DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 05/22/2026 has been entered.
The following is a non-final action in response to communications received 05/22/2026. Claims 1, 15 have been amended. Claims 4, 13, 18 have been cancelled. Claims 21-22 have been added. Therefore claims 1-3, 5-12, 14-17, 19-22 are pending and addressed below.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-3, 5-12, 14-17, 21-22 are rejected under 35 U.S.C. 103 as being unpatentable over Arasu et al (Pub. No. US 20160306995) in view of Ortiz et al (Pub. No. US 2022/0108026).
As per claim 1, Arasu discloses a method in one or more servers for performing a join operation (…a semantically secure join operator joins two input tables into one resulting table…see par. 45), the method comprising: receiving, at a module executing in a trusted execution environment (TEE) from a first party (1P) data source, a first dataset including personal identifiable information (PII) data and non-PII data (…(table 4 and table 5: see Ailment (encrypted) and Ailment (original))…EDBMS TM framework that can be stored on a trusted machine such as computing device…an EDBMS TM framework can contain a query processor configured for receiving a query having encrypted contents and one or more encrypted records from a data store…the query processor can coordinate the execution of the query on a trusted machine and can return a query result…the query received by the query processor is a complete query, while in others, it can be an intermediate query…an intermediate query can be one of several query operations needed to process a complete query according to a query plan…when the query processor coordinates the execution of an intermediate query, the query result that is returned can be an intermediate query result…see par. 33, 35); matching, in the TEE, the first formatted PII data to second formatted PII data included in a second dataset; performing a join operation between the first dataset and the second dataset based on the matching, to generate a joined dataset (…after the encrypted records and the encrypted query contents have been decrypted, the query processor can process the query by utilizing semantically secure query operators…a semantically secure query operator can be used to execute an associated query operation on decrypted data derived from the encrypted records…semantically secure query operators remove information that can be used to identify correlations between a query parameter and a query result… a semantically secure join operator joins two input tables into one resulting table…see par. 38, 45). Arasu does not explicitly disclose pre-processing the PII data to generate first formatted PII data, the first formatted PII data conforming to a defined format; providing, to a data service operating independently of the 1P data source, the joined dataset wherein: the module implements a secure connector configured to use credentials associated with the 1P data source; and the matching is implemented in a secure join module which is prevented from accessing the credentials associated with the 1P data source. However Ortiz discloses pre-processing the PII data to generate first formatted PII data, the first formatted PII data conforming to a defined format (he data encryption technology can include, for example, SQL databases and SQL servers, among others, that are configured to protect sensitive data at rest on the server, during movement between client and server and while the data is in use to ensure that sensitive data never appears as plaintext inside the database system, par. 159, data custodian architecture and a corresponding data agent architecture (including a data loader) are described for interoperation with a trusted execution environment, such as the secure enclave, having a segregated or isolated data processing subsystem controlling access to protected database elements (e.g., in the context of a relational database, protected tabular database tables, or in a non-relational database, protected non-tabular data, such as documents or dynamically defined schemas). The access to protected database elements can be provisioned to the secure enclave for query/machine learning processing at various levels, such as at a database level, a table level, a row/column level, or an individual field level, protected database elements can also be extended within the protected database elements beyond the initially loaded data, and can include machine learning intermediate outputs, joined versions of various tables, future looking data extrapolated from existing data, derivative data, among others, and these additional elements may inherit restrictions or permissions from their parent data, par. 157-158); providing, to a data service operating independently of the 1P data source, the joined dataset (a data custodian architecture and a corresponding data agent architecture (including a data loader) are described for interoperation with a trusted execution environment, such as the secure enclave, having a segregated or isolated data processing subsystem controlling access to protected database elements (e.g., in the context of a relational database, protected tabular database tables, or in a non-relational database, protected non-tabular data, such as documents or dynamically defined schemas). The access to protected database elements can be provisioned to the secure enclave for query/machine learning processing at various levels, such as at a database level, a table level, a row/column level, or an individual field level, par. 157, protected database elements can also be extended within the protected database elements beyond the initially loaded data, and can include machine learning intermediate outputs, joined versions of various tables, future looking data extrapolated from existing data, derivative data, among others, and these additional elements may inherit