DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 26 May 2026 has been entered. Applicant amended claims 1, 4, and 7. Applicant canceled claims 10-11. Accordingly, claims 1-9 and 12 remain pending.
Response to Amendment
Applicant’s amendment to the abstract overcomes the abstract objection of 23 February 2026. Therefore, the abstract objection of 23 February 2023 is withdrawn.
Applicant’s cancellation of claims 10-11 results in the 35 USC 112(a) rejection to be moot.
Response to Arguments
35 USC 101 rejection:
Applicant's arguments filed 26 May 2026 have been fully considered but they are not persuasive.
Applicant’s remarks:
Claim 1 is not directed merely to "assessing compliance" or "organizing information." Claim 1 now specifically recites a computer-implemented data-protection resilience architecture which leverages computerized propagation over a structured graph of resource and resource-group records in memory. In particular, claim 1 requires generating, in memory, an "R-graph" that comprises object records and dependency relationships;… .
The Patent Office has not shown that the ordered combination of resource object records, resource-group object records, stored data-protection protected- status tiers, propagation of child resource values to a parent resource-group object record, and setting the parent compliance state based on child protected-status values was well- understood, routine, and conventional. The amended claim therefore does not merely add generic computer components to an abstract idea; it recites a specific data-structure-driven computation pipeline for data-protection resilience status propagation.
Independent claims 4 and 7 recite analogous limitations in apparatus and computer-program- product form and are patent eligible for at least the same reasons. The dependent claims are eligible for at least the same reasons and further limit the claimed R-graph implementation and domain-specific presentation. Accordingly, the rejection under 35 U.S.C. § 101 should be withdrawn.
Applicant’s support:
It is true that a person might draw a simplified illustrative graph on paper, but that is not the claimed invention. The claim requires machine-maintained object records in memory, stored data-protection status attributes, dependency relationships among resource and resource- group object records, and machine-implemented propagation operations that update parent resource-group object states based on child resource object states. These are operations on a particular computer data structure representing data-processing resources, not mental observations, judgments, or opinions.
The practical application is not the business result of knowing whether an enterprise is compliant. Rather, the practical application is the claimed R-graph mechanism for computing data-protection resilience status across nested machine-resource relationships. The claim has the technical effect of improving operation of a data-protection management system by replacing isolated resource-level status reporting with propagated resource-group status computation based on child-resource compliance, criticality, and protected-status attributes. That is the technological mechanism recited in the claim. The claim recites the particular implementation that provides the improvement: the R-graph object-record structure, the protected/protected-with- warnings/not-protected data-protection status tiers, and the child-to-parent propagation logic that changes the parent resource-group compliance state. The specification support already identified by Applicants likewise describes resource-group objects, nested groups, propagation logic applied to the R-graph, propagation of statuses from child members of a hierarchy or group, and protected-status tiers including "Protected," "Protected-With- Warnings," and "Not-Protected."
Examiner’s remarks:
The mental process abstract idea involves the limitations of “generating a model of data processing resources within the data processing environment, the model identifying resources, resource groups each comprising a plurality of the resources, and nested group relationships among the resource groups; generating a data resilience graph (R-graph) based on the model, the R- graph comprising a plurality of object records and dependency relationships between the object records, the plurality of object records including: a resource object record for each resource, and a resource-group object record for each resource group; applying compliance and criticality rules, including propagation logic, to the object records in the R-graph based on the dependency relationships nested group relationships, the applying comprising:
propagating compliance values and, criticality values, and protected-status values from resource object records representing child resources to a resource-group object record representing a parent resource group, determining, for the resource-group object record, a propagated compliance attribute and a propagated criticality attribute based at least in part on the compliance attributes, criticality attributes, and protected-status attributes of the child resources; and setting the propagated compliance attribute of the resource-group object record to a non-compliant value or a warning value when at least one child resource object record has a not-protected value or a protected-with-warnings value according to the propagation logic”. The combination of steps above recites an abstract idea
Apart from citing generic computing components (such as data processor and memory), these steps are can be achieved in the human mind and/or using pencil and paper. If a claim recites a limitation that can practically be performed in the human mind, with or without the use of a physical aid such as pen and paper, the limitation falls within the mental processes grouping, and the claim recites an abstract idea. Claims can recite a mental process even if they are claimed as being performed on a computer. The examiner reviewed the specification and determine that the claimed invention involves a concept that is performed in the human mind and the applicant is merely claiming that concept is performed 1) on a generic computer, or 2) in a computer environment, or 3) is merely using a computer as a tool to perform the concept. In these situations, the claim is considered to recite a mental process
The additional element are the (a) generic computing components; (b) the steps of record storing at least a compliance attribute and, a criticality attribute, and a protected-status attribute for the corresponding resource; and the step of (c) displaying a domain-specific view of the R-graph; for an operational scope of the data processing environment, the domain-specific view including the resource-group object record and visually indicating the propagated compliance attribute and the propagated criticality attribute for the operational scope.
It has been determined that the generic computing components (data processor and memory) are merely instructions to apply an exception/abstract idea. As explained by the Supreme Court, in order to make a claim directed to a judicial exception patent-eligible, the additional element or combination of elements must do "‘more than simply stat[e] the [judicial exception] while adding the words ‘apply it’” (or an equivalent). Alice Corp. v. CLS Bank, 573 U.S. 208, 221, 110 USPQ2d 1976, 1982-83 (2014) (quoting Mayo Collaborative Servs. V. Prometheus Labs., Inc., 566 U.S. 66, 72, 101 USPQ2d 1961, 1965). Thus, for example, claims that amount to nothing more than an instruction to apply the abstract idea using a generic computer do not render an abstract idea eligible. Alice Corp., 573 U.S. at 223, 110 USPQ2d at 1983. See also 573 U.S. at 224, 110 USPQ2d at 1984. Implementing an abstract idea on a generic computer does not integrate the abstract idea into a practical application or add significantly more.
