CTNF 18/101,043 CTNF 89379 DETAILED ACTION 07-03-aia AIA 15-10-aia The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA. This Office Action is in response to Application No. 18/101,043 filed on 01/24/2023. Claims 1-20 have been examined and are pending in this application. Information Disclosure Statement The information disclosure statement (IDS), submitted on 01/24/2023, is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Claim Rejections - 35 USC § 103 07-20-aia AIA The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 07-06 AIA 15-10-15 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. 07-21-aia AIA Claim (s) 1-2, 4, 6, 9-10, 12, 14, 17-18, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Jain et al. (US 2022/0391927; Hereinafter “Jain”) in view of Fleck et al. (WO 2019/213536; Hereinafter “Fleck”) . Regarding claim 1 , Jain teaches an apparatus comprising: a processor configured to receive a request to modify a software artifact stored on a host platform; query a database based on a user identifier associated with the request to retrieve historical communications of a user from the database (Jain: Para. [0022], receive from an endpoint device account identifiers for a plurality of online accounts associated with a user, and respective usage contexts for the plurality of online accounts; analyze the usage contexts to determine respective periodicities of user interaction for the online accounts.) ; execute an artificial intelligence (Al) model based on the historical communications to determine whether the user is authorized to modify the software artifact (Jain: Para. [0065], Client scanner 228 may include a number of distributed scanners, each responsible for collecting and scanning and locally processing one or more digital trails to discover user online accounts. These online account scanners scan their respective digital trails, which may include, by way of illustrative and nonlimiting example, short messaging service (SMS), email, email headers, stored password (which may include both login information and autofill data), web activities, browser logs, phone logs, and/or internet chat services such as Jabber, IRC, ICQ, XMPP, Slack, Nextcloud, ownCloud or others. These scanners may distinguish personal, marketing, and account-related items. For example, a scanner may have an ability, such as via a process or machine-learning (ML) model, to distinguish personal, marketing, and account-related activities using various features. These features can include, for example, known senders, name and email address, interaction periodicity, communication type, and others. In some cases, to preserve user privacy, a scanner may scan only metadata, such as email headers or metadata about transactions, such as sender, receiver, and time of the message. Jain: Para. [0082], Thus, cloud service 204 may partner with human actors who can perform some of the human intervention steps with the permission and verification of the end-user.) ; and prevent the request to modify the software artifact from being performed to the software artifact (Jain: Para. [0082], Thus, cloud service 204 may partner with human actors who can perform some of the human intervention steps with the permission and verification of the end-user. In other cases, cloud service 204 provides to the user, via client device 202, instructions for deleting accounts, such as via websites or apps provided by the account providers.) . Jain does not explicitly teach in response to a determination that the user is not authorized, prevent the request to modify the software artifact from being performed to the software artifact. In an analogous art, Fleck teaches execute an artificial intelligence (Al) model based on the historical communications to determine whether the user is authorized to modify the software artifact (Fleck: Para. [0154], The policy may specify which applications accessed via the CEB, which device types running the CEB, which user accounts, and/or which location at which the client running the CEB, among other considerations, have permission to the data maintained on the secure container. The policy may also specify whether sensitive information contained the data is to be removed, even if there is permission to access. [user account with permission to the data meets the user is or is not authorized limitation]) ; in response to a determination that the user is not authorized, prevent the request to modify the software artifact from being performed to the software artifact (Fleck: Para. [0007], The policy may specify which applications accessed via the CEB, which device types running the CEB, which user accounts, and/or which location at which the client running the CEB, among other considerations, have permission to the data maintained on the secure container. [user account with permission to the data meets the user is or is not authorized limitation] Para. [0008], If the data is permitted to be replicated in the second application under the policy, the IPC manager may determine whether a portion of the data is to be removed (e.g., via redaction or deletion) prior to the replication. The