DETAILED ACTION
Claims 1, 3, 18 are amended. Claim 4 is canceled. Claims 1-3, 5-20 are pending.
Priority: 4/27/2021(FP)
Assignee: GrabTaxi
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Note: In the Remarks, the Applicant does not mention the relevant specification paragraph(s) that recite the amendment(s).
Claim(s) 1-3, 5-20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
1.Amended Claims 1, 18 are rejected for reciting a limitation that is unclear, ambiguous and indefinite.
Amended Claim 1 recites, ‘the ….controller….to: access the data storage table to access the data element by the data access client, in response to the request and the grant of access to the data access client having access rights of at least one of read access and write access to the data element.’
The double use of ‘to access’ creates confusion over whether the controller accesses the data storage table to let the client access the element, or if the client performs the access via the controller.
The spec discloses a distinct sequence performed by the controller (determine a data storage table…., determine whether the client has access rights…, grant access…., restrict access to read/write), whereas the claim collapses these discrete steps into an ambiguous result-oriented phrase.
Therefore the limitation phrase 'the controller to access the data storage table to access the data element by the access client' is vague and ambiguous because it fails to clearly show the operational cooperation between the controller, the data storage table, and the client. Specifically, it is unclear whether the client or the controller is initiating the secondary access step.
Para-0004 of the spec recites, ‘controller to….determine whether the data access client has access rights to the determined data storage table’. So the right to ‘grant access’ is bounded by the spec’s condition of the controller performing a check ‘whether the client has access rights to the determined data storage table’, whereas the claim broadly recites rights to the data element. Hence claim 1 is indefinite and is rejected. Claim 18 has the same issue and is also rejected.
Furthermore, the limitation is redundant because it unnecessarily, without adding value, repeats the previous steps.
2.Amended Claim 3 is rejected for reciting a limitation that is unclear, ambiguous and indefinite.
Amended Claim 3 recites, ‘wherein the access controller is configured to determine the data storage table by reverse lookup mapping from based on the identifier of the storage location’. (Specification, [0059])
It is unclear why ‘(Specification, [0059])’ is included in the claim.
That being said, the limitation uses both ‘from’ and ‘based’ back-to-back (‘from based on’), leaving it ambiguous whether the reverse lookup mapping originates from the identifier or is based on the identifier.
‘Reverse lookup mapping’ implies going backwards from a value to a key, but coupling it with the confused syntax makes it unclear whether the storage location identifier is the input, the output, or the indexing mechanism for the data storage table.
Para-0006 of the spec recites, ‘….by reverse lookup mapping from the identifier of the storage location’.
Under the MPEP 2173.05, grammatical errors that result in contradictory phrasing make the scope of the claim uncertain. Consequently, claim 3 being indefinite is rejected.
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112:
The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention.
Note: In the Remarks, the Applicant does not mention the relevant specification paragraph(s) that recite the amendment(s).
Claim(s) 1-3, 5-20 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention.
1.Amended Claims 1, 18 are rejected for reciting a limitation which lacks written description support in the spec.
Amended Claim 1 recites, ‘the data access controller to….access the data storage table to access the data element by the data access client, in response to the request and the grant of access to the data access client having access rights of at least one of read access and write access to the data element’.
The spec does not recite this limitation. The spec only discloses determining access rights based on a data storage table associated with the data element, whereas the claim broadly recites granting access based on rights to the data element itself.
The spec limits the controller's determination step to evaluating rights for a ‘determined table’. The claim shifts the scope to checking access rights to the ‘data element’ (of at least one of read/write access), which is broader than the disclosed table-level authorization scheme.
Specifically, the spec at Para-0004 explicitly limits the access determination to 'determine whether the client has access rights to the determined table allowing the access to the data element’. There is no disclosure in the spec of granting access rights directly tied to the data element independent of the determined table.
Therefore the spec does not provide support for the broader claim language. Hence the limitation recites new matter and claim 1 is rejected.
Note: This issue was previously mentioned. But it is unresolved. Based on the amendments and the arguments, the rejection has been clarified and maintained.
2.Amended Claim 3 is rejected as failing to comply with the written description requirement for ‘reverse lookup mapping’.
Amended claim 3 recites, ‘wherein the….controller is configured to determine the data storage table by reverse lookup mapping from based on the identifier of the storage location’. See the 112(b) for the ‘from based on’ issue. However Para-0006 of the spec recites, ‘determine…. from the identifier of the storage location’, and is used for reference.
Para-0007 of the spec recites, ‘the identifier of the storage location is a Uniform Resource Identifier and the access controller is configured to perform the reverse lookup mapping by means of traversal of a search tree which comprises a node for each character of the URI and which comprises a leaf node comprising an indication of the data storage table’.
The spec functionally states what the tree achieves (mapping a URI character-by-character to a leaf node indicating a storage table), but lacks descriptive support detailing how such a character-by-character search tree is constructed, updated, or traversed given the variable length, hierarchical syntax, and percent-encoding schemes inherent to URIs.
Merely restating the functional language of the claim as a desired result in the spec does not satisfy the requirement to show possession of the invention. The figures do not provide any information.
Para-0050 of the spec recites, ‘a reverse index mechanism is used that allows identifying the associated table (or tables) for a given file/directory URI’. But there is no written description about the ‘reverse index’, the ‘reverse index mechanism’ or how the reverse (lookup) index identifies the table associated with the URI.
The spec uses structural language (‘a node for each character’), and treats the implementation as a black box (‘A reverse index mechanism is used….’). Reciting a specific software structure (a character-level search tree) that is not actually described in operative detail in the spec, fails the possession test. In addition, the spec does not disclose where the search tree is stored. This is a major drawback of the disclosure.
The spec does not teach how a character-level search tree for full URIs maps to storage tables. The spec does not provide working examples, algorithmic steps for traversal, or architectural layouts for the nodes and leaves.
