Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
Applicant’s arguments filed 07/08/2026 have been fully considered. Applicant argues the prior art fails to teach or suggest “searching the resource for a first set of a plurality of sets of sensitive features defined for the data type, wherein each set of the plurality of sets of sensitive features is defined for a different one of the plurality of data types”.
Applicant’s arguments are not persuasive as Bhaskar discloses a system that searches resources for sensitive features where each set of sensitive features are defined for data types such as images, web pages, videos, documents, PDFs, JPEGs, etc. The resources are searched for sets of sensitive features such as personally identifiable information, sensitive information in images, protected health information, confidential individual information, confidential organizational information, contracts, sales quotes, customer information, phone numbers, compensation information (see ¶ 1-5, 66, 87-89, 90-91, 94, 98-99, 104, 113-115, 116, and 118).
Applicant argues the prior art fails to teach or suggest “determining a confidentiality level of the resource relative to the data type based on confidentiality levels of those of the first set of sensitive features present in the resource”. Applicant’s arguments are not persuasive in this regard as Bhaskar discloses confidentiality levels of the resource relative to the data type based on varying confidentiality levels of the resource (¶ 88-89, 91, 94).
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(B) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
Claim(s) 53 is rejected under 35 U.S.C. 112, second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which applicant regards as the invention.
Regarding claim 53, applicant' s recitation of “wherein the confidentiality level of the resource is a sum, over each first feature in the first set of sensitive features, of a product of a number of times the first feature appears in the resource and a confidentiality level of the first feature” would have been unclear to one of ordinary skill in the art. It is unclear what is meant by a sum “over each feature in the first set of sensitive features”. It is unclear what is meant by a sum “of a product of the number of times the first feature appears”. The claims are obfuscated such that one of ordinary skill in the art at the time of the invention would not know from the claim language how to properly construe scope of the confidentiality level.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention.
Claim 20, 23, 25-27, 30, 32-34, 37, 39, 46, 48, 52, and 54 are rejected under 35 U.S.C. 103 as being unpatentable over US 20210194888 to Bhaskar in view of US 20200152213 to Chauhan.
Regarding claim 20, Bhaskar teaches a method comprising:
based on detecting a request from a user, at a browser in a first environment, to access a resource, wherein the first environment is isolated from one or more ambient environments of an endpoint (abstract, ¶ 3-4, 33, 57, 59, 63, 65-66, 108-109, receiving request for content via isolated browser),
determining that the resource comprises one or more data types from a plurality of data types known to correspond to sensitive data (¶ 3-4, 6, 88, 91, 94, determination of sensitive content and content type); and
for each data type of the one or more data types,
searching the resource for a first set of a plurality of sets of sensitive features defined for the data type, wherein each set of the plurality of sets of sensitive features is defined for a different one of the plurality of data types (¶ 1-5, 66, 87-89, 90-91, 94, 99, 104, 113-115, 116, 118; see also ¶ 120, 146, 161, 165),
determining a confidentiality level of the resource relative to the data type based on confidentiality levels of those of the first set of sensitive features present in the resource (¶ 88-89, 91, 94, determination of confidentiality level of data type);
determining whether the user has clearance to access a portion of the resource comprising data for the data type based, at least in part, on the confidentiality level (¶ 88-89, 91, 94, access based on user clearance and confidentiality level of data type);
based on determining that the user does not have clearance to access the portion of the resource comprising data for the data type, at least one of blocking the request and allowing partial access to the portion of the resource (¶ 88-91, 94, blocking request and allowing partial access to content based on clearance); and
Bhaskar fails to teach but Chauhan teaches:
based on determining that the confidentiality level of the resource is above a threshold confidentiality level for the data type, watermarking the portion of the resource with a watermark (¶ 179-183, 209-211, watermarking based on determined sensitivity/confidentiality level; ¶ 98, 145).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to include the teachings of Chauhan. The motivation to do so is that the teachings of Chauhan would have been advantageous in terms of facilitating the control of sensitive content (Chauhan, ¶ 3, 146-147, 179).