policy may also specify an information type of the data is to be removed prior to replication onto the second application. The IPC manager may parse the data to identify whether a portion of the data matches the information type specified by the policy. The IPC manager may remove the portion matching the information type specified by the policy. The IPC manager may subsequently replicate the data with the portion removed on the second application. Para. [0010], In some embodiments, the method may include determining, in accordance to the application of the policy, whether to restrict a replication of the data stored in the secure container onto a second network application of the plurality of network applications. Para. [0011], the method may include presenting, via the embedded browser, a prompt indicating a restriction of replication, responsive to determining to restrict the replication of the data.) . It would have been obvious to a person having ordinary skill in the art, before the effective filing date of the claimed invention, to combine the teachings of Fleck with the system and method of Jain to include in response to a determination that the user is not authorized, prevent the request to modify the software artifact from being performed to the software artifact because this functionality provides for methods of preventing data loss (Fleck: Para. [0002]). Regarding claim 2 , Jain, in combination with Fleck, teaches the apparatus of claim 1, wherein the request comprises a request to delete the software artifact from a data store of the host platform, and the processor is configured to execute the Al model to determine whether the user is authorized to delete the software artifact based on frequency of communications associated with the software artifact within the historical communication (Fleck: Para. [0007], [removed data meets delete the software artifact limitation]; Para. [0172], The data analysis engine 1140 may use a model to identify the one or more portions of the data 1125 to be altered or removed. In some embodiments, the model may be part of a natural language processing algorithm. The model may include formats or regular expressions for the predefined types of information. In some embodiments, the model may include an artificial neural network with one or more weights. Para. [0069], Client scanners 228 may also use historical analysis to identify the frequency or periodicity with which the user interacts with the service. For example, some services the users may interact with daily, while others may interact with on a weekly, biweekly, monthly, yearly, or other schedule. Client scanners 228 may access SMS or email or web activities related to each unique sender. In some cases, SMS, email, or other may be used to identify second-factor authentication prompts for logins. For example, a password reset email or one-time password (OTP) may be identified and correlated to active account use. A password manager log may also provide historical intervals of password updates for each unique sender. [frequency of a key word such as password])) . Regarding claim 4 , Jain, in combination with Fleck, teaches the apparatus of claim 1, wherein the software artifact is hosted within a tenant environment of the host platform (Fleck: Para. [0005], A client application with an embedded browser (CEB) may be used to access applications and resources hosted on various servers. These applications may include, for example, web applications accessed via the browser, cloud hosted applications (e.g., as part of Software as a Service (SaaS), Infrastructure as a Service (IaaS), and Platform as a Service (PaaS)), and virtual applications hosted on a virtual machine, among others) , and the processor is configured to query one or more of a meeting application, an email application, a call log, and a chat application, within the tenant environment, to retrieve historical communications of the user (Fleck: Para. [0050], The secure applications may be email applications, web browsing applications, software-as-a-service (SaaS) access applications, Windows Application access applications, and the like.) . Regarding claim 6 , Jain, in combination with Fleck, teaches the apparatus of claim 1, wherein the processor is configured to execute the Al model to identify the software artifact associated with the request (Fleck: Para. [0172], The data analysis engine 1140 may use a model to identify the one or more portions of the data 1125 to be altered or removed. In some embodiments, the model may be part of a natural language processing algorithm. The model may include formats or regular expressions for the predefined types of information. In some embodiments, the model may include an artificial neural network with one or more weights.) . Regarding claims 9-10 , Claims 9-10 are rejected under the same rational as claims 1-2, respectively. Regarding claim 12 , Claim 12 is rejected under the same rational as claim 4. Regarding claim 14 , Claim 14 is rejected under the same rational as claim 6. Regarding claims 17-18 , Claims 17-18 are rejected under the same rational as claims 1-2, respectively. Regarding claim 20 , Claim 20 is rejected under the same rational as claim 4 . 