Para-0065 of the spec discloses, ‘the search tree is a prefix search tree implemented by extending a Trie data structure’. While the spec casually mentions a Trie and a reverse lookup for a URI, it fails to describe the necessary algorithmic details for extending the Trie data structure to accommodate the specific character node mapping and multi-table leaf association recited in the spec.
The spec fails to teach that the applicant was in possession of an operative search tree implementation —specifically how a tree with a node for each character and leaf nodes mapping variable-length URIs to tables is algorithmically able to store and retrieve ‘data elements’ at the time of filing.
In summary, the inventor's possession of ‘reverse lookup mapping’, the search tree, traversal configuration and lookup process at the time of filing was incomplete. Hence claim 1 is rejected. Claim 18 has the same issue and is also rejected.
Note: The issue that the spec does not disclose the details of ‘reverse lookup mapping’, was previously mentioned. Based on the amendments and arguments, the rejection has been clarified and maintained.
Note: On August 4, 2025, the USPTO memo on patent eligibility rejections focused on AI inventions. Though the memo addressed eligibility for software-related inventions, the memo also stated that it “is not intended to announce any new USPTO practice or procedure and is meant to be consistent with existing USPTO guidance.”
That being said, the amendments do not overcome the rejection because they do not add ‘significantly more’ to the exception, to recite an inventive concept and/or technical improvement. Based on the amendments and arguments, the rejection has been clarified and maintained.
Claim Rejections - 35 USC§ 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-3, 5-20 are rejected under 35 U.S.C. § 101 because the claimed invention is directed to a judicial exception (i.e., a law of nature, a natural phenomenon, or an abstract idea) without significantly more.
Claim 1 recites, ‘A data storage system comprising: a data storage….;
a data storage access interface to receive a request for an access to a data element….; an access controller to determine a data storage table; determine whether the data access client has access rights….; grant the data access client access….’.
Claim 1 is directed to ‘a data storage system comprising a data storage and an access controller’ and claim 18 is directed to 'a method for controlling access to data stored in a data storage’. Hence they are directed to a statutory category, i.e., a machine (Step 1: Yes).
Under revised Step 2A, Prong 1 of the eligibility analysis, it is necessary to evaluate whether the claim recites a judicial exception by referring to subject matter groupings articulated in 2106.04(a) of the MPEP. In consideration of the analysis, the claims recite an abstract idea.
Claims 1, 2-3, 18 recite a judicial exception such as an abstract idea by broadly using the concept of ‘Uniform Resource Identifier/URI’ and ‘reverse lookup mapping’ to include a data storage system receiving an access request with a URI from a client to access a ‘data element’ in a ‘data storage table’ (henceforth, table) of a database. The access controller grants access to the client if it determines that the client has access rights to the table, based on the received input URI, which inherently is a hierarchical structure represented as a ‘search tree’ with parent-child nodes.
Claim 3 further clarifies the abstract idea because it recites the concept of data correlation, mapping, and information analysis —specifically, determining the table via a ‘reverse lookup mapping’ of the URI. This concept falls within the method of organizing human activity and mental processes, as it describes a process of organizing and relating pieces of information that can be performed conceptually or via fundamental logic.
Although claim 3 broadly recites 'reverse lookup mapping,' the spec illuminates the nature of this mapping by disclosing that the reverse lookup is performed by traversal of a ‘search tree’ which comprises a node for each character of the URI and which comprises a leaf/child node comprising an indication of the table. When read in light of the spec, the claimed ‘reverse lookup mapping’ via tree-traversal encompasses the algorithmic concept for organizing and searching data, thereby further confirming that claim 3 is directed to the abstract idea.
A ‘search tree’ is based on graph theory, a subfield of mathematics and a basic concept in computer science. Since the search tree is based on the client input URI, claim 3 recites the abstract idea of traversing a pre-populated tree structure that uses hierarchical ordering relationships to locate nodes in the tree. Traversing a search tree is an activity a human can do with a pencil and paper. In fact, the pre-populated search tree encourages an effortless pencil-paper approach to readily locate nodes rather than employ a realistic assessment of the technical requirements to understand how the search tree was built (from the beginning). Thus the searching of the pre-populated tree is a ‘mental process’. What further validates the abstract idea is that the underlying tree design and search rules of the tree remain the same regardless of whether the tree is used in a client-server application, an embedded application or a simple sorting algorithm.
Therefore, receiving by the access controller a client request to access a data storage element, search a pre-populated tree to determine access or denial for the client, and notify the client, is a mental process that can be performed using a pen and paper. It is similar to the abstract idea of ‘organizing human activity’ that involves collecting and comparing information from the client, use rules to search and locate nodes in a pre-populated hierarchical structure, determine options for the client and transmit the result to the client. Both, the ‘search tree’ and ‘organizing human activity’, use the hierarchical structure, with the main goal at the root, that branches into sub-goals and actions, which are then evaluated to reach a final outcome. Even if the claims require a computer, they may still be considered a mental process since the computer is used merely as a tool to perform the mental steps. See MPEP 2106.04(a)(2). Thus claims 1, 2-3, 18 recite an abstract cognitive concept performable in the human mind.
Under revised Step 2A, Prong 2 of the eligibility analysis, if it is determined that the claims recite a judicial exception, it is then necessary to evaluate whether the claims recite additional elements that integrate the judicial exception into a practical application of that exception.
In this case, claims 1, 18, 6-12 recite additional elements such as ‘a data access interface’, ‘access rights’, ‘a temporary access token’, ‘an access stream’ and ‘a logging system’. Here the data access client interacting with the data access interface to send the input URI and an access stream to request and receive the temporary access token, while the entire transaction is logged/recorded in the logging system, does not provide significantly more than the judicial exception because these features are well-understood, routine, and conventional activity previously known to the industry of client access control, data management, and data processing.