The steps of storing the attributes and displaying the domain specific view of the R-graph are considered to be activities that are well-known/well-understood, routine, and conventional. Therefore these additional elements, as a combination, do not integrate the abstract idea into a practical application and do not add an inventive concept to the claims because they do not amount to significantly more than the judicial exception.
Therefore, in response to Applicant’s remarks “The Patent Office has not shown that the ordered combination of resource object records, resource-group object records, stored data-protection protected- status tiers, propagation of child resource values to a parent resource-group object record, and setting the parent compliance state based on child protected-status values was well- understood, routine, and conventional”, the steps of “propagation of child resource values to a parent resource-group object record” and “setting the parent compliance state based on child protected-status values” were determined to be an abstract idea and not activity that is routine, conventional, and well-understood. “Storing data” is the additional element that is well-understood, routine, and conventional, wherein in combination with other additional components (see 101 rejection) do not amount to significantly more than the abstract idea.
35 USC 103 rejection
Applicant’s arguments with respect to independent claims have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-9 and 12 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea (mental process) without significantly more. The independent claim(s) recite(s) “generating a model of data processing resources within the data processing environment, the model identifying resources, resource groups each comprising a plurality of the resources, and nested group relationships among the resource groups; generating a data resilience graph (R-graph) based on the model, the R- graph comprising a plurality of object records and dependency relationships between the object records, the plurality of object records including: a resource object record for each resource, and a resource-group object record for each resource group; applying compliance and criticality rules, including propagation logic, -to the object records in the R-graph based on the dependency relationships nested group relationships, the applying comprising: propagating compliance values and, criticality values, and protected-status values from resource object records representing child resources to a resource-group object record representing a parent resource group, determining, for the resource-group object record, a propagated compliance attribute and a propagated criticality attribute based at least in part on the compliance attributes, criticality attributes, and protected-status attributes of the child resources; and setting the propagated compliance attribute of the resource-group object record to a non-compliant value or a warning value when at least one child resource object record has a not-protected value or a protected-with-warnings value according to the propagation logic”.
The limitations above pertain to the method for assessing data protection resilience status of a data processing environment which is a process that under its broadest reasonable interpretation covers performance of the limitations being an abstract idea of a mental process. The method can be performed mentally by a human using pencil and paper, but for the recitation of generic computer components such as “data processing environment” (claims 1, 4, and 7), “generating in memory”, a data processor and computer readable media (claim 4), and non-transient medium and data processing system (claim 7). Therefore, nothing in the claimed elements preclude the steps from being practically performed manually by a human via a mental process or by a human using pencil or paper. If a claim under its broadest reasonable interpretation covers performance in the human mind or by a human using pencil and paper, but for the recitation of generic computer components, then if falls within the mental processing grouping of abstract ideas. Thus, claims 1, 4, and 7 recite an abstract idea.
This judicial exception is not integrated into a practical application. The independent claims recite additional elements of within the data processing environment, additional generic computer components, and displaying a domain specific view of the R-graph.
The generic computer components (including the data processing environment) are recited at a high level of generality such that it amounts to no more than mere instructions to apply the judicial exception using generic computing components. Accordingly, such additional elements do not integrate the abstract idea into a practical application because it does not impose meaningful limits on practicing the abstract idea. In addition, the processing environment is merely linking the judicial exception to a particular environment or field of use and does not qualify as significantly more than the judicial exception.
The additional element of “each resource object record storing at least at compliance attribute, criticality attribute, and a protected status attribute for the corresponding resource” is determined to be merely storage of data that is well-understood, routine, and conventional activity (MPEP 2106.05(d)).
The additional element of “displaying a domain-specific view of the R-graph; for an operational scope of the data processing environment, the domain-specific view including the resource-group object record and visually indicating the propagated compliance attribute and the propagated criticality attribute for the operational scope” is determined to be post solution activity/insignificant extra solution activity that involves selecting a particular data source or type of data to be manipulated and displayed (see MPEP 2106.05(g)) and activity that is well-understood, routine, and conventional activity (MPEP 2106.05(d)). Therefore the additional element does not integrate the abstract idea into a practical application and do not add an inventive concept to the claims.
The additional elements above evaluated individually and in combination do not amount to significantly more than the abstract idea.
For the reasons above, the independent claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception. Thus, claims 1, 4, 7 are ineligible under 35 U.S.C 101.
Claims 2, 5, and 8 provide limitations that under the broadest reasonable interpretation further narrow the R-graph, which is activity that can be perform by a human using pencil and paper. The generation of the domain specific view by applying inheritance attributes of the compliance and criticality rules to the hierarchy of object appear to be an additional element that is not enough to qualify as significantly more than the abstract idea because the limitations is adding the words apply it with the judicial exception (MPEP 2106.05(d)). In addition, applying attributes/settings/rules to a display objects is determined to be well-understood, routine, conventional activity. Thus, claims 2, 5, and 8 are not eligible under 35 USC 101.
Claims 3, 6, and 9 provide limitations that under the broadest reasonable interpretation further narrow the domain specific view to a particular environment or field of use and does not qualify as significantly more than the judicial exception. Thus, claims 3, 6, and 9 are not eligible under 35 USC 101.