07-21-aia AIA Claim (s) 3, 7, 11, 15, and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Jain et al. (US 2022/0391927; Hereinafter “Jain”) in view of Fleck et al. (WO 2019/213536; Hereinafter “Fleck”) in view of Sharifi (US 2025/0052587; Hereinafter “Sharifi”) . Regarding claim 3 , Jain, in combination with Fleck, teaches the apparatus of claim 1. Jain, in combination with Fleck, does not explicitly teach wherein the processor is configured delete the request to modify the software artifact without executing it and transmit an error message to a computing terminal that submitted the request in response to determining that the user is not authorized to modify the software artifact. In an analogous art, Sharifi teaches wherein the processor is configured delete the request to modify the software artifact without executing it and transmit an error message to a computing terminal that submitted the request in response to determining that the user is not authorized to modify the software artifact (Sharifi: Para. [0040], According to some examples, if the system determines that the second user has not authorized location sharing with the first user 102, the system may transmit a notification to the second user, as shown in FIG. 2 and discussed below. Additionally or alternatively, if the system determines that the second user has not authorized location sharing with the first user 102, the system may transmit an error notification to the first user 102. The error notification may provide an indication that the second user has not shared their location information with the first user 102. In some examples, the error notification may ask the first user 102 if the system should send a request to the second user to share their location information. [request to execute function that requires user sharing location is deleted and not executed] Para. [0030]-[0031], Para. [0001], A user can share their location with other users by authorizing mapping applications to share their location with selected users. Location sharing can display the locations of users that have provided authorization. Para. [0052]-[0053]) It would have been obvious to a person having ordinary skill in the art, before the effective filing date of the claimed invention, to combine the teachings of Sharifi with the system and method of Jain and Fleck to include wherein the processor is configured delete the request to modify the software artifact without executing it and transmit an error message to a computing terminal that submitted the request in response to determining that the user is not authorized to modify the software artifact because this functionality provides for improved modification and updating of navigation routes shared between authorized users (Sharifi: Para. [0074]). Regarding claim 7 , Jain, in combination with Fleck, teaches the apparatus of claim 1. Jain, in combination with Fleck, does not explicitly teach wherein the processor is further configured to transmit a notification to another computing terminal with an identification of a future point in time when the software artifact will be modified, in response to a determination that the user is authorized to modify the software artifact. In an analogous art, Sharifi teaches wherein the processor is further configured to transmit a notification to another computing terminal with an identification of a future point in time when the software artifact will be modified, in response to a determination that the user is authorized to modify the software artifact (Sharifi: Para. [0053], According to some examples, the location sharing request 222 may include additional options delineating the parameters of location sharing. For example, the second user may authorize location sharing with the first user 102 for a predefined period of time, such as a day, week, month, year, etc. In some examples, the second user may authorize location sharing for a specific trip, such as the trip for the second user to meet the first user 102.) It would have been obvious to a person having ordinary skill in the art, before the effective filing date of the claimed invention, to combine the teachings of Sharifi with the system and method of Jain and Fleck to include wherein the processor is further configured to transmit a notification to another computing terminal with an identification of a future point in time when the software artifact will be modified, in response to a determination that the user is authorized to modify the software artifact because this functionality provides for improved modification and updating of navigation routes shared between authorized users (Sharifi: Para. [0074]). Regarding claim 11 , Claim 11 is rejected under the same rational as claim 3. Regarding claim 15 , Claim 15 is rejected under the same rational as claim 7. Regarding claim 19 , Claim 19 is rejected under the same rational as claim 3 . 