14 section 5.1). Qin et al. shows storing the updated data (Qin et al. page 7 section 3.3). The BRI of the claims do not require compressing the updated data because it is interpreted as being an optional limitation.
Claim 9 is directed to locking of selected data components and payload blocks protected by digital signatures to allow only authenticated users with sufficient access privileges to update the protected data.
Cheung et al. shows users may define the attributes, chunks, genomic regions, and ranges of table indices on which a privacy rule is applied and any number of XML signature elements can be present in the Table Protection box and shall use a URI to specify the attributes and chunks associated with each signature (Cheung et al. page 25 section 6.4.2.4.3).
An invention would have been obvious to one or ordinary skill in the art if some motivation in the prior art would have led that person to modify reference teachings to arrive at the claimed invention. It would have been obvious to one of ordinary skill in the art before the effective filling date of the invention to have modified the storage process and system of Cheung et al. which relies on access control processes of encryption and digital signatures with the process and system which provides steps for re-encryption and signature generation of updated files of Qin et al. because this would allow for the ability of revoking users from accessing any new file or update to files to preserve confidentiality of new data that is stored (Qin et al. page 7 section 3.3). One would have a reasonable expectation of success because Cheung et al. and Qin et al. both show storage systems which utilize encryption and digital signatures to protect data from unauthorized access.
Conclusion
No claims are allowed.
This Office action is a Non-Final action. A shortened statutory period for reply to this action is set to expire THREE MONTHS from the mailing date of this action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to JONATHAN EDWARD HAYES whose telephone number is (571)272-6165. The examiner can normally be reached M-F 9am-5pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Olivia Wise can be reached at 571-272-2249. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/JONATHAN EDWARD HAYES/Examiner, Art Unit 1685