restrictions or permissions from their parent data, par. 158), wherein: the module implements a secure connector configured to use credentials associated with the 1P data source (a data custodian architecture and a corresponding data agent architecture (including a data loader) are described for interoperation with a trusted execution environment, such as the secure enclave, having a segregated or isolated data processing subsystem controlling access to protected database elements (e.g., in the context of a relational database, protected tabular database tables, or in a non-relational database, protected non-tabular data, such as documents or dynamically defined schemas). The access to protected database elements can be provisioned to the secure enclave for query/machine learning processing at various levels, such as at a database level, a table level, a row/column level, or an individual field level, par. 157, protected database elements can also be extended within the protected database elements beyond the initially loaded data, and can include machine learning intermediate outputs, joined versions of various tables, future looking data extrapolated from existing data, derivative data, among others, and these additional elements may inherit restrictions or permissions from their parent data, par. 158, differing levels of protection can be established through the use of multiple or separate keys that can be established for each (e.g., a database level key, a table level key, a row/column level key, keys for individual fields), which can then be exposed accordingly so that the secure enclave only receives a minimum level of access required for processing the query or machine learning activities, par. 160); and the matching is implemented in a secure join module which is prevented from accessing the credentials associated with the 1P data source (a data custodian architecture and a corresponding data agent architecture (including a data loader) are described for interoperation with a trusted execution environment, such as the secure enclave, having a segregated or isolated data processing subsystem controlling access to protected database elements, par. 157, differing levels of protection can be established through the use of multiple or separate keys that can be established for each (e.g., a database level key, a table level key, a row/column level key, keys for individual fields), which can then be exposed accordingly so that the secure enclave only receives a minimum level of access required for processing the query or machine learning activities, par. 158-160). Therefore one ordinary skill in the art would have found it obvious before the effective filling date of the claimed invention to use Ortiz in Arasu for including the above limitations because one ordinary skill in the art would recognize it would further improve a secure computing infrastructure that utilizes secure computing and cryptographic approaches to store sensitive information that can only be access with one or more automatically enforced data custodian policies for conducting analytics while preserving privacy and confidentiality, par. 13-14.
As per claim 15, Arasu discloses a system comprising: one or more servers including processing hardware (see fig.1) and configured to; receive, at a module executing in a trusted execution environment (TEE) from a first party (1P) data source, a first dataset including personal identifiable information (PII) data and non-PII data (…(table 4 and table 5: see Ailment (encrypted) and Ailment (original))…EDBMS TM framework that can be stored on a trusted machine such as computing device…an EDBMS TM framework can contain a query processor configured for receiving a query having encrypted contents and one or more encrypted records from a data store…the query processor can coordinate the execution of the query on a trusted machine and can return a query result…the query received by the query processor is a complete query, while in others, it can be an intermediate query…an intermediate query can be one of several query operations needed to process a complete query according to a query plan…when the query processor coordinates the execution of an intermediate query, the query result that is returned can be an intermediate query result…see par. 33, 35); match, in the TEE, the first formatted PII data to second formatted PII data included in a second dataset; perform a join operation between the first dataset and the second dataset based on the matching, to generate a joined dataset (…after the encrypted records and the encrypted query contents have been decrypted, the query processor can process the query by utilizing semantically secure query operators…a semantically secure query operator can be used to execute an associated query operation on decrypted data derived from the encrypted records…semantically secure query operators remove information that can be used to identify correlations between a query parameter and a query result… a semantically secure join operator joins two input tables into one resulting table…see par. 38, 45). Arasu does not explicitly disclose pre-processing the PII data to generate first formatted PII data, the first formatted PII data conforming to a defined format; provide, to a data service operating independently of the 1P data source, the joined dataset wherein: the module implements a secure connector configured to use credentials associated with the 1P data source; and the matching is implemented in a secure join module which is prevented from accessing the credentials associated with the 1P data source. However Ortiz discloses pre-processing the PII data to generate first formatted PII data, the first formatted PII data conforming to a defined format (he data encryption technology can include, for example, SQL databases and SQL servers, among others, that are configured to protect sensitive data