Claims 15, 16 recite additional elements such as ‘a datalake’, and ‘a cloud data storage’, without reciting how these additional elements can be integrated with the claimed access controller to function as ‘data storage’ in the ‘data storage system’ to assist in the reverse lookup mapping of the search tree that is dynamically changing as multiple clients send requests to the ‘data storage system’.
In essence, the additional elements recited in claims 1, 18, 6-12, and 15-16, individually and in combination, do not integrate the exception into a practical application. This is because they are merely being used to apply the abstract idea using a generic processor, as defined in MPEP 2106.04(d).
They are mentioned only as available technologies, but do not show how they can be integrated into the claims.
Furthermore, the additional elements, ‘a data storage’, ‘a datalake’, and ‘a cloud data storage’, are mentioned without reciting their physical structure, location, volatility type and management. Hence these additional elements amount to software structures unsupported by an underlying hardware architecture. They merely comprise the software to access and store data via requests, to the cloud or datalake. See MPEP 2106.01 (I). Hence claims 1-3, 5-20 are drawn to software per se.
Though the spec recites, ‘controlling access to data stored in a data storage’, claims 1-3, 5-20 merely recite software data structures (URI, data access interface, data storage table, data element), and software instructions (client request, database query), without any hardware support. The generic access controller's interaction with the database represents a conventional use of the input URI rather than a specific, technical improvement in database functionality or a specialized algorithm in reverse lookup mapping to process the URI. Hence claims 1-3, 5-20 are directed to organizing, storing and retrieving data based on the received URI, which is well-known in the art.
Claim 13 recites that ‘the access to the data element is a write access or a read access’, and claim 14 recites that ‘the access to the data element is an access to a plurality of data elements including the data element’. Granting read or write access to data elements are considered to be insignificant extra-solution activity. Extra solution activity are activities that are incidental to the primary method that are merely a nominal or tangential addition to the claim. See MPEP 2106.05(g). Granting read or write access merely involves routine, conventional data storage or retrieval used as a post-collection step, rather than an improvement to computer functionality itself.
Under Step 2B of the eligibility analysis, if it is determined that the claims recite a judicial exception that is not integrated into a practical application of that exception, it is then necessary to evaluate the additional elements individually and in combination to determine whether they provide an inventive concept.
In this case, claims 1-3, 5-20 recite a ‘data storage system’ where the client sends a request with an identifier to access a table in a database in the storage system, wherein the request is processed by the controller, to grant or deny access to the client, is nothing more than routine, well-understood, well-documented activity between a client and a server. Implementing access control via read/write access rights using standard components like a client, a generic access controller, a database, database tables, data elements etc., does not constitute an inventive concept. This arrangement is simply the application of a well-understood, routine technique for providing access to data, which does not set forth an unconventional inventive concept. Claims 1-3, 5-20 recite a standard, conventional computer-based approach to access data based on read/write privileges. that was well-known at the time of filing. The claims focus on collecting, analyzing, and outputting data based on the input request, a method well-known in client server communication and does not constitute a technical improvement. Claims 1-3, 5-20 do not provide an improvement in data access technology and/or database processing.
Since the claims do not recite how the data access client, the generic access controller, and the additional elements, considered individually or in combination, enhance the functioning of the ‘data storage system’ or provide a clear technological improvement, the claims do not provide an inventive concept to transform the abstraction into ‘significantly more’.
The claims amount to no more than applying the abstract idea of using a tree-based client input to grant/deny access to the client using a generic computer. For court cases, please see at least: Digitech Image Tech's v. Electronics for Imaging, 758 F. 3d 1344; Planet Bingo, LLC v. VKGS, LLC, 576 Fed. Appx. 1005; Affinity Labs of Texas, LLC v. DirecTV, LLC, 838 F.3d 1253.
Hence independent claims 1 and 18 recite limitations of the abstract idea and are ineligible subject matter. Dependent claims 2-3, 5-17, 19-20 also being ineligible, do not aid in the eligibility of their respective parent.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-2, 5-7, 13-14, 18-20 are rejected under AIA 35 U.S.C. 103 as being unpatentable over Geller et al (20160173406) in view of Hamilton et al (8910240) and Wissner at al (20100268700).
