Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
Claim Status
Claims 1-20 are pending.
Response to Arguments
Applicant’s arguments regarding the 101 rejection have been considered but are not persuasive.
The applicant argues:
Claim 1 is not directed to an abstract concept, but rather a system for controlling access to data within a networked computing environment. Claim 1 recites actions that include a "memory device," "external terminal," "database," "social networking website," and a "computer network," and also how these components interact to regulate access to stored data in a memory which is to be used for a transfer.
The Office notes that claim 1 is directed to a method and not a system. Nevertheless, while claim 1 may be directed to controlling access to data it is also directed to an abstract idea because the two are not mutually exclusive. Controlling access to data is risk mitigation. Controlling access to data in a computer network is risk mitigation applied to a particular field or environment. Regarding how the components interact, the applicant has not identified any particular interactions that indicate the claims are not directed to an abstract idea.
The steps are not merely evaluating information and making a decision, but include identifying specific data in memory, retrieving identification data from multiple heterogeneous network sources, and modifies a network security safeguard based on an analysis of the data, prior to execution of an action on the computer network. The process modifies a network and then executes an action on the modified network, which goes beyond a mental process or a commercial practice.
The Office notes that the process modifies a security safeguard within a network and not the network itself, i.e., software or instructions are modified. Again, the modification of instructions do not necessarily require a computer but for application of the modification within a particular field or environment.
Claim 1 includes a sequence of operations that cannot practically be performed in the human mind or with pen and paper. The retrieval of identification data from distributed sources such as an external terminal, database, and social networking website, and the dynamic control of access to data stored in the memory device, are steps that inherently require a computer. Thus, Applicant contends that the inquiry into the abstraction of Applicant's claims should end at this first prong as Applicant's claims do not fall into any of the enumerated groupings and therefore cannot be abstract.
The applicant fails to explain why the steps of the claim cannot be performed in the human mind, absent the recited components. The claims merely recite, receiving, computing, retrieving, generating and determining and modifying data and executing a transfer based on the modified data. These actions are appended to apply them in a computer network but can generally be performed in manual environments. The applicant does not explain why these steps inherently require a computer.
The process causes a change in system operation by changing the security safeguard on the network and then executing the transfer using the modification to the network.
The Office notes that the process causes a change in the results obtained by the system, i.e., making it harder or easier to access data through a change in security safeguards but the system, or method, itself remains the same. The method or system does not purport to improve security measures in some particular technical fashion but merely changes security measures.
Furthermore, the claimed process improves the security and operation of network-based transactions by introducing a dynamic, multi-source verification and access control mechanism. Here, a trust score is compared against a threshold derived from transaction-specific attributes. This comparison is used by the system to enforce context-sensitive access control over data to be used for the transfer. This results in a more secure and adaptive system for managing data access and network transactions.
The claims do not recite any improvement in security of the system but merely a change in the security measures. The functioning of the system itself or technology or technical field is not improved by modifying security measures because modifying security measures is an abstract idea and there is no evidence that these modifications improve the functioning of the system, technology or technical field.
The 112 rejection of the claims is withdrawn in view of the claim amendments.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claim(s) 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. The claim(s) recite(s):
1. A method comprising:
receiving a request to perform a transfer from a requesting device associated with a user;
computing a threshold trust score for accessing data stored in a memory device which is to be used for the transfer based on attributes of the transfer;
retrieving identification data associated with the user of the requesting device from an external terminal, a database, and a social networking website;
generating a list of identification data including the retrieved identification data;
determining a user trust score associated with the user of the requesting device
based on the generated list of identification data;
modifying a security safeguard of a computer network based on a comparison of
the user trust score to the threshold trust score; and
executing the transfer via the computer network based on the modified security safeguard.
The underlined elements are certain methods of organizing human activity, fundamental economic practices or principles including risk mitigation because the claims recite determining a risk level for performing a transfer and performing the transfer if the risk level is above a threshold risk level.
This judicial exception is not integrated into a practical application because the claims also recite , a memory device, a requesting device, a terminal, database and website, adding the words “apply it”, or the like, to the abstract idea. The claim(s) does/do not include additional elements that are sufficient to amount to significantly more than the judicial exception because the claims do not include more than the abstract idea and the additional elements mentioned. The requesting device merely represents the vehicle by which a requester makes the transfer request, according to the specification. The identification data and trust scores are all associated with the requester and not specifically the device, so the device is merely a tool. Claims 12 and 19 are similarly rejected but include a system and a non-transitory computer-readable medium which amount to adding the words “apply it”, or the like to the judicial exception.
The dependent claims merely narrow the abstract idea. As a whole and in combination the claims do not reflect integration into a practical application or significantly more.
Claims 2-5, 8 and 9 narrow the idea of computing, claim 6 does not further define the identification data of claim 1, and claims 7 and 10 merely perform comparing steps, all of which narrow the abstract idea. The remaining dependent claims are similar.
Conclusion
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to WILLIAM E RANKINS whose telephone number is (571)270-3465. The examiner can normally be reached on 9-530 M-F.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Bennett Sigmond can be reached on 303-297-4411. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/WILLIAM E RANKINS/Primary Examiner, Art Unit 3694