DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Continued Examination Under 37 CFR 1.114
A request for continued examination (RCE) under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on May 12, 2026 has been entered.
Response to Amendments
This office action is responsive to application 18/529,923 where the Applicant filed an RCE on June 12, 2026 for the corresponding amendments filed on May 12, 2026. Claims 2, 34, and 36 are amended, claim 38 is added as a new claim, and claims 2, 10, 18, and 33-38 remain for examination.
Response to Arguments
The Examiner has fully considered the Applicant’s arguments filed with the RCE, and the Examiner responds as provided below.
Regarding the Applicant’s response at pages 8 and 9 of the Remarks that concerns the § 101 rejection, the amendments to the independent claims are sufficient to bring the claimed subject matter withing the purview of eligible patentable subject matter, and the § 101 rejection is withdrawn.
Regarding the Applicant’s response at pages 9 and 10 of the Remarks that concerns the § 103 rejection, the Applicant’s arguments in conjunction with the claim amendments are persuasive, and consequently the Examiner conducted a new prior art search. The Applicant’s arguments are now moot with respect to the pending claims because the arguments do not apply to some of the references currently used in the rejection of the aforementioned claims as detailed below.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The following conventions apply to the mapping of the prior art to the claims:
Italicized text – claim language.
Parenthetical plain text – Examiner’s citation and explanation.
Citation without an explanation – an explanation has been previously provided for the respective limitation(s).
Quotation marks – language quoted from a prior art reference.
Underlining – language quoted from a claim.
Brackets – material altered from either a prior art reference or a claim, which includes the Examiner’s explanation that relates a claim limitation to the quoted material of a reference.
Braces – a limitation taught by another reference, but the limitation is presented with the mapping of the instant reference for context.
Numbered superscript – a first phrase to be moved upwards to the primary reference analysis.
Lettered superscript – a second phrase to be moved after the movement of the first phrase from which it was lifted, or more succinctly, move numbered material first, lettered material last.
A. Claims 2, 18, and 33-37 are rejected under 35 U.S.C. 103 as being unpatentable over Kodavanji et al. (US 2020/0250340, “Kodavanji”) in view of Dash et al. (US 10,963,590, “Dash”) and Rudden et al. (US 10,304,442, “Rudden”), and further in view of Su et al. (US 2018/0357226, “Su”) and Harrison et al. (US 2009/0138938, “Harrison”).
Regarding Claim 2
Kodavanji discloses
A computer-implemented method (Fig. 1, ¶ [0010], “Further, the computing systems may handle [via a computer implemented method] the PII, such as store, process, backup, or transfer the PII for various reasons.”) comprising:
generating a machine-readable representation of processing operations (¶¶ [0031]-[0032], “To facilitate compliance with the security rules during the handling of the first PII 204, the hosting system 101 may add [generate] metadata [machine-readable] tags to the first PII 204.”; and ¶ [0059], “For instance, based on the first metadata tag 210, if the compliance module 402 determines that the first PII 204 is to be protected using a particular minimum encryption level [with each encryption level representing one processing operation], the compliance module 402 can utilize the data encryption module 418 to encrypt the first PII 204 accordingly [amongst a plurality of processing operations].”),
wherein the processing operations are based on one or more algorithms applied to data by a computing resource (¶ [0059], “Further, based on the first metadata tag 210 [and associated encryption processing operation], the compliance module 402 may determine that the first PII [data] 204 is to be protected using [based on] a particular sanitization algorithm, and may instruct the data sanitization module 416 to utilize the appropriate sanitization algorithm to sanitize the first PII 204.”; and Fig. 1, ¶ [0010], “Further, the computing systems [computing resource] may handle the PII, such as store, process, backup, or transfer the PII for various reasons.”);