As per Claim 1, Geller discloses a data storage system (Geller, [Figs. 1, 2A-2B, 3, 7]; [0048 - The system architecture in Fig. 1 may includes components configured to provide a resource-based web services access control model. Fig. 2A shows an access control service/ACS 150 is interposed between web services interface 130 and a number of web services resources 140]) comprising:
a data storage (Geller, [Figs. 2A-2B: data store 160]) storing data comprising a plurality of data elements (Geller, [0059 - Fig. 3 shows resource table 300, displaying a number of access control entries/ACEs 310, each of which corresponds to a record/data element including a number of fields. ACE 310 includes resource URI field 320, principal ID field 330, subject pool field 340, and an access type field 350]),
each data element being associated with a data storage table (Geller, [Figs. 3, 6, 11, 14-15]; [0069 - ACS 150 is configured to generate and maintain one or more tables that correspond to different views of the data reflected in table 300. For example, data in two different table views are optimized for searching according to either principals/clients 100 or resources 140. Such table views are stored within data store 160 in a manner similar to storage of table 300]),
a data storage access interface (Geller, [Figs. 2A, 7: web services interface 130]) configured to receive from a data access client (Geller, [Fig. 2A: web services client]), a request to the data storage for an access to a data element (Geller, [0071,0072 – In Fig. 4, step 400, web services client 110, on behalf of a principal 100, generates a request specifying one or more access operations directed to a web services resource 140. In step 402, client 110 conveys the generated request to web services interface 130]),
the request including an identifier of a storage location of the data element (Geller, [0071 – In Fig. 4, client 110 generates an HTTP request or an XML document specifying the URI/Uniform Resource Identifier of resource 140 and information about the requested operation, e.g., read, write, delete etc.; Since it is well-known that a URI is a sequence of characters that identifies a logical or physical resource, it implies that the request includes an identifier of a storage location of the data element]);
an access controller (Geller, [Fig. 2B: ACS 150]; [Fig. 12: storage host controller 510]) configured to:
determine the data storage table associated with the data element (Geller, [0077 – In Fig. 5, step 502, for each received request specifying a desired access operation, a particular resource 140 and a particular principal 100, ACS 150 determines whether an ACE 130/row/data storage table/sub-table exists that is associated with both the particular resource 140/identifier and the particular principal 100, and that specifies one or more access types]) based on the identifier of the storage location included in the request (Geller, [0078 - ACS 150 is configured to search through one or more instances of table 300, stored as a collection of records by data store 160, to determine whether any ACE 310/data storage table/sub-table/row matches the resource identifier, e.g., the URI of resource 140 and the access identifier of principal 100, and one or more access types/access rights to perform the specified access operation according to the access policy for resource 140; Para-0084 of the spec defines ‘data storage table’ as a sub-table/ACE 310/row of a larger table/Fig. 3:Resource Table 300]; [Fig. 5: step 504 - ACE exists? Yes, thereby determining the data storage table/ACE 310/sub-table/row associated with the data element based on the identifier of the storage location included in the request]);
determine whether the data access client has access rights to the determined data storage table allowing the access to the data element (Geller, [Fig. 5: step 504 - ACE exists?]; [0031 - The access control information includes information identifying a particular user or principal/client as well as information identifying the access privileges/access rights held by the principal with respect to the particular web services resource]);
grant the data access client access to the data element in an instance the data access client has access rights to the determined data storage table allowing the access to the data element (Geller, [Fig. 5: step 504 - ACE exists? Yes, step 506 - Allow request to proceed]; [0082 – In Fig. 5, in response to determining that there exists at least one ACE 310 corresponding to resource 140 and principal 100 and indicating one or more access types/access rights sufficient to perform the requested operation, ACS 150 is configured to allow the request to proceed to resource 140 in step 506]),
access the data storage table to access the data element by the data access client ([See 112(b)]), in response to the request and the grant of access to the data access client (Geller, [Fig. 4: steps 400 to 410]) having access rights (Geller, [0088 - The ListResourceAccess operation function to allow the entity/controller invoking the operation to determine what principals 100 have any sort of access rights to a resource 140]) of at least one of read access and write access (Geller, [0127 – In Fig. 10, step 1000, manager 161 receives a request from a client to store/write a structured data record within a table]) to the data element (Geller, [0041 - A URI is used to identify a resource/data element 140]; [0039 - <path> identifies the path to be resolved by the host to access the identified resource/data element. One example of a URL/URI corresponding to a resource 140 is:http://storage.host.com/smith/music/Artist/Album/Trackl.mp3; Here file Track1.mp3 is the data element]).
Hamilton clarifies receiving the URI in the request from the data access client as follows,
a data storage access interface (Hamilton, [Fig. 1: universal interface 114]; [Col. 17, lines 17-19 - Fig. 9: Computing device 900 implemented as a standard server 920]) configured to receive a request for an access (Hamilton, [Col. 6, lines 5-7 - An authority scope can determine whether a content provider has permission/access rights to read from the device, write to the device]) to a data element (Hamilton, [Col. 7, lines 60-63 - In Fig. 3, when the clock content provider processes a request to read ‘content://clock/alarm/1’, the clock content provider can read from the ‘alarm’ table in the ‘clock’ database and return the requested column, which is column ‘1/data element]) from a data access client (Hamilton, [Col. 2, lines 66-67 – In Fig. 1, mobile device 104 is a cell phone that includes operating platform 102 with applications 108,110,112 to send a request]; [Col. 2, lines 22-23 - Fig. 9 shows a computer device/900 and a mobile computer device/950, thereby implying that mobile computer device 950 sends a request to computing device 900]; [Col. 19, lines 39-41 - A client/950 and server/900 are generally remote from each other and interact through a communication network]),
the request including an identifier of a storage location of the data element (Hamilton, [Col. 1, lines 45-47 - An application transmits a request having a uniform resource identifier/URI associated with data and a data store that is accessible for storing and retrieving the data]; [Col. 2, lines 41-45 - The URI has a hierarchal structure/tree that permits applications to specify the type of data to retrieve/read or store/write. A URI ‘content://contacts/phones/Bob’ indicates that the data specified by the URI is a phone number for a user Bob that is stored as contact information/data element]);
Therefore it would have been obvious to a person of ordinary skill at the time of filing to incorporate the URI of Hamilton into the access control system of Geller, for the benefit of retrieving and storing all data on a device using URIs. Every piece of content has a string that uniquely identifies it. Different applications can retrieve data stored on the device using a single mechanism by specifying the data with a URI (Hamilton, Col. 2, lines 31-36).
Wissner discloses verifying client access rights as follows,
access the data storage table (Wissner, [Fig. 2: databases 216, 218]; [0063 – In Fig. 2, host server 200 retrieves data stored in repositories/databases 128,130,132 based on query submitted by user/client, thereby implying accessing the data storage table]) to access the data element (Wissner, [0244 - In Fig. 25, step 2508, an advertisement/data element is presented to the user in the user interface, thereby implying access of data element]) by the data access client (Wissner, [Fig. 1: client device 102N]), in response to the request (Wissner, [0141 – In Fig. 3, host server 300 includes UI module 312]; [0046 - The location identifier of electronic content/data element or a source is a web address that a web browser uses to locate the content of the source for access by a user via a web browser, e.g., URI]; [0076 – In Fig. 2, host 200 includes web application server 212 which accepts a request from the user/client and responds to the request by providing the requestor with web pages, such as HTML documents/data element and objects that can include static and/or dynamic content]) and the grant of access to the data access client (Wissner, [0142 - The user can login before requesting search such that personalized semantic types and associated attributes can be used in performing search; Here login by user suggests determining access and grant of access to client/user]) having access rights of at least one of read access and write access to the data element (Wissner, [0089 - An object is any electronic object stored, shared, distributed, and/or accessed, such as documents, articles, audio files, video files, multimedia content, etc.]; [0089 - The location identifier of the object can be a location identifier in the WWW]) of the request (Wissner, [0070 – In Fig. 2, host server 200 includes firewall 204 to enforce a predetermined set of access rights between a particular set of machines and applications/users to regulate resource sharing between these entities. Firewall 204 manages access to an access control list which details permissions including the access and operation rights of an object by an individual/user, a machine, and/or an application, and the circumstances under which the permission rights stand]).