07-21-aia AIA Claim (s) 5 and 13 are rejected under 35 U.S.C. 103 as being unpatentable over Jain et al. (US 2022/0391927; Hereinafter “Jain”) in view of Fleck et al. (WO 2019/213536; Hereinafter “Fleck”) in view of Nagaraja et al. (US 2020/0244605; Hereinafter “Nagaraja”) . Regarding claim 5 , Jain, in combination with Fleck, teaches the apparatus of claim 1. Jain, in combination with Fleck, does not explicitly teach wherein the processor is further configured to identify a role of the user within the host platform, override the determination that the user is not authorized to modify the software artifact based on the identified role, and modify the software artifact according to the request. In an analogous art, Nagaraja teaches wherein the processor is further configured to identify a role of the user within the host platform, override the determination that the user is not authorized to modify the software artifact based on the identified role, and modify the software artifact according to the request (Nagaraja: Para. [0030], Artificial intelligence models are used to provide assistance to updating a profile of the user, determining from the user input elements that trigger changes in the workflow, as well as modifying ruleset(s) used to generate the workflow. Para. [0043], In some embodiments, Jiseki engineering 107a enables Jiseki administrative/engineering personnel to implement rulesets that dictate, for example and without limitations, how to associate a user with a service (e.g., a workflow of a service) based on various conditions, how to modify a workflow based on user input information, the profile data, chatting history data on the particular channel associated with the service and/or the user, chatting history data on channels other than the particular channel associated with the service and/or the user, and so on. Furthermore, Jiseki engineering 107a enables Jiseki administrative/engineering personnel to implement tokens and their mapping relationship with corresponding services, set up individuals and/or organizations whose members/affiliates/agents for access/subscription to groups of particular one or more services provided at platform 106, and register professionals (e.g., agent) with authorized role-based access to platform 106 to service users. Para. [0105], Para. [0139], In the first case, the agent claims selected user 481-4 to start handling user 481-4's request manually. In the second case, the agent decides not to claim user 481-4 anyway, thereby reverting back the effect of the agent entering a response and sending of the entered response. In some embodiments, dashboard 480 further prompts the agent to login under a role other than the current one associated with the logging-in account of the agent. For example, dashboard 480 can prompt the agent to log in as an administrator. In some embodiments, upon being prompted, the agent can switch the logging-in account to a super-agent or agent manager role so that the agent can further perform other actions, such as assigning user 481-4 to other agents under his/her management. [unauthorized user can be prompted to login to super-agent or agent manager role to further perform actions]) It would have been obvious to a person having ordinary skill in the art, before the effective filing date of the claimed invention, to combine the teachings of Nagaraja with the system and method of Jain and Fleck to include wherein the processor is further configured to identify a role of the user within the host platform, override the determination that the user is not authorized to modify the software artifact based on the identified role, and modify the software artifact according to the request because this functionality provides for improved service with effective, efficient, and more responsive systems (Nagaraja: Para. [0005]). Regarding claim 13 , Claim 13 is rejected under the same rational as claim 5 . 07-21-aia AIA Claim (s) 8 and 16 are rejected under 35 U.S.C. 103 as being unpatentable over Jain et al. (US 2022/0391927; Hereinafter “Jain”) in view of Fleck et al. (WO 2019/213536; Hereinafter “Fleck”) in view of Kursun et al. (US 2020/0068031; Hereinafter “Kursun”) . Regarding claim 8 , Jain, in combination with Fleck, teaches the apparatus of claim 1, wherein the processor is configured to assign weights to communications from among the historical communications based on natural language processing (NLP) (Fleck: Para. [0172], The data analysis engine 1140 may use a model to identify the one or more portions of the data 1125 to be altered or removed. In some embodiments, the model may be part of a natural language processing algorithm. The model may include formats or regular expressions for the predefined types of information. In some embodiments, the model may include an artificial neural network with one or more weights. Para. [0069], Client scanners 228 may also use historical analysis to identify the frequency or periodicity with which the user interacts with the service. For example, some services the users may interact with daily, while others may interact with on a weekly, biweekly, monthly, yearly, or other schedule. Client scanners 228 may access SMS or email or web activities related to each unique sender. In some cases, SMS, email, or other may be used