at rest on the server, during movement between client and server and while the data is in use to ensure that sensitive data never appears as plaintext inside the database system, par. 159, data custodian architecture and a corresponding data agent architecture (including a data loader) are described for interoperation with a trusted execution environment, such as the secure enclave, having a segregated or isolated data processing subsystem controlling access to protected database elements (e.g., in the context of a relational database, protected tabular database tables, or in a non-relational database, protected non-tabular data, such as documents or dynamically defined schemas). The access to protected database elements can be provisioned to the secure enclave for query/machine learning processing at various levels, such as at a database level, a table level, a row/column level, or an individual field level, protected database elements can also be extended within the protected database elements beyond the initially loaded data, and can include machine learning intermediate outputs, joined versions of various tables, future looking data extrapolated from existing data, derivative data, among others, and these additional elements may inherit restrictions or permissions from their parent data, par. 157-158); provide, to a data service operating independently of the 1P data source, the joined dataset (a data custodian architecture and a corresponding data agent architecture (including a data loader) are described for interoperation with a trusted execution environment, such as the secure enclave, having a segregated or isolated data processing subsystem controlling access to protected database elements (e.g., in the context of a relational database, protected tabular database tables, or in a non-relational database, protected non-tabular data, such as documents or dynamically defined schemas). The access to protected database elements can be provisioned to the secure enclave for query/machine learning processing at various levels, such as at a database level, a table level, a row/column level, or an individual field level, par. 157, protected database elements can also be extended within the protected database elements beyond the initially loaded data, and can include machine learning intermediate outputs, joined versions of various tables, future looking data extrapolated from existing data, derivative data, among others, and these additional elements may inherit restrictions or permissions from their parent data, par. 158), wherein: the module implements a secure connector configured to use credentials associated with the 1P data source (a data custodian architecture and a corresponding data agent architecture (including a data loader) are described for interoperation with a trusted execution environment, such as the secure enclave, having a segregated or isolated data processing subsystem controlling access to protected database elements (e.g., in the context of a relational database, protected tabular database tables, or in a non-relational database, protected non-tabular data, such as documents or dynamically defined schemas). The access to protected database elements can be provisioned to the secure enclave for query/machine learning processing at various levels, such as at a database level, a table level, a row/column level, or an individual field level, par. 157, protected database elements can also be extended within the protected database elements beyond the initially loaded data, and can include machine learning intermediate outputs, joined versions of various tables, future looking data extrapolated from existing data, derivative data, among others, and these additional elements may inherit restrictions or permissions from their parent data, par. 158, differing levels of protection can be established through the use of multiple or separate keys that can be established for each (e.g., a database level key, a table level key, a row/column level key, keys for individual fields), which can then be exposed accordingly so that the secure enclave only receives a minimum level of access required for processing the query or machine learning activities, par. 160); and the matching is implemented in a secure join module which is prevented from accessing the credentials associated with the 1P data source (a data custodian architecture and a corresponding data agent architecture (including a data loader) are described for interoperation with a trusted execution environment, such as the secure enclave, having a segregated or isolated data processing subsystem controlling access to protected database elements, par. 157, differing levels of protection can be established through the use of multiple or separate keys that can be established for each (e.g., a database level key, a table level key, a row/column level key, keys for individual fields), which can then be exposed accordingly so that the secure enclave only receives a minimum level of access required for processing the query or machine learning activities, par. 158-160). Therefore one ordinary skill in the art would have found it obvious before the effective filling date of the claimed invention to use Ortiz in Arasu for including the above limitations because one ordinary skill in the art would recognize it would further improve a secure computing infrastructure that utilizes secure computing and cryptographic approaches to store sensitive information that can only be access with one or more automatically enforced data custodian policies for conducting analytics while preserving privacy and confidentiality, par. 13-14.
As per claim 2, the combination of Arasu and Ortiz disclose performing, by the module and prior to the receiving of the first dataset, authentication with the 1P data source (Ortiz: par. 196). The motivation for claim 2 is the same motivation as in claim 1 above.