Therefore it would have been obvious to a person of ordinary skill at the time of filing to incorporate the access rights of Wissner into the access control system of Geller,Hamilton for the benefit of performing search and search optimization using a pattern of a location identifier (Wissner, 0045).
As per Claim 2, the rejection of claim 1 is incorporated, and Geller discloses,
wherein the identifier of the storage location is a Uniform Resource Identifier (Geller, [0040 - A URI identifies host, domain and path/location information associated with a resource 140 that is sufficient to uniquely identify that resource within a particular naming scheme]; [0041 - A URI has the general format: <scheme>:<host.domain>/<path>; See RFC 3986]).
As per Claim 5, the rejection of claim 1 is incorporated, and Geller discloses,
wherein the access controller is configured to reject the data access client (Geller, [0083 – In Fig. 5, step 508 – Deny/reject request, thereby implying that the client access is rejected]) access to the data element (Geller, [0076 – In Fig. 5, step 500, ACS 150 receives requests that are submitted by clients 110 on behalf of principals 100 and that are forwarded via interface 130]) in an instance the data access client does not have access rights to the determined data storage table allowing the access to the data element (Geller, [0077 – In Fig. 5, steps 502-504, for each received request specifying a desired access operation, a resource 140 and a principal 100, ACS 150 determines whether an ACE 130 exists that is associated with both the resource 140 and principal 100, and that specifies one or more access types/rights that are sufficient to perform the specified access operation]; [Fig. 5: step 504 – ACE exists? No]).
As per Claim 6, the rejection of claim 1 is incorporated, and Geller discloses,
comprising a data access interface (Geller, [Figs. 2A, 7: web services interface 130]),
wherein granting (Geller, [Fig. 5: step 504: ACE exists? Yes, step 506: Allow request to proceed]) and rejecting (Geller, [Fig. 5: step 504 - ACE exists? No, step 508 - Deny request]) access to the data element comprises transmitting to the data access interface, information specifying whether the data access client has access to the data element (Geller, [0048 – In Fig. 2A, ACS 150 is interposed between web services interface 130 and web services resources 140], [0111 – In Fig. 2B, interface 130 submits the request to resource 140 contingent upon a response from ACS 150 that the particular principal 150 has or does not have sufficient privileges to perform the request]).
As per Claim 7, the rejection of claim 1 is incorporated, and Geller discloses,
wherein the information specifies access rights (Geller, [0088 - The ListResourceAccess operation functions to allow the entity invoking the operation to determine what principals 100 have any sort of access rights to a resource 140]; [0089 - The GetUserRightsForResource operation functions to allow the entity invoking the operation to identify those access rights, if any, that a principal 100 has with respect to a resource 140, thereby implying that the operations determine the access rights which are included in the transmitted information]) of the data access client (Geller, [Figs. 11, 14-15 show access type/access rights 350 for each client]; [0059 - ACE 310 includes a resource URI field 320, a principal ID field 330, a subject pool field 340, and an access type field 350]).
As per Claim 13, the rejection of claim 1 is incorporated, and Geller discloses,
wherein the access to the data element is a write access (Geller, [0127 – In Fig. 10, step 1000, manager 161 receives a request from a client to store/write a structured data record within a table]) or wherein the access to the data element is a read access (Geller, [0146 - ReadRecords operation]; [0159 – In Fig. 12, host 163 receives numerous requests to read records from managers 161 on behalf of clients of data store 160]; [0114 – In Fig. 8: step 800, where web services interface 130 receives a web services request from client 110. The request specifies principal 100/access identifier, a web services resource 140/URI, and an access operation requested to be performed with respect to resource 140 on behalf of principal 100; Here the request can be a read access request]).
As per Claim 14, the rejection of claim 1 is incorporated, and Geller discloses,
wherein the access to the data element is an access to a plurality of data elements including the data element (Geller, [Figs. 3, 11, 14-15]; [0076 – In Fig. 5, ACS 150 receives requests that are submitted by clients 110 on behalf of principals 100 and that are forwarded via interface 130]; [0085 - ACS 150 is configured to concurrently perform Fig. 5 operations on multiple different requests for access operations to multiple distinct, unrelated resources 140, thereby implying that the access to the data element is an access to a plurality of data elements including the data element]).
As per Claim 18, it is similar to claim 1 and therefore the same mappings are incorporated.
As per Claim 19, it is similar to claims 1, 18 and therefore the same mappings are incorporated.
As per Claim 20, Geller discloses a computer-readable medium comprising program instructions, which, when executed by one or more processors (Geller, [0154 - Instructions stored on a computer-accessible medium and executable by a processor]), cause the one or more processors (Geller, [0203 – Fig. 18 shows computer system 1800 includes one or more processors 1810 coupled to a system memory 1820 via I/O interface 1830]) to perform the method of claim 18.
Claim 3 is rejected under AIA 35 U.S.C. 103 as being unpatentable over Geller et al (20160173406) in view of Hamilton et al (8910240), Wissner at al (20100268700) and Shukla et al (20200133967).