Claim 12 provides limitations that under the broadest reasonable interpretation further narrow the domain specific view and does not qualify as significantly more than the judicial exception. Thus, claim 12 is not eligible under 35 USC 101.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1-9 and 12 is/are rejected under 35 U.S.C. 103 as being unpatentable over Sylor et al US 20020186238 (hereinafter Sylor) in view of Maes US 20190140914 (hereinafter Maes).
As to claim 1, Sylor teaches a computer-implemented method for assessing data-protection resilience status of a data processing environment (Abstract discloses method for displaying the status of network resources. Paragraph 2 discloses the method relates to network monitoring. Paragraph 3 discloses network monitoring software detects problems and potential problems with network resources. The network monitoring software is therefore concerned with how problems can propagate from one resource to the next) , the method comprising, by one or more data processors (Paragraph 23 discloses the invention features a computing apparatus which includes a processor and main memory):
generating a model of data processing resources within the data processing environment, the model identifying resources, resource groups each comprising a plurality of the resources, and nested group relationships among the resource groups (Paragraph 82 discloses a logical hierarchy offers a tree-based data model describing a web of dependency relationships between resource profiles. Paragraph 88 discloses by using its tree-based data model, logical hierarchy 30 can organize information into tiers, with parent-child relationships between entities of adjacent tiers. The parent-child relationships are based on dependency relationships: for instance, parent resource profiles can be dependent upon child resource profiles. Alternatively, parent resource profiles can provide to multiple child resource profiles, as with a server that provides multiple networked services, while each of the networked services (for instance, DNS, file sharing, and network security) provides its features to multiple software applications);
generating, in memory (Paragraph 23 discloses the invention features a computing apparatus which includes a processor and main memory), a data resilience graph (R-graph) based on the model, the R- graph comprising a plurality of object records and dependency relationships between the object records (Paragraph 49 discloses a hierarchical status display process arranges the resources for display in a visual hierarchy (thus a graph). The visual hierarchy derives from a logical hierarchy containing resources in dependency relationships with one another. The logical hierarchy is a data model, while the visual hierarchy is a graphical representation of a logical hierarchy), the plurality of object records including:
a resource object record for each resource (Paragraph 82 discloses a logical hierarchy offers a tree-based data model describing a web of dependency relationships between resource profiles. Paragraph 88 discloses by using its tree-based data model, logical hierarchy 30 can organize information into tiers, with parent-child relationships between entities of adjacent tiers. The parent-child relationships are based on dependency relationships: for instance, parent resource profiles can be dependent upon child resource profiles. Alternatively, parent resource profiles can provide to multiple child resource profiles. The child resource profiles are the resource object record for the child resource), each resource object further including record storing at least a compliance attribute and, a criticality attribute, and a protected-status attribute for the corresponding resource; the protected-status attribute having a value selected from at least protected, protected-with-warnings, and not-protected (Paragraph 182 reveals each rendered object for resource profile contains information such as rendering database ID specifying its referenced resource profile, severity level, positional information, and other attributes necessary. Paragraphs 19-20 reveal the resource profile includes a status and associating the status with a severity. Associating the status with a severity includes a using a status metric associated with the monitored resource profile. The method include acquiring notice of a change in the status, updating the severity; and re-rendering the hierarchy in a fishbone layout, to include rendering the monitored resource profile to indicate the updated severity. The severity includes applying an application-wide override to deviate from a behavior indicated by the status metric. The deviation includes suppressing a change in severity. Paragraph 17 discloses the status includes acquiring information about properties of the monitored resource that have changed in the most recent interval. Paragraphs 64-65 the status of an example resource can be trouble-free, warning, or error. Therefore, the reference resource profile can be the compliance attribute, the severity level is the criticality attribute, and the protected status attribute is the status (where warning label can be selected)); and
a resource-group object record for each resource group (Paragraph 82 discloses a logical hierarchy offers a tree-based data model describing a web of dependency relationships between resource profiles. Paragraph 88 discloses by using its tree-based data model, logical hierarchy 30 can organize information into tiers, with parent-child relationships between entities of adjacent tiers. The parent-child relationships are based on dependency relationships: for instance, parent resource profiles can be dependent upon child resource profiles. Alternatively, parent resource profiles can provide to multiple child resource profiles. Therefore, the parent resource profiles are the resource group object record for the parent resource);
applying compliance and criticality rules, including propagation logic, to the object records in the R-graph based on the dependency relationships and the nested group relationships (Paragraph 17 discloses the monitored resource profile includes a propagation rule for how the acquired status should propagate to dependent resource profiles that are in dependency relationships (this relationship include nested group relationship, see also paragraphs 76-78) with the monitored resource profile), the applying comprising:
propagating compliance values and, criticality values, and protected-status values from resource object records representing child resources to and a resource-group object record representing a parent resource group (Paragraphs 17, 71, and 200 disclose the monitored resource profile includes a propagation rule for how the acquired status should propagate to dependent resource profiles that are in dependency relationships with the monitored resource profile. Thus, the prior art discloses how a status (or multiple statuses) should propagate from dependent resource profile/child to the monitored resource profile/parent);
determining, for the resource-group object record, a propagated compliance attribute and a propagated criticality attribute based at least in part on the compliance attributes, criticality attributes, and protected-status attributes of the child resources (Paragraph 71 discloses obtaining status values that are derived from states of the associated resource representation. The derivation is given by a status metric. Status metric determines the states that status value represents and how their values are weighed, status metric can represent a context through its choice of states and through the outputs that it assigns. Paragraph 200 discloses monitored agent determines, based on resource profiles, if a condition exists for which it should raise alarm); and
setting the propagated compliance attribute of the resource-group object record to a non-compliant value or a warning value…(Paragraphs 64-65 disclose the status of an example resource can be trouble-free, warning, or error. Therefore, propagated compliance attribute is set to warning status or error status );and
displaying a domain-specific view of the R-graph ,for an operational scope of the data processing environment, the domain-specific view including the resource-group object record and visually indicating the propagated compliance attribute and the propagated criticality attribute for the operational scope (Paragraph 21 discloses displaying the status (which can be the propagated compliance attribute and the propagated criticality attribute) of networked resources. The method includes acquiring a logical hierarchy that includes resource profiles, as well as dependency relationships among the resource profiles. The resource profiles represent networked resources. The method also includes deriving a visual hierarchy from the logical hierarchy, where components of the visual hierarchy correspond to components of the logical hierarchy, such that the visual hierarchy is a tree. The method includes rendering the visual hierarchy in a fishbone. Paragraph 24 discloses the fishbone layouts each feature a hierarchy with resource profiles and dependency relationships among the resource profiles, where the resource profiles represent networked resources. Each hierarchy shares a common root. Preferred embodiments with regards to one or more fishbone layouts in the snowflake layout include one or more of the features already described with regards to a fishbone layout).