1 …determining one or more privacy-preserving techniques to be applied to the data (¶ [0059], “Further, based on the first metadata tag 210, the compliance module 402 may determine that the first PII [data] 204 is to be protected using a particular sanitization algorithm [as a privacy-preserving technique],…”) based on data privacy requirements for the data and the machine-readable representation of the processing operations to be performed on the data (¶¶ [0058]-[0059], “The compliance module 402 may handle the PII [data] received from the hosting system 101 based on the metadata tags [as machine-readable representations that are associated with particular processing operations to be performed on the data/PII] such that the compliance rules [data privacy requirements] associated with the PII [for the data] are complied with.”);
2 …;
3 …applying the determined one or more privacy-preserving techniques (¶ [0059], “For instance, based on the first metadata tag 210, if the compliance module 402 determines that the first PII 204 is to be protected using a particular minimum encryption [privacy-preserving technique] level, the compliance module 402 can utilize the data encryption module 418 to encrypt [apply the privacy-preserving technique] the first PII 204 accordingly.”),
wherein automatically applying the determined one or more privacy-preserving techniques (¶ [0059]) comprises:
4 …;
5 …; and
6 …that specify the use of the privacy-preserving techniques for encrypted data processing (¶ [0059], “For instance, based on the first metadata tag 210, if the compliance module 402 determines that the first PII 204 is to be protected using a particular minimum encryption [privacy-preserving technique] level, the compliance module 402 can utilize the data encryption module 418 to encrypt [process] the first PII 204 accordingly.”).
Kodavanji doesn’t disclose
1 automatically…
2 wherein automatically determining the one or more privacy-preserving techniques comprises quantifying compliance with the data privacy requirements when the data are processed in accordance with the processing operations;
3 automatically…
4 applying natural language processing to the data privacy requirements;
5 generating the data privacy requirements as the machine-readable representation.
6 deploying the machine-readable representation files…
Dash, however, discloses
1 automatically… (Col. 5:5-15, “Accordingly, anonymization logic 160 is provided on anonymization server 135. Briefly, the anonymization logic 160 may be configured to cause the server 135 to automatically anonymize (e.g., identically replace the sensitive information of) the service request document(s) stored in service request document repository 155 in order to generate anonymized service request documents 165.”, and further noting that it would be obvious to one skilled in the art to “automatically” perform functions with a computer, as opposed to relying upon manual actions by an administrator)
2 automatically… (Col. 5:5-15)
Regarding the combination of Kodavanji and Dash, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the PII security system of Kodavanji to arrive at the claimed invention. KSR establishes that a rationale for obviousness is proven by showing a “use of [a] known technique to improve similar devices in the same way.” See MPEP § 2143(I)(C).
To substantiate the conclusion of obviousness under this KSR rationale, the Examiner finds pursuant to MPEP § 2143(I)(C):
1) the prior art contained a base system, namely the PII security system of Kodavanji, upon which the claimed invention can be seen as an “improvement” through the use of a PII automation feature;
2) the prior art contained a “comparable” system, namely the data anonymization system of Dash, that has been improved in the same way as the claimed invention through the PII automation feature; and
3) one of ordinary skill in the art could have applied the known improvement technique of applying the PII automation feature to the base PII security system of Kodavanji, and the results would have been predictable to one of ordinary skill in the art.
Rudden, however, discloses
3 applying natural language processing to the data privacy requirements (Col. 10:43-53, “Further features described herein include the use [application] of natural language processing and machine learning algorithms to harvest dynamic based privacy requirements [i.e., the “harvesting” relies upon the application of NPL to data privacy requirements] (‘locality’) and creation of contextual-based ontological systems that are employed through a rule-based engine.”; and Col. 7:51-8:6, “Contextual understanding [such as natural language processing] informs of privacy requirements applicable to the digital information, and the selected training sets [or alternatively the application of NLP] can be reflective of those privacy requirements applicable to digital information.”);
4 generating the data privacy requirements as the machine-readable representation (Col. 10:43-53, “A machine learning capability is leveraged [generated] to build an ontology that feeds an NLP-based detection mechanism [via a machine-readable representation of the data privacy requirements] to trigger rules in the system.”).