As per Claim 3, the rejection of claim 1 is incorporated, and Geller,Hamilton,Wissner discloses the hierarchical tree structure of the URI.
Shukla further discloses,
wherein the access controller is configured to determine the data storage table by reverse lookup mapping from (Shukla, [Fig. 26: Realtime Document Index/RDI 2628]; [0318 - The serving stack stores the RDI, which is an inverted index that inverts the collected and indexed documents to a topic space, which maintains a mapping of the topics associated with one or more of the documents, e.g., which is not pre-sorted, but the topics and documents are associated with each other in the reverse index data structure; Since neither the spec nor the claim define ‘reverse lookup mapping’, the citation is a valid interpretation]; [0255 - A query is organized as a tree, e.g., a query tree. A node in the query tree can be a parent, or a child. A parent node has at least one child node below it]) based on the identifier of the storage location (Shukla, [0002 - A website is hosted on a web server that is typically accessible via a network, through a web address known as a Uniform Resource Indicator/URI or a Uniform Resource Locator/URL]; [0003 - A search engine performs a search based on the user query and output results that are presented in a ranked list, referred to as search results or hits, e.g., links or URIs/URLs for one or more web pages and/or websites]).
Therefore it would have been obvious to a person of ordinary skill at the time of filing to incorporate the search and feed system of Shukla into the access control system of Geller,Hamilton,Wissner for the benefit of using RDI which includes the indexer, scheduler, and inverted index serving stack of the search and feed system. The RDI is rapidly refreshed and updated based on online content changes in the online world to facilitate identifying new content to provide to users using the search and feed system (Shukla, 0307, 0309).
Claims 9-12 are rejected under AIA 35 U.S.C. 103 as being unpatentable over Geller et al (20160173406) in view of Hamilton et al (8910240), Wissner at al (20100268700) and Vepa et al (20170329957).
As per Claim 9, the rejection of claim 1 is incorporated, and Geller, Hamilton,Wissner disclose security tokens.
Vepa further discloses,
wherein granting the data access client access to the data element comprises transmitting a temporary access token to the data access interface (Vepa, [0248 – In Fig. 13, at step 1302, OAuth service 1340 validates the client by issuing a user/client combination asking for all of the allowed scopes from the Authorization module, i.e., a policy enforcement point/PEP API 1360/controller such as Cloud Gate 702 of Fig. 7. At step 1304, the response is the allowed scopes, which is computed and which is incorporated in the access token, thereby implying transmitting a temporary access token to the data access interface/OAuth service]),
wherein the data access interface is configured to open access for the data access client (Vepa, [0140 - Fig. 7 implements a Cloud Gate 702 running in web server 712 and acting as a Policy Enforcement Point/PEP configured to integrate with IDCS Policy Decision Point/PDP using open standards, e.g., OAuth2, OpenID Connect, etc., while securing access to web browser and REST API resources 714 of application. The PDP/interface is implemented at OAuth and/or OpenID Connect microservices 704]) for which it has received the temporary access token from the access controller (Vepa, [Fig. 13: step 1304, allowedscopes + custom claims received from PEP/controller]).
Therefore it would have been obvious to a person of ordinary skill at the time of filing to incorporate the mobile phone access of Vepa into the access control system of Geller,Hamilton,Wissner for the benefit of using a system that receives an access token request for an access token that corresponds to the resource, the request including user information and application information, the user information including roles of a user and the application information including dynamic roles of the application and dynamic roles for the application (Vepa, 0004).
As per Claim 10, the rejection of claim 6 is incorporated, and Geller,Hamilton,Wissner disclose security tokens.
Vepa further discloses,
wherein the request comprises a request for an access token (Vepa, [0308 – In Fig. 30, step 3002, OAuth Service 1340 of Fig. 13 receives an access token request for an access token that corresponds to the resource desired to be accessed by a user/application/client]),
granting the data access client access to the data element comprises transmitting a temporary access token to the data access client (Vepa, [0311 – In Fig. 30, at step 3006, the access token with the computed scopes is provided to the client]; [0248 – In Fig. 13, at step 1304, the response is the allowed scopes, which is computed and which is incorporated in the access token and sent back to client 1320 at step 1305]),
wherein the temporary access token includes an identification of the data access client (Vepa, [0154 - The client identifies itself as a client that lives in ‘tenant 1’ by including a ‘client assertion’ in the request. The client assertion includes a client ID/client 1 and the client tenancy ‘tenant 1’. As ‘client 1’ in ‘tenant 1’, the client has the right to invoke a request for a token on ‘tenant 3’, and the client wants the token for a user in ‘tenant 2’. Accordingly, a ‘user assertion’ is also passed as part of the same HTTP request. The access token that is generated/temporary access token will be issued in the context of the target tenancy which is the application tenancy/tenant 3 and will include the user tenancy/tenant 2]).
Therefore it would have been obvious to a person of ordinary skill at the time of filing to incorporate the mobile phone access of Vepa into the access control system of Geller,Hamilton,Wissner for the benefit of using a system that receives an access token request for an access token that corresponds to the resource, the request including user information and application information, the user information including roles of a user and the application information including dynamic roles of the application and dynamic roles for the application (Vepa, 0004).
As per Claim 11, the rejection of claim 1 is incorporated, and Geller discloses,
wherein the data access interface is configured to open access for the data access client for which it has received the temporary access token from the data access client (Geller, [0072 - Interface 130 verifies the credentials of principal 100/client, which is included within the request or received through a separate interrogation conducted by interface 130. Such credentials include the principal's access identifier or another identifier, such as a username, as well as a password, cookie or security token/temporary access token; See 112(b)]).