PNG
media_image1.png
406
462
media_image1.png
Greyscale
PNG
media_image2.png
481
464
media_image2.png
Greyscale
Figure 9 of Maes Figure 10 of Maes
Sylor does not teach, but Maes teaches setting a propagated compliance attribute of the resource-group object record to a non-compliant value or a warning value when at least one child resource object record has a not-protected value or a protected-with-warnings value according to the propagation logic (Figure 9 and paragraphs 188-190 reveal a propagated compliance attribute of the parent/Service C 1004 has a critical warning notification associated with it. When the user selects service C, the user sees the child topology represented by Figure 10, where there is a warning value associated a node of the child graph).
It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify Sylor’s teaching of monitoring software detected problems and potential problems with network resources with Maes’s teachings of setting a propagated compliance attribute of the resource-group object record to a warning value when at least one child resource object has-warnings value according to the propagation logic such that the system can autonomously or semi-autonomously remediate any events or incidents that may be detected from the monitoring of the instantiated service or provided via an information technology service management system (ITSM) (Paragraph 28 of Maes).
As to claim 2, the combination of Sylor in view of Maes teaches additionally wherein the R-graph consists of a hierarchy of objects, and the domain-specific view is further generated by applying inheritance attributes of the compliance and criticality rules to the hierarchy of objects (Sylor: Paragraph 49 discloses a hierarchical status display process arranges the resources for display in a visual hierarchy (thus a graph). The visual hierarchy derives from a logical hierarchy containing resources in dependency relationships with one another. The logical hierarchy is a data model, while the visual hierarchy is a graphical representation of a logical hierarchy. Paragraph 82 discloses a logical hierarchy offers a tree-based data model describing a web of dependency relationships between resource profiles. Paragraph 88 discloses by using its tree-based data model, logical hierarchy 30 can organize information into tiers, with parent-child relationships between entities of adjacent tiers. The parent-child relationships are based on dependency relationships: for instance, parent resource profiles can be dependent upon child resource profiles. Paragraph 21 discloses displaying the status (which can be the propagated compliance attribute and the propagated criticality attribute) of networked resources. The method includes acquiring a logical hierarchy that includes resource profiles, as well as dependency relationships among the resource profiles. The resource profiles represent networked resources. The method also includes deriving a visual hierarchy from the logical hierarchy, where components of the visual hierarchy correspond to components of the logical hierarchy, such that the visual hierarchy is a tree. The method includes rendering the visual hierarchy in a fishbone. Paragraph 24 discloses the fishbone layouts each feature a hierarchy with resource profiles and dependency relationships among the resource profiles, where the resource profiles represent networked resources. Each hierarchy shares a common root. Preferred embodiments with regards to one or more fishbone layouts in the snowflake layout include one or more of the features already described with regards to a fishbone layout).
As to claim 3, the combination of Sylor in view of Maes teaches wherein the domain-specific view is for an entire enterprise, a department within the enterprise, an application, or a service (Sylor: Paragraph 49 discloses a hierarchical status display process arranges the resources for display in a visual hierarchy (thus a graph). Paragraph 51 reveals resources include hardware, applications, services, business processes, organizational structures (such as business units within an enterprise, or departments within a university), paths within a network, and other network resources. Hardware resources include clients, servers, routers, switches, and NIC's, as well as peripheral devices (such as disk drives) and networked devices (such as printers and networked storage)).