Regarding the combination of Kodavanji-Dash and Rudden, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the PII security system of Kodavanji-Dash to arrive at the claimed invention. KSR establishes that a rationale for obviousness is proven by showing a “use of [a] known technique to improve similar devices in the same way.” See MPEP § 2143(I)(C).
To substantiate the conclusion of obviousness under this KSR rationale, the Examiner finds pursuant to MPEP § 2143(I)(C):
1) the prior art contained a base system, namely the PII security system of Kodavanji-Dash, upon which the claimed invention can be seen as an “improvement” through the use of a NLP feature;
2) the prior art contained a “comparable” system, namely the PII system of Rudden, that has been improved in the same way as the claimed invention through the NLP feature; and
3) one of ordinary skill in the art could have applied the known improvement technique of applying the NLP feature to the base PII security system of Kodavanji-Dash, and the results would have been predictable to one of ordinary skill in the art.
Su, however, discloses
2 wherein {automatically (Dash Col. 5:5-15)} determining the one or more {privacy-preserving techniques (Kodavanji ¶ [0059])} comprises quantifying compliance with the data privacy requirements when the data are processed in accordance with the processing operations (¶ [0025], “The security and compliance system 118 may be configured to analyze data, usage pattern, and security and compliance policies [i.e., data privacy requirements when the data are processed] (e.g., data retention policies, data loss protection policies, etc.,) associated with a tenant of the hosted service in order to create a model for importing tenant data based on the analysis.”; and “Example machine learning approaches [that quantify the compliance] may include, but are not limited to, linear regression, logistic regression, decision tree, various Bayesian algorithms, K-means, neural networks, and random forest.”);
Regarding the combination of Kodavanji-Dash-Rudden and Su, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the PII security system of Kodavanji-Dash-Rudden to arrive at the claimed invention. KSR establishes that a rationale for obviousness is proven by showing a “use of [a] known technique to improve similar devices in the same way.” See MPEP § 2143(I)(C).
To substantiate the conclusion of obviousness under this KSR rationale, the Examiner finds pursuant to MPEP § 2143(I)(C):
1) the prior art contained a base system, namely the PII security system of Kodavanji-Dash-Rudden, upon which the claimed invention can be seen as an “improvement” through the use of a policy compliance feature;
2) the prior art contained a “comparable” system, namely the data management system of Su, that has been improved in the same way as the claimed invention through the policy compliance feature; and
3) one of ordinary skill in the art could have applied the known improvement technique of applying the policy compliance feature to the base PII security system of Kodavanji-Dash-Rudden, and the results would have been predictable to one of ordinary skill in the art.
Harrison, however, discloses
6 deploying the machine-readable representation files… (¶ [0010], “…creating one or more policy [specifying privacy-preserving techniques] instances, each based on one of the templates and instantiating the template for identified sets of hosts within the network to which the usage control model is to be applied, deploying the policy instances by generating and providing one- or: more configuration [machine-readable] files for provisioning corresponding policy enforcement points within the network.”)
Regarding the combination of Kodavanji-Dash-Rudden-Su and Harrison, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the PII security system of Kodavanji-Dash-Rudden-Su to arrive at the claimed invention. KSR establishes that a rationale for obviousness is proven by showing a “use of [a] known technique to improve similar devices in the same way.” See MPEP § 2143(I)(C).
To substantiate the conclusion of obviousness under this KSR rationale, the Examiner finds pursuant to MPEP § 2143(I)(C):
1) the prior art contained a base system, namely the PII security system of Kodavanji-Dash-Rudden-Su, upon which the claimed invention can be seen as an “improvement” through the use of a configuration file feature;
2) the prior art contained a “comparable” system, namely the data management system of Harrison, that has been improved in the same way as the claimed invention through the configuration file feature; and
3) one of ordinary skill in the art could have applied the known improvement technique of applying the configuration file feature to the base PII security system of Kodavanji-Dash-Rudden-Su, and the results would have been predictable to one of ordinary skill in the art.