As per Claim 12, the rejection of claim 9 is incorporated, and Geller,Hamilton,Wissner,Vepa disclose,
comprising a logging system configured to log the access (Vepa, [0089 - Privileged account management/PAM allows for a password checkout as well as setting time limits, forcing periodic changes, automatically tracking checkout, and reporting/logging on all activities; Here reporting implies that since logging is done, the log can be accessed]) with the identification of the data access client included in the temporary access token (Vepa, [0154 - The client identifies itself as a client that lives in ‘tenant 1’ by including a ‘client assertion’ in the request. The client assertion includes a client ID/client 1 and the client tenancy ‘tenant 1’, thereby implying that the client provides the identification that is included in the temporary access token]; [0116 - A login process includes validation of credentials, submission of a log report, updating of the last login time, etc.]; [0092 – audits, e.g. tracking/recording]).
Therefore it would have been obvious to a person of ordinary skill at the time of filing to incorporate the mobile phone access of Vepa into the access control system of Geller,Hamilton,Wissner for the benefit of using a system that receives an access token request for an access token that corresponds to the resource, the request including user information and application information, the user information including roles of a user and the application information including dynamic roles of the application and dynamic roles for the application (Vepa, 0004).
Claims 8, 15-17 are rejected under AIA 35 U.S.C. 103 as being unpatentable over Geller et al (20160173406) in view of Hamilton et al (8910240), Wissner at al (20100268700) and Paraschiv et al (20220121673).
As per Claim 8, the rejection of claim 1 is incorporated, and Geller,Hamilton,Wissner disclose a data access interface.
Paraschiv further discloses,
wherein the data access interface is configured to open an access stream to the data element in an instance the access controller has granted (Paraschiv, [0022 - As with the access management system 110, the access management system 118 allows users to create and manage users, roles, and groups, and use permissions to allow or deny access to cloud services and resources]; [0013 - Fig. 1 shows a shared data processing platform 100 in which a network-based data warehouse system 102 implements database stream tracking, e.g., view streams; Since the claim does not define ‘access stream’, the citation is a valid interpretation]) the data access client access to the data element (Paraschiv, [0018 - Data to be tracked via streams is stored and accessed on the cloud computing storage platform 104]).
Therefore it would have been obvious to a person of ordinary skill at the time of filing to incorporate the streams of Paraschiv into the access control system of Geller,Hamilton,Wissner for the benefit of using a shared data processing platform in which a network-based data warehouse system implements database stream tracking, e.g., view streams (Paraschiv, 0013).
As per Claim 15, the rejection of claim 1 is incorporated, and Geller,Hamilton,Wissner disclose a data store.
Paraschiv further discloses,
wherein the data storage is a data lake (Paraschiv, [0012 - A multi-stage database partition unloader exports data to a remote datastore such as a data lake]; [0020 – In Fig. 1, data storage devices 124-1 to 124-n is an Azure Data Lake]).
Therefore it would have been obvious to a person of ordinary skill at the time of filing to incorporate the data lake of Paraschiv into the access control system of Geller,Hamilton,Wissner for the benefit of using a multi-stage database partition unloader which can export data to a remote datastore such as a data lake, using a single database copy command that uses a partition expression to parallelize processing of the files into a plurality of result files at the remote location using a plurality of nodes in the database in a distributed and scalable approach (Paraschiv, 0012).
As per Claim 16, the rejection of claim 1 is incorporated, and Geller,Hamilton,Wissner disclose a data store.
Paraschiv further discloses,
wherein the data storage is a cloud data storage (Paraschiv, [0020 – In Fig. 1, data storage devices 124-1 to 124-n is part of a public cloud infrastructure or a private cloud infrastructure]).
Therefore it would have been obvious to a person of ordinary skill at the time of filing to incorporate the shared data processing platform of Paraschiv into the access control system of Geller,Hamilton,Wissner for the benefit of using the shared data processing platform which comprises the network-based data warehouse system, a cloud computing storage platform, and a remote computing device. The network-based data warehouse system is used for storing and accessing data in an integrated manner, and reporting and analysis of the integrated data from disparate sources (Paraschiv, 0014).
As per Claim 17, the rejection of claim 1 is incorporated, and Geller,Hamilton,Wissner disclose a data store.
Paraschiv further discloses,
wherein the data access client is implemented by a data processing entity operating according to a cluster computing framework (Paraschiv, [0021 – In Fig. 1, a set of processes on a compute node executes a query plan compiled by the compute service manager 112. Here, a fifth process handles all communication with a compute cluster for a given job provided by the compute service manager 112 and communicates information back to the compute service manager 112 and other compute nodes of the execution platform 114]; [0017 - The compute service manager 112 also performs query optimization and compilation as well as managing clusters of computing services that provide compute resources, e.g., virtual warehouses, virtual machines, EC2 clusters]).
Therefore it would have been obvious to a person of ordinary skill at the time of filing to incorporate the shared data processing platform of Paraschiv into the access control system of Geller,Hamilton,Wissner for the benefit of using the shared data processing platform which comprises the network-based data warehouse system, a cloud computing storage platform, and a remote computing device. The network-based data warehouse system is used for storing and accessing data in an integrated manner, and reporting and analysis of the integrated data from disparate sources (Paraschiv, 0014).
Response to Arguments
The Applicant's arguments filed on June 30, 2026 have been fully considered, but they are not persuasive.
Applicant argues: ‘….support for the claimed aspects of "the grant of access to the data access client having access rights of at least one of read access and write access to the data element" is provided in the Specification at least at paragraphs [0043], [0055], [0082], and [0083] and FIG. 4, access controller 404’. (Rem, Pg. 8)
Response: This argument is incorrect.
Nowhere does the spec disclose the above limitation. The spec does not recite and/or describe the limitation in the manner the applicant claims it does. The limitation in the spec is mis-paraphrased. Please see the 112(a) and the 112(b).
Applicant further argues:‘….claims 1 and 18 do not recite a "search tree". Accordingly, the alleged "abstract" basis for rejecting claims 1 and 18 under Section 101 is not recited in amended claims 1 and 18’. (Rem, Pg. 10)
Response: This argument is incorrect.