As per claim 3, the combination of Arasu and Ortiz disclose wherein the performing of the authentication includes performing a decryption operation using credentials associated with the 1P data source (Ortiz: par. 223-226). The motivation for claim 3 is the same motivation as in claim 1 above.
As per claim 14, the combination of Arasu and Ortiz disclose wherein the receiving of the first dataset includes receiving the first dataset in cleartext over an encrypted link (Arasu: see par. 34).
As per claim 16, the combination of Arasu and Ortiz disclose wherein the one or more servers are further configured to: perform, by the module and prior to the receiving of the first dataset, authentication with the 1P data source (Ortiz: par. 196). The motivation for claim 16 is the same motivation as in claim 1 above.
As per claim 17, the combination of Arasu and Ortiz disclose wherein the one or more servers are configured to perform the authentication by performing a decryption operation using credentials associated with the 1P data source (Ortiz: par. 223-226). The motivation for claim 17 is the same motivation as in claim 1 above.
As per claims 21, 22, the combination of Arasu and Ortiz disclose wherein the predefined format includes one or more predefined string formats (Ortiz: par. 177-180). The motivation for claims 21, 22 is the same motivation as in claims 1, 15 above.
Claims 19-20 are rejected under 35 U.S.C. 103 as being unpatentable over Arasu et al (Pub. No. US 20160306995) in view of Ortiz et al (Pub. No. US 2022/0108026) as applied to claim 15 above, and further in view of Sultan et al (Pub. No. US 2022/0343021).
As per claim 19, the combination of Arasu and Ortiz does not explicitly disclose wherein the one or more servers are further configured to: provide the first formatted PII data from the secure connector to the secure join module via an extract-transform-load (ETL) pipeline. However Sultan discloses wherein the one or more servers are further configured to: provide the first formatted PII data from the secure connector to the secure join module via an extract-transform-load (ETL) pipeline (…match different PII data among trading partners using the main tokenizer, and corresponding tokens may be sent back to the trading partners…linking of records may be performed by certain additional special programming and analysis software. For example, record linking fits into a general class of data processing known as data integration, which can be defined as the problem of combining information from multiple heterogeneous data sources. Data integration can include data preparation steps such as parsing, profiling, cleansing, normalization, and parsing and standardization of the raw input data prior to record linkage to improve the quality of the input data and to make the data more consistent and comparable (these data preparation steps are sometimes referred to as ETL or extract, transform, load) …see par. 145, 151). Therefore one ordinary skill in the art would have found it obvious before the effective filling date of the claimed invention to use Sultan in the combination of Arasu and Ortiz for including the above limitations because one ordinary skill in the art would recognize it would further detect and prevent fraud from plurality of PII fields…see Sultan, par. 20-21.
As per claim 20, the combination of Arasu, Ortiz and Sultan discloses wherein the ETL pipeline is configured to provide the first formatted PII data to (i) the data service and (ii) a repository for time-deferred consumption of the first formatted PII data (Sultan: par. 150-151). The motivation for claim 20 is the same motivation as in claim 19 above.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure (see PTO-form 892).
The following Patents and Papers are cited to further show the state of the art at the time of Applicant’s invention with respect to a secure computing environment…for improving data security and computational efficiency when performing such operations as joining datasets.
Gkoulalas-Vivanis (Pub. No. US 2019/0266352); “Coordinated De-Identification of a Dataset Across a Network”;
-Teaches data masking and data pseudonymization technology protects direct identifiers in a dataset such as, for example, full names of individuals, social security numbers, medical IDs, phone numbers, credit card numbers, email addresses, etc., which are personal information that is most vulnerable in a person-specific dataset with respect to re-identification of individuals via triangulation attacks with external, publicly available datasets, such as voter registration lists, yellow pages, etc. Protection of direct identifiers in a dataset significantly reduces an overall privacy risk, thereby making the dataset less vulnerable during data transfer, par. 20.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to GHAZAL B SHEHNI whose telephone number is (571)270-7479. The examiner can normally be reached Mon-Fri 9am-5pm PCT.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Philip Chea can be reached at 5712723951. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/GHAZAL B SHEHNI/Primary Examiner, Art Unit 2499