As to claim 4, Sylor teaches an apparatus for assessing data-protection resilience status of a data processing environment (Paragraph 23 discloses the invention features a computing apparatus which includes a processor and main memory; abstract discloses method for displaying the status of network resources. Paragraph 2 discloses the method relates to network monitoring. Paragraph 3 discloses network monitoring software detects problems and potential problems with network resources. The network monitoring software is therefore concerned with how problems can propagate from one resource to the next), the apparatus comprising:
one or more data processors (Paragraph 23 discloses the invention features a computing apparatus which includes a processor and main memory); and
one or more computer readable storage media storing instructions that, when executed by the one or more data processors, cause the one or more data processors to perform operations comprising (Paragraphs 56-57 disclose computer instructions resident in main memory. A processor can access main memory to execute the computer instructions for operating system. Claim 29 and paragraphs 25 and 59 disclose a computer usable medium having computer readable program code means embodied therein, including a processor, a main memory, a visual display, a storage device, and a network connection, the program code means comprising: computer readable program code means for causing a computer to represent a hierarchy including a plurality of resource profiles and a plurality of dependency relationships among resource profiles in the plurality of resource profiles, where the resource profiles represent networked resources; computer readable program code means for causing the computer to acquire a status of a monitored resource profile in the plurality of resource profiles; and computer readable program code means for causing the computer to render the hierarchy in a fishbone layout, including rendering a visual representation of the status of the monitored resource profile):
generating a model of data processing resources within the data processing environment, the model identifying resources, resource groups each comprising a plurality of the resources, and nested group relationships among the resource groups (Paragraph 82 discloses a logical hierarchy offers a tree-based data model describing a web of dependency relationships between resource profiles. Paragraph 88 discloses by using its tree-based data model, logical hierarchy 30 can organize information into tiers, with parent-child relationships between entities of adjacent tiers. The parent-child relationships are based on dependency relationships: for instance, parent resource profiles can be dependent upon child resource profiles. Alternatively, parent resource profiles can provide to multiple child resource profiles, as with a server that provides multiple networked services, while each of the networked services (for instance, DNS, file sharing, and network security) provides its features to multiple software applications);
generating, in memory (Paragraph 23 discloses the invention features a computing apparatus which includes a processor and main memory), a data resilience graph (R-graph) based on the model, the R- graph comprising a plurality of object records and dependency relationships between the object records (Paragraph 49 discloses a hierarchical status display process arranges the resources for display in a visual hierarchy (thus a graph). The visual hierarchy derives from a logical hierarchy containing resources in dependency relationships with one another. The logical hierarchy is a data model, while the visual hierarchy is a graphical representation of a logical hierarchy), the plurality of object records including:
a resource object record for each resource (Paragraph 82 discloses a logical hierarchy offers a tree-based data model describing a web of dependency relationships between resource profiles. Paragraph 88 discloses by using its tree-based data model, logical hierarchy 30 can organize information into tiers, with parent-child relationships between entities of adjacent tiers. The parent-child relationships are based on dependency relationships: for instance, parent resource profiles can be dependent upon child resource profiles. Alternatively, parent resource profiles can provide to multiple child resource profiles. The child resource profiles are the resource object record for the child resource), each resource object further including record storing at least a compliance attribute and, a criticality attribute, and a protected-status attribute for the corresponding resource; the protected-status attribute having a value selected from at least protected, protected-with-warnings, and not-protected (Paragraph 182 reveals each rendered object for resource profile contains information such as rendering database ID specifying its referenced resource profile, severity level, positional information, and other attributes necessary. Paragraphs 19-20 reveal the resource profile includes a status and associating the status with a severity. Associating the status with a severity includes a using a status metric associated with the monitored resource profile. The method include acquiring notice of a change in the status, updating the severity; and re-rendering the hierarchy in a fishbone layout, to include rendering the monitored resource profile to indicate the updated severity. The severity includes applying an application-wide override to deviate from a behavior indicated by the status metric. The deviation includes suppressing a change in severity. Paragraph 17 discloses the status includes acquiring information about properties of the monitored resource that have changed in the most recent interval. Paragraphs 64-65 the status of an example resource can be trouble-free, warning, or error. Therefore, the reference resource profile can be the compliance attribute, the severity level is the criticality attribute, and the protected status attribute is the status (where warning label can be selected)); and
a resource-group object record for each resource group (Paragraph 82 discloses a logical hierarchy offers a tree-based data model describing a web of dependency relationships between resource profiles. Paragraph 88 discloses by using its tree-based data model, logical hierarchy 30 can organize information into tiers, with parent-child relationships between entities of adjacent tiers. The parent-child relationships are based on dependency relationships: for instance, parent resource profiles can be dependent upon child resource profiles. Alternatively, parent resource profiles can provide to multiple child resource profiles. Therefore, the parent resource profiles are the resource group object record for the parent resource);
applying compliance and criticality rules, including propagation logic, to the object records in the R-graph based on the dependency relationships and the nested group relationships (Paragraph 17 discloses the monitored resource profile includes a propagation rule for how the acquired status should propagate to dependent resource profiles that are in dependency relationships (this relationship include nested group relationship, see also paragraphs 76-78) with the monitored resource profile), the applying comprising:
propagating compliance values and, criticality values, and protected-status values from resource object records representing child resources to and a resource-group object record representing a parent resource group (Paragraphs 17, 71, and 200 disclose the monitored resource profile includes a propagation rule for how the acquired status should propagate to dependent resource profiles that are in dependency relationships with the monitored resource profile. Thus, the prior art discloses how a status (or multiple statuses) should propagate from dependent resource profile/child to the monitored resource profile/parent);
determining, for the resource-group object record, a propagated compliance attribute and a propagated criticality attribute based at least in part on the compliance attributes, criticality attributes, and protected-status attributes of the child resources (Paragraph 71 discloses obtaining status values that are derived from states of the associated resource representation. The derivation is given by a status metric. Status metric determines the states that status value represents and how their values are weighed, status metric can represent a context through its choice of states and through the outputs that it assigns. Paragraph 200 discloses monitored agent determines, based on resource profiles, if a condition exists for which it should raise alarm); and
setting the propagated compliance attribute of the resource-group object record to a non-compliant value or a warning value…(Paragraphs 64-65 disclose the status of an example resource can be trouble-free, warning, or error. Therefore, propagated compliance attribute is set to warning status or error status );and
displaying a domain-specific view of the R-graph ,for an operational scope of the data processing environment, the domain-specific view including the resource-group object record and visually indicating the propagated compliance attribute and the propagated criticality attribute for the operational scope (Paragraph 21 discloses displaying the status (which can be the propagated compliance attribute and the propagated criticality attribute) of networked resources. The method includes acquiring a logical hierarchy that includes resource profiles, as well as dependency relationships among the resource profiles. The resource profiles represent networked resources. The method also includes deriving a visual hierarchy from the logical hierarchy, where components of the visual hierarchy correspond to components of the logical hierarchy, such that the visual hierarchy is a tree. The method includes rendering the visual hierarchy in a fishbone. Paragraph 24 discloses the fishbone layouts each feature a hierarchy with resource profiles and dependency relationships among the resource profiles, where the resource profiles represent networked resources. Each hierarchy shares a common root. Preferred embodiments with regards to one or more fishbone layouts in the snowflake layout include one or more of the features already described with regards to a fishbone layout).