Based on 101 guidelines, during a 101 eligibility analysis, the spec and figures are often referred to understand what the claim means, what the claim terms mean, how the components interact and if the claim integrates an abstract idea into a technical improvement.
Claims 1, 18 recite ‘determine a data storage table with which the data element is associated from the identifier of the storage location’. Claim 2 recites that the ‘identifier’ is a URI. To interpret the claim as a whole, and to understand how the identifier is used to determine a data storage table, the spec is referred.
The identifier or URI has an inherent hierarchical structure represented by a search tree with parent-child nodes. The path segments map directly to parent-child nodes branching downward from a root.
The spec further confirms that the claimed identifier/URI is associated with a ‘search tree’ which is a prefix search tree extending a Trie data structure, and a leaf node of the search tree comprises an indication of the data storage table. See at least Paras: 0007,0065 of the spec.
Organizing and representing data via hierarchical relationships (such as parent-child nodes, directories, or paths) as in the URI, is mapped to the judicial exception of ‘methods of organizing human activity’ or ‘data manipulation/collection’ under Alice Step 2A (Prong 1).
Applicant further argues:‘….reminds the Office "to consult the specification to determine whether the disclosed invention improves technology or a technical field,, and evaluate the claim to ensure it reflects the disclosed improvement’. (Rem, Pg. 11)
Response: Claims 1-3, 5-20 are directed to the abstract idea of managing access to a database. Restricting direct client access to a database via a generic access controller is a well-known, conventional, and generic computer function that has been implemented in the art for decades to enhance database security, and does not provide an inventive concept or a technical improvement. The claims merely disclose a conventional client-server system.
The client-controller-database configuration does not improve the storage system in any way, but rather uses a computer to automate a basic, well-known business practice in e-Commerce. The claims fail to provide 'significantly more' than the routine, generic use of a computer in database access.
The generic access controller's interaction with the client and database to authorize the client represents a conventional use of database security to determine access rights rather than a specific, technical improvement in access controller functionality. Though spec, Para-0049 makes a fleeting mention of ‘cloud IAM systems’, a security framework, neither the spec nor the claims disclose an improvement in data access control by integrating the access controller with ‘cloud IAM systems’.
Para-0049 also fleetingly recites well-known, third-party data processing engines like Apache Spark, and Apache Hadoop Filesystem, without reciting how any of these data processing engines can be integrated with the claimed client-controller-database setup to improve access control.
The claims lack specific recitations of a particular technical integration with a system like Hadoop, which would potentially demonstrate an improvement to system architecture, processing time, or energy consumption. Without such specific claim limitations integrated with a third-party practical application, the claims remain an abstract idea and thus do not constitute patent-eligible subject matter.
Applicant further argues: ‘The claim itself does not need to explicitly recite the improvement described in the specification’. (Rem, Pg. 11)
Response: This argument is incorrect.
Under MPEP 2106.04(d), to establish that an invention integrates a judicial exception into a practical application via a technological improvement (Step 2A, Prong Two), the spec must disclose the improvement, and the claim itself must show that specific technical improvement through its recited elements or limitations.
The claim cannot merely rely on an improvement described in the spec. It must explicitly recite the operational steps, components, and interactions that produce the technological improvement.
Without the technological improvement in the claim, the recited elements amount to generic, conventional functions applied using generic components.
Applicant further argues: Applicant respectfully reiterates that the while some dependent claim 3 recites a "tree" structure that might be based on mathematical concepts (as noted in the OA), the claims do not recite any mathematical concepts as required for rejecting the claims based on this specific category of abstract ideas’. (Rem, Pg. 10)
Response: This argument is incorrect.
Independent claims 1, 18 recite an identifier/URI which inherently has a hierarchical structure represented as a tree. A tree is based on graph theory, a subfield of mathematics. Therefore at least claims 1, 18 recite a mathematical concept.
Claim 3 recites, ‘wherein the access controller is configured to determine the data storage table by reverse lookup mapping from the identifier of the storage location’.
A tree is a data structure that organizes data in a hierarchical parent-child relationship. And the limitation of performing ‘a reverse lookup mapping from a URI’ falls under the abstract idea of a mental process (manipulating and correlating information) or managing information content.
Under the 101 eligibility guidelines, a process or step is classified as a mental process if it can be performed in the human mind or by a human using a pen and paper. In this case, a human can read a Uniform Resource Identifier/URI string, trace it backward/reverse, and manually map or look up an entry in a data storage table.
Based on Step 2A, Prong Two, the generic access controller configured to perform routine mapping does not integrate the abstract idea into a specific technological improvement. Instead, it merely performs a mental sorting/lookup in a conventional computer environment.
Since the mapping and lookup steps use generic, well-understood, and conventional computer components (e.g. data storage, data access client, data storage table, data element, access controller, etc.,), the claim lacks an inventive concept to transform the abstraction into ‘significantly more’ (fails 2B).
Applicant further argues:‘That is, the claimed request and the Hamilton request including the URI are not the same’. (Rem, Pg. 12)
Response: This argument is incorrect.
The claimed request and the Hamilton request include the Uniform Request Identifier or URI. The URI is a standard Internet entity.
The URI has a hierarchical structure. Its components are organized from left to right, moving from the most general scope to the most specific resource. Since the URI has a standard definition with a syntax managed globally for naming and identifying resources, the claimed request and the Hamilton request are the same because they include the same standard ‘URI’.
Conclusion
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to ARVIND TALUKDAR whose telephone number is (303)297-4475. The examiner can normally be reached M-F, 10 am-6pm EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Hosain Alam can be reached at 571-272-3978. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
Arvind Talukdar
Primary Examiner
Art Unit 2132
/ARVIND TALUKDAR/Primary Examiner, Art Unit 2132