to identify second-factor authentication prompts for logins. For example, a password reset email or one-time password (OTP) may be identified and correlated to active account use. A password manager log may also provide historical intervals of password updates for each unique sender.) and execute the Al module on the historical communications based on the assigned weights (Fleck: Para. [0172], In some embodiments, the model may include an artificial neural network with one or more weights.) . Jain, in combination with Fleck, does not explicitly teach wherein the processor is configured to assign weights to communications from among the historical communications based on natural language processing (NLP) and frequency of keywords. In an analogous art, Kursun teaches wherein the processor is configured to assign weights to communications from among the historical communications based on natural language processing (NLP) and frequency of keywords (Kursun: Para. [0003], input historical and streaming user interaction data from across a plurality of communication channels into the neural network learning engine; determine one or more neural network-derived user interaction patterns from across the plurality of communication channels, wherein the one or more neural network-derived interaction patterns are associated with authorized user activity; and build a unified user profile from the one or more neural network-derived user interaction patterns. The unified user profile comprises a channel profile component, a natural language processing profile component, a resource usage profile component, an interaction history profile component, and a user knowledge content profile component. Para. [0007], the system further includes a natural language processing module, wherein the one or more neural network-derived user interaction patterns comprise a communication pattern of the user. The system is further configured to establish a signature marker of the user based on the communication pattern; and store the signature marker in the unified user profile, wherein the marker is used to at least partially identify and authenticate the user in subsequent interactions. In yet another embodiment, the signature marker comprises at least one of vocabulary, word frequency patterns, syntax, grammar, misspellings, abbreviations, pronunciation, intonation, timbre, pitch, cadence, language, and dialect. Para. [0027]) , and execute the Al module on the historical communications based on the assigned weights (Kursun: Para. [0055], The system may analyze the components of the user profile and calculate a weighted confidence function, level, score or the like for each individual component. Para. [0058], For example, if a suspected unauthorized user previously communicated via phone, a low confidence score or weighting may be assigned to NLP data from that particular communication channel or from NLP data in general. Para. [0059], the system may determine that an authorized user does not typically exhibit adequate knowledge of past interactions and give a low confidence weighting to user responses associated with the content profile. Para. [0062]) . It would have been obvious to a person having ordinary skill in the art, before the effective filing date of the claimed invention, to combine the teachings of Kursun with the system and method of Jain and Fleck to include wherein the processor is configured to assign weights to communications from among the historical communications based on natural language processing (NLP) and frequency of keywords because this functionality provides for calculation and assignment of weights to historical communication to improve security and unauthorized access (Kursun: Para. [0001]). Regarding claim 16 , Claim 16 is rejected under the same rational as claim 8 . Conclusion 07-96 AIA The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. U.S. Patent Application Publication No. 2021/0211446 by Albero et al. Any inquiry concerning this communication or earlier communications from the examiner should be directed to Nelson Giddins whose telephone number is (571)272-7993. The examiner can normally be reached on Monday - Friday, 9:00 AM - 5:00 PM. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Linglan Edwards can be reached at (571) 270-5440. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /NELSON S. GIDDINS/ Primary Examiner, Art Unit 2408 Application/Control Number: 18/101,043 Page 2 Art Unit: 2408 Application/Control Number: 18/101,043 Page 3 Art Unit: 2408 Application/Control Number: 18/101,043 Page 4 Art Unit: 2408 Application/Control Number: 18/101,043 Page 5 Art Unit: 2408 Application/Control Number: 18/101,043 Page 6 Art Unit: 2408 Application/Control Number: 18/101,043 Page 7 Art Unit: 2408 Application/Control Number: 18/101,043 Page 8 Art Unit: 2408 Application/Control Number: 18/101,043 Page 9 Art Unit: 2408 Application/Control Number: 18/101,043 Page 10 Art Unit: 2408 Application/Control Number: 18/101,043 Page 11 Art Unit: 2408 Application/Control Number: 18/101,043 Page 12 Art Unit: 2408 Application/Control Number: 18/101,043 Page 13 Art Unit: 2408