Sylor does not teach, but Maes teaches setting a propagated compliance attribute of the resource-group object record to a non-compliant value or a warning value when at least one child resource object record has a not-protected value or a protected-with-warnings value according to the propagation logic (Figure 9 and paragraphs 188-190 reveal a propagated compliance attribute of the parent/Service C 1004 has a critical warning notification associated with it. When the user selects service C, the user sees the child topology represented by Figure 10, where there is a warning value associated a node of the child graph).
It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify Sylor’s teaching of monitoring software detected problems and potential problems with network resources with Maes’s teachings of setting a propagated compliance attribute of the resource-group object record to a warning value when at least one child resource object has-warnings value according to the propagation logic such that the system can autonomously or semi-autonomously remediate any events or incidents that may be detected from the monitoring of the instantiated service or provided via an information technology service management system (ITSM) (Paragraph 28 of Maes).
As to claim 5, the combination of Sylor in view of Maes teaches additionally wherein the R-graph consists of a hierarchy of objects, and the domain-specific view is further generated by applying inheritance attributes of the compliance and criticality rules to the hierarchy of objects (Sylor: Paragraph 49 discloses a hierarchical status display process arranges the resources for display in a visual hierarchy (thus a graph). The visual hierarchy derives from a logical hierarchy containing resources in dependency relationships with one another. The logical hierarchy is a data model, while the visual hierarchy is a graphical representation of a logical hierarchy. Paragraph 82 discloses a logical hierarchy offers a tree-based data model describing a web of dependency relationships between resource profiles. Paragraph 88 discloses by using its tree-based data model, logical hierarchy 30 can organize information into tiers, with parent-child relationships between entities of adjacent tiers. The parent-child relationships are based on dependency relationships: for instance, parent resource profiles can be dependent upon child resource profiles. Paragraph 21 discloses displaying the status (which can be the propagated compliance attribute and the propagated criticality attribute) of networked resources. The method includes acquiring a logical hierarchy that includes resource profiles, as well as dependency relationships among the resource profiles. The resource profiles represent networked resources. The method also includes deriving a visual hierarchy from the logical hierarchy, where components of the visual hierarchy correspond to components of the logical hierarchy, such that the visual hierarchy is a tree. The method includes rendering the visual hierarchy in a fishbone. Paragraph 24 discloses the fishbone layouts each feature a hierarchy with resource profiles and dependency relationships among the resource profiles, where the resource profiles represent networked resources. Each hierarchy shares a common root. Preferred embodiments with regards to one or more fishbone layouts in the snowflake layout include one or more of the features already described with regards to a fishbone layout).
As to claim 6, the combination of Sylor in view of Maes teaches wherein the domain-specific view is for an entire enterprise, a department within the enterprise, an application, or a service (Sylor: Paragraph 49 discloses a hierarchical status display process arranges the resources for display in a visual hierarchy (thus a graph). Paragraph 51 reveals resources include hardware, applications, services, business processes, organizational structures (such as business units within an enterprise, or departments within a university), paths within a network, and other network resources. Hardware resources include clients, servers, routers, switches, and NIC's, as well as peripheral devices (such as disk drives) and networked devices (such as printers and networked storage)).