Regarding claim 23, 37, 30,
Bhaskar teaches:
wherein allowing partial access to the portion of the resource comprises hooking a renderer of the browser to instructions to at least one of locally mask and delete the data for the data type in the resource, wherein hooking the renderer of the browser to mask or delete the data comprises masking or deleting the data for the request without changing the resource at a memory location where the resource was downloaded at the endpoint (¶ 91, redacting or removing data without changing original resource).
Regarding claim 25, 32, 39,
Bhaskar teaches:
wherein allowing partial access to the portion of the resource comprises at least one of,
masking the portion of the resource when the data type is text data; masking and/or watermarking the portion of the resource when the data type is image data; and masking and/or watermarking the portion of the resource when the data type is audio data (¶ 66, 90-91, masking, watermarking, ¶ 91, text, images).
Regarding claim 26, 33,
Bhaskar teaches:
determining the confidentiality level for the data type based on clustering at least one of character strings, regular expression strings, N-grams, and text patterns for the resource (¶ 96-99, 111,114, 116, 118 sensitivity classification based on character strings, text patterns).
Claim 27 and 34 are addressed by similar rationale as claim 1.
Regarding claim 46, 48,
Bhaskar fails to teach but Chauhan teaches:
wherein the watermark comprises at least one of a uniform resource locator of the resource, a file type of the resource, a rendered web page corresponding to the resource, and content corresponding to the resource displayed in the browser (¶ 179-183, 209-211, watermarking based on determined sensitivity/confidentiality level; ¶ 98, 145). Motivation to include Chauhan is the same as presented above.
Regarding claim 52,
Bhaskar teaches:
wherein determining the confidentiality level of the resource relative to the data type comprises determining the confidentiality level based on numbers of times each of the first set of sensitive features appears in the resource (¶ 146-148, determination of confidentiality level is based on number of times set of sensitive features appears; information is extracted into tokens which are analyzed for frequency of occurrence of sensitive features)
Regarding claim 54,
Bhaskar teaches:
determining whether to partially allow access to the portion of the resource based, at least in part, on a confidentiality level of a first feature of the first set of sensitive features corresponding to the portion of the resource and a clearance level of the user for the first feature (¶ 89-91, 94, 99, 118, 165, determination to allow partial access bases on confidentiality level of resource and clearance of use for certain feature of resource; see also ).
Claim 47 is rejected under 35 U.S.C. 103 as being unpatentable over Bhaskar and Chauhan in view of US 20170024551 to Phadke.
Regarding claim 47,
Bhaskar fails to teach: determining, with a neural network, whether to watermark the portion of the resource with a visible watermark or a hidden watermark; based on determining to watermark the portion of the resource with the visible watermark, watermarking the resource with the visible watermark; and based on determining to watermark the portion of the resource with the hidden watermark, watermarking the resource with the hidden watermark.
However, but Chauhan teaches: determining, with a neural network, whether to watermark the portion of the resource with a visible watermark or a hidden watermark; based on determining to watermark the portion of the resource with the visible watermark, watermarking the resource with the visible watermark; and based on determining to watermark the portion of the resource with the hidden watermark, watermarking the resource with the hidden watermark (¶ 138, application of hidden and visible watermarking).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to include the teachings of Phadke. The motivation to do so is that the teachings of Phadke would have been advantageous in terms of facilitating watermarking for security purposes (Phadke, ¶ 138).
Claim 24, 31, 38 are rejected under 35 U.S.C. 103 as being unpatentable over Bhaskar and Chauhan in view of US 20200293684 to Harris.
Regarding claim 24, 31, 38,
Bhaskar teaches: wherein determining whether the user has clearance to access a portion of the resource comprises determining a clearance level of the user for the data type (¶ 88-89, 91, 94, access based on user clearance and confidentiality level of data type).
Bhaskar fails to teach using a machine learning model in determining a clearance level for a user. However, Harris teaches determining a clearance level for a user with a machine learning model (Harris, ¶ 95).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to include the teachings of Harris. The motivation to do so is that the teachings of Harris would have been advantageous in terms of facilitating automated privacy control (Harris, ¶ 74, 95).
CONCLUSION
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to RYAN J JAKOVAC whose telephone number is (571)270-5003. The examiner can normally be reached on 8-4 PM EST. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Oscar A. Louie can be reached on 572-270-1684. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/RYAN J JAKOVAC/Primary Examiner, Art Unit 2445