Regarding Claim 18
Kodavanji in view of Dash and Rudden, and further in view of Su and Harrison (“Kodavanji-Dash-Rudden-Su-Harrison”) discloses the computer-implemented method of claim 2, and Kodavanji further discloses
further comprising:
receiving information on processing operations that are to be performed on data (Fig. 4, ¶ [0053], “The data processing center 208 may be connected to the hosting system 101 through a communication network (not shown in FIG. 4) to receive data 400 from the hosting system 101. The data 400 may include the encrypted tags, such as the first metadata tag [that possesses information on processing operations to be performed on the data] 210 and the second metadata tag 214, and the encrypted PII, such as the first PII 204.”),
the information specifying the one or more algorithms to be applied to the data (¶ [0059], “Further, based on the first metadata tag [possessing information] 210, the compliance module 402 may determine that the first PII [data] 204 is to be protected using a particular [specified] sanitization algorithm, and may instruct the data sanitization module 416 to utilize the appropriate sanitization algorithm to sanitize the first PII 204.”).
Regarding Claim 33
With respect to claim 33, a corresponding reasoning as given earlier for claim 2 applies, mutatis mutandis, to the subject matter of claim 33. Therefore, claim 33 is rejected, for similar reasons, under the grounds set forth for claim 2.
Regarding Independent Claim 34
With respect to claim 34, a corresponding reasoning as given earlier for claims 2 and 18 applies, mutatis mutandis, to the subject matter of claim 34. Therefore, claim 34 is rejected, for similar reasons, under the grounds set forth for claims 2 and 18.
Regarding Claim 35
Kodavanji-Dash-Rudden discloses the processing device for configuring data protection settings of a system of claim 34, and Kodavanji further discloses
A processing device for configuring data protection settings of a system (¶¶ [0058]-[0059]), comprising:
an integrated circuit adapted to perform the method of claim 34 (¶¶ [0018]-[0019], “FIG. 1 illustrates a system 100 to facilitate compliance with security rules associated with Personally Identifiable Information (PII), according to an example implementation of the present subject matter.”; and “The hosting system 101 includes a processor [integrated circuit] 102 and a memory 104 coupled to the processor 102.”).
Regarding Independent Claim 36
With respect to claim 36, a corresponding reasoning as given earlier for claims 2 and 18 applies, mutatis mutandis, to the subject matter of claim 36. Therefore, claim 36 is rejected, for similar reasons, under the grounds set forth for claims 2 and 18.
Regarding Claim 37
With respect to claim 37, a corresponding reasoning as given earlier for claim 35 applies, mutatis mutandis, to the subject matter of claim 37. Therefore, claim 37 is rejected, for similar reasons, under the grounds set forth for claim 35.
B. Claim 10 is rejected under 35 U.S.C. 103 as being unpatentable over Kodavanji in view of Dash, Rudden Su, and Harrison, and further in view of Kothari et al. (US 8,694,646, “Kothari”).
Regarding Claim 10
Kodavanji-Dash-Rudden-Su-Harrison discloses the computer-implemented method of claim 2, and Kodavanji further discloses
wherein the one or more privacy-preserving techniques (¶ [0059]) are…1
Dash further discloses
1 automatically…a (Col. 5:5-15)
Regarding the combination of Kodavanji and Dash, the rationale to combine is the same as provided for claim 2 due to the overlapping subject matter of claims 2 and 10.
Kodavanji-Dash-Rudden-Su-Harrison doesn’t disclose
a …determined from a set of predefined techniques.