As to claim 7, Sylor teaches a computer program product embodied in one or more non-transitory computer readable storage media, the computer program product storing computer program instructions that (Claim 29 and paragraphs 25 and 59 disclose a computer usable medium having computer readable program code means embodied therein, including a processor, a main memory, a visual display, a storage device, and a network connection, the program code means comprising: computer readable program code means for causing a computer to represent a hierarchy including a plurality of resource profiles and a plurality of dependency relationships among resource profiles in the plurality of resource profiles, where the resource profiles represent networked resources; computer readable program code means for causing the computer to acquire a status of a monitored resource profile in the plurality of resource profiles; and computer readable program code means for causing the computer to render the hierarchy in a fishbone layout, including rendering a visual representation of the status of the monitored resource profile. Paragraphs 56-57 disclose computer instructions resident in main memory. A processor can access main memory to execute the computer instructions for operating system), when executed by a data processing system cause the data processing system to perform operations for assessing data protection resilience status of a data processing environment (Paragraph 23 discloses the invention features a computing apparatus which includes a processor and main memory; abstract discloses method for displaying the status of network resources. Paragraph 2 discloses the method relates to network monitoring. Paragraph 3 discloses network monitoring software detects problems and potential problems with network resources. The network monitoring software is therefore concerned with how problems can propagate from one resource to the next), the operation comprising:
generating a model of data processing resources within the data processing environment, the model identifying resources, resource groups each comprising a plurality of the resources, and nested group relationships among the resource groups (Paragraph 82 discloses a logical hierarchy offers a tree-based data model describing a web of dependency relationships between resource profiles. Paragraph 88 discloses by using its tree-based data model, logical hierarchy 30 can organize information into tiers, with parent-child relationships between entities of adjacent tiers. The parent-child relationships are based on dependency relationships: for instance, parent resource profiles can be dependent upon child resource profiles. Alternatively, parent resource profiles can provide to multiple child resource profiles, as with a server that provides multiple networked services, while each of the networked services (for instance, DNS, file sharing, and network security) provides its features to multiple software applications);
generating, in memory (Paragraph 23 discloses the invention features a computing apparatus which includes a processor and main memory), a data resilience graph (R-graph) based on the model, the R- graph comprising a plurality of object records and dependency relationships between the object records (Paragraph 49 discloses a hierarchical status display process arranges the resources for display in a visual hierarchy (thus a graph). The visual hierarchy derives from a logical hierarchy containing resources in dependency relationships with one another. The logical hierarchy is a data model, while the visual hierarchy is a graphical representation of a logical hierarchy), the plurality of object records including:
a resource object record for each resource (Paragraph 82 discloses a logical hierarchy offers a tree-based data model describing a web of dependency relationships between resource profiles. Paragraph 88 discloses by using its tree-based data model, logical hierarchy 30 can organize information into tiers, with parent-child relationships between entities of adjacent tiers. The parent-child relationships are based on dependency relationships: for instance, parent resource profiles can be dependent upon child resource profiles. Alternatively, parent resource profiles can provide to multiple child resource profiles. The child resource profiles are the resource object record for the child resource), each resource object further including record storing at least a compliance attribute and, a criticality attribute, and a protected-status attribute for the corresponding resource; the protected-status attribute having a value selected from at least protected, protected-with-warnings, and not-protected (Paragraph 182 reveals each rendered object for resource profile contains information such as rendering database ID specifying its referenced resource profile, severity level, positional information, and other attributes necessary. Paragraphs 19-20 reveal the resource profile includes a status and associating the status with a severity. Associating the status with a severity includes a using a status metric associated with the monitored resource profile. The method include acquiring notice of a change in the status, updating the severity; and re-rendering the hierarchy in a fishbone layout, to include rendering the monitored resource profile to indicate the updated severity. The severity includes applying an application-wide override to deviate from a behavior indicated by the status metric. The deviation includes suppressing a change in severity. Paragraph 17 discloses the status includes acquiring information about properties of the monitored resource that have changed in the most recent interval. Paragraphs 64-65 the status of an example resource can be trouble-free, warning, or error. Therefore, the reference resource profile can be the compliance attribute, the severity level is the criticality attribute, and the protected status attribute is the status (where warning label can be selected)); and
a resource-group object record for each resource group (Paragraph 82 discloses a logical hierarchy offers a tree-based data model describing a web of dependency relationships between resource profiles. Paragraph 88 discloses by using its tree-based data model, logical hierarchy 30 can organize information into tiers, with parent-child relationships between entities of adjacent tiers. The parent-child relationships are based on dependency relationships: for instance, parent resource profiles can be dependent upon child resource profiles. Alternatively, parent resource profiles can provide to multiple child resource profiles. Therefore, the parent resource profiles are the resource group object record for the parent resource);
applying compliance and criticality rules, including propagation logic, to the object records in the R-graph based on the dependency relationships and the nested group relationships (Paragraph 17 discloses the monitored resource profile includes a propagation rule for how the acquired status should propagate to dependent resource profiles that are in dependency relationships (this relationship include nested group relationship, see also paragraphs 76-78) with the monitored resource profile), the applying comprising:
propagating compliance values and, criticality values, and protected-status values from resource object records representing child resources to and a resource-group object record representing a parent resource group (Paragraphs 17, 71, and 200 disclose the monitored resource profile includes a propagation rule for how the acquired status should propagate to dependent resource profiles that are in dependency relationships with the monitored resource profile. Thus, the prior art discloses how a status (or multiple statuses) should propagate from dependent resource profile/child to the monitored resource profile/parent);
determining, for the resource-group object record, a propagated compliance attribute and a propagated criticality attribute based at least in part on the compliance attributes, criticality attributes, and protected-status attributes of the child resources (Paragraph 71 discloses obtaining status values that are derived from states of the associated resource representation. The derivation is given by a status metric. Status metric determines the states that status value represents and how their values are weighed, status metric can represent a context through its choice of states and through the outputs that it assigns. Paragraph 200 discloses monitored agent determines, based on resource profiles, if a condition exists for which it should raise alarm); and
setting the propagated compliance attribute of the resource-group object record to a non-compliant value or a warning value…(Paragraphs 64-65 disclose the status of an example resource can be trouble-free, warning, or error. Therefore, propagated compliance attribute is set to warning status or error status );and
displaying a domain-specific view of the R-graph ,for an operational scope of the data processing environment, the domain-specific view including the resource-group object record and visually indicating the propagated compliance attribute and the propagated criticality attribute for the operational scope (Paragraph 21 discloses displaying the status (which can be the propagated compliance attribute and the propagated criticality attribute) of networked resources. The method includes acquiring a logical hierarchy that includes resource profiles, as well as dependency relationships among the resource profiles. The resource profiles represent networked resources. The method also includes deriving a visual hierarchy from the logical hierarchy, where components of the visual hierarchy correspond to components of the logical hierarchy, such that the visual hierarchy is a tree. The method includes rendering the visual hierarchy in a fishbone. Paragraph 24 discloses the fishbone layouts each feature a hierarchy with resource profiles and dependency relationships among the resource profiles, where the resource profiles represent networked resources. Each hierarchy shares a common root. Preferred embodiments with regards to one or more fishbone layouts in the snowflake layout include one or more of the features already described with regards to a fishbone layout).