Kothari, however, discloses
a …determined from a set of predefined techniques (Col. 7:45-52, “The user may select one or more of the [predefined] anonymization strategies [and corresponding techniques] to be applied to various data fields of the application, using the user computer.”; Col. 9:14-33, “The anonymization technique selected [determined] for a data field may be based upon multiple factors. One of the factors is level of desired security. One of the other factors is data attribute preservation for the data field.”; and Col. 9:34-45, “Anonymization techniques may be broadly divided into two [predefined] categories. One, a token based anonymization. The token based anonymization may be implemented in the tokenization module 412 and may require local storage of the tokens in the token vault 414. Another technique is to use a symmetric key encryption based anonymization.”).
Regarding the combination of Kodavanji-Dash-Rudden-Su-Harrison and Kothari, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the PII security system of Kodavanji-Dash-Rudden-Su-Harrison to arrive at the claimed invention. KSR establishes that a rationale for obviousness is proven by showing a “use of [a] known technique to improve similar devices in the same way.” See MPEP § 2143(I)(C).
To substantiate the conclusion of obviousness under this KSR rationale, the Examiner finds pursuant to MPEP § 2143(I)(C):
1) the prior art contained a base system, namely the PII security system of Kodavanji-Dash-Rudden-Su-Harrison, upon which the claimed invention can be seen as an “improvement” through the use of a predefined techniques feature;
2) the prior art contained a “comparable” system, namely the data anonymization system of Kothari, that has been improved in the same way as the claimed invention through the predefined techniques feature; and
3) one of ordinary skill in the art could have applied the known improvement technique of applying the predefined techniques feature to the base PII security system of Kodavanji-Dash-Rudden-Su-Harrison, and the results would have been predictable to one of ordinary skill in the art.
C. Claim 38 is rejected under 35 U.S.C. 103 as being unpatentable over Kodavanji in view of Dash, Rudden Su, and Harrison, and further in view of Mireshghallah et al. (US 2021/0390188 “Mireshghallah”).
Regarding Claim 38
Kodavanji-Dash-Rudden-Su-Harrison discloses the computer-implemented method of claim 2, and Kodavanji further discloses
wherein automatically determining the one or more privacy-preserving techniques (¶ [0059]) further comprises…1.
Kodavanji-Dash-Rudden-Su-Harrison doesn’t disclose
1 …solving an optimization problem to identify the one or more privacy-preserving techniques that result in a metric having a maximum or minimum value.
Mireshghallah, however, discloses
1 …solving an optimization problem to identify the one or more privacy-preserving techniques that result in a metric having a maximum or minimum value (¶ [0072], “We provide an analytical formulation of the stochasticity learning problem as a constrained convex optimization program that maximizes the privacy [identifying one privacy-preserving technique] by minimizing the mutual information between the raw input and the data sent to the cloud subject to a restriction on the degradation of the DNN utility (accuracy).”).
Regarding the combination of Kodavanji-Dash-Rudden-Su-Harrison and Mireshghallah, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the PII security system of Kodavanji-Dash-Rudden-Su-Harrison to arrive at the claimed invention. KSR establishes that a rationale for obviousness is proven by showing a “use of [a] known technique to improve similar devices in the same way.” See MPEP § 2143(I)(C).
To substantiate the conclusion of obviousness under this KSR rationale, the Examiner finds pursuant to MPEP § 2143(I)(C):
1) the prior art contained a base system, namely the PII security system of Kodavanji-Dash-Rudden-Su-Harrison, upon which the claimed invention can be seen as an “improvement” through the use of an optimization feature;
2) the prior art contained a “comparable” system, namely the data privacy system of Mireshghallah, that has been improved in the same way as the claimed invention through the optimization feature; and
3) one of ordinary skill in the art could have applied the known improvement technique of applying the optimization feature to the base PII security system of Kodavanji-Dash-Rudden-Su-Harrison, and the results would have been predictable to one of ordinary skill in the art.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to D'ARCY WINSTON STRAUB whose telephone number is (303)297-4405. The examiner can normally be reached Monday-Friday 9:00-5:00 Mountain Time.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, WILLIAM KORZUCH can be reached at (571)272-7589. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/D'Arcy Winston Straub/Primary Examiner, Art Unit 2491