Sylor does not teach, but Maes teaches setting a propagated compliance attribute of the resource-group object record to a non-compliant value or a warning value when at least one child resource object record has a not-protected value or a protected-with-warnings value according to the propagation logic (Figure 9 and paragraphs 188-190 reveal a propagated compliance attribute of the parent/Service C 1004 has a critical warning notification associated with it. When the user selects service C, the user sees the child topology represented by Figure 10, where there is a warning value associated a node of the child graph).
It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify Sylor’s teaching of monitoring software detected problems and potential problems with network resources with Maes’s teachings of setting a propagated compliance attribute of the resource-group object record to a warning value when at least one child resource object has-warnings value according to the propagation logic such that the system can autonomously or semi-autonomously remediate any events or incidents that may be detected from the monitoring of the instantiated service or provided via an information technology service management system (ITSM) (Paragraph 28 of Maes).
As to claim 8, the combination of Sylor in view of Maes teaches additionally wherein the R-graph consists of a hierarchy of objects, and the domain-specific view is further generated by applying inheritance attributes of the compliance and criticality rules to the hierarchy of objects (Sylor: Paragraph 49 discloses a hierarchical status display process arranges the resources for display in a visual hierarchy (thus a graph). The visual hierarchy derives from a logical hierarchy containing resources in dependency relationships with one another. The logical hierarchy is a data model, while the visual hierarchy is a graphical representation of a logical hierarchy. Paragraph 82 discloses a logical hierarchy offers a tree-based data model describing a web of dependency relationships between resource profiles. Paragraph 88 discloses by using its tree-based data model, logical hierarchy 30 can organize information into tiers, with parent-child relationships between entities of adjacent tiers. The parent-child relationships are based on dependency relationships: for instance, parent resource profiles can be dependent upon child resource profiles. Paragraph 21 discloses displaying the status (which can be the propagated compliance attribute and the propagated criticality attribute) of networked resources. The method includes acquiring a logical hierarchy that includes resource profiles, as well as dependency relationships among the resource profiles. The resource profiles represent networked resources. The method also includes deriving a visual hierarchy from the logical hierarchy, where components of the visual hierarchy correspond to components of the logical hierarchy, such that the visual hierarchy is a tree. The method includes rendering the visual hierarchy in a fishbone. Paragraph 24 discloses the fishbone layouts each feature a hierarchy with resource profiles and dependency relationships among the resource profiles, where the resource profiles represent networked resources. Each hierarchy shares a common root. Preferred embodiments with regards to one or more fishbone layouts in the snowflake layout include one or more of the features already described with regards to a fishbone layout).
As to claim 9, the combination of Sylor in view of Maes teaches wherein the domain-specific view is for an entire enterprise, a department within the enterprise, an application, or a service (Sylor: Paragraph 49 discloses a hierarchical status display process arranges the resources for display in a visual hierarchy (thus a graph). Paragraph 51 reveals resources include hardware, applications, services, business processes, organizational structures (such as business units within an enterprise, or departments within a university), paths within a network, and other network resources. Hardware resources include clients, servers, routers, switches, and NIC's, as well as peripheral devices (such as disk drives) and networked devices (such as printers and networked storage)).
As to claim 12, the combination of Sylor in view of Maes teaches wherein the domain-specific view presents the propagated compliance attributes and criticality attributes color-coded according to protection tiers and policy thresholds (Sylor: paragraphs 19-20 disclose the monitored resource profile is rendered with a visual trait indicating the severity status. The visual trait includes a color selected from a plurality of colors representing a severity scale. See also paragraphs 134-135. Figure 9 and paragraphs 188-190 reveal a propagated compliance attribute of the parent/Service C 1004 has a critical warning notification associated with it. When the user selects service C, the user sees the child topology represented by Figure 10, where there is a warning value associated a node of the child graph).
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: Maor et al US 20210203684 (hereinafter Maor).
Maor teaches method for assessing data-protection resilience status of a data processing environment (Abstract discloses the detection of a risky edge in a lateral movement path is detected by determining the weakest point in the configuration of the user accounts, groups, and devices having access to the resources of a tenant of the cloud service); generating a data resilience graph, the R-graph comprising a plurality of object records and dependency relationships between object records (Paragraph 31 discloses LMP graph generation component generates a lateral movement graph, for each tenant, representing the relationships between the users, devices, groups associated with a tenant. In one aspect, the LMP graph generation component retrieves data from the management service regarding the relationships between the users, devices, and logon sessions of a tenant in order to construct the LMP graph for the tenant) as disclosed in claims 1, 4, and 7.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to FELICIA FARROW whose telephone number is (571)272-1856. The examiner can normally be reached M - F 7:30am-4:00pm (EST).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached at (571)270-5143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/F.F/Examiner, Art Unit 2437
/ALI S ABYANEH/Primary Examiner, Art Unit 2437