DETAILED ACTION
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
The amendment filed 9/4/2026 has been placed of record in the file.
Claims 1, 2, 5-9, and 11-14 have been amended.
Claims 15-22 have been added.
Claims 1, 2, and 5-22 are now pending.
The double patenting rejection remains of record.
The applicant’s arguments with respect to claims 1, 2, and 5-22 have been considered but are moot in view of the following new grounds of rejection.
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 9/4/2026 has been entered.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 2, and 5-22 are rejected under 35 U.S.C. 103 as being unpatentable over Barday et al. (U.S. Patent Application Publication Number 2018/0341784), hereinafter referred to as Barday, in view of Kurtin et al. (U.S. Patent Application Publication Number 2019/0026488), hereinafter referred to as Kurtin.
Barday disclosed techniques for the identification and deletion of personal data in computer systems. In an analogous art, Kurtin disclosed techniques for the identification of sensitive data in documents. Both systems are directed toward identifying and protecting personal data.
Regarding claim 1, Barday discloses a tangible non-transitory computer readable storage media, including program instructions loaded into memory that, when executed on processors, cause the processors to implement a method of responding to right to be forgotten requests (paragraph 163, right to be forgotten), the method including: a cloud access security broker (abbreviated CASB) controlling exfiltration of consumer data stored on cloud-based services by a service provider (paragraph 165, Subject Access Request Module, and paragraph 186, cloud-based servers); in response to receiving a right to be forgotten request from a particular consumer, the CASB identifying one or more locations on one or more of the cloud-based services at which consumer data for the particular consumer is stored, the one or more locations comprising document locations on the one or more cloud-based services (paragraph 165, request to delete personal data, and paragraph 166, identify database, server, etc., and paragraph 205, document of particular storage location); the CASB performing deep inspection of the consumer data stored at the identified locations, the performing the deep inspection including applying one or more content inspection rules to the consumer data stored at the identified locations to identify sensitive data related to the particular consumer, and detecting at least some sensitive data related to the particular consumer in the consumer data (paragraph 166, intelligent identity scanning, and paragraphs 137-141, scan storage locations to identify personal data); and the CASB fulfilling the right to be forgotten request by removing the detected sensitive data from the cloud-based services (paragraph 169, facilitate deletion of personal data).
Barday does not explicitly state performing the deep inspection at the identified document locations to identify the sensitive data. However, performing rule-based analysis on particular user documents in such a fashion was well known in the art as evidenced by Kurtin. Since the inventions encompass the same field of endeavor, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the system of Barday by adding the ability for performing the deep inspection at the identified document locations to identify the sensitive data as provided by Kurtin (see paragraphs 33-34, searches documents for personal identity information). One of ordinary skill in the art would have recognized the benefit that identifying and protecting a user’s sensitive data in this way would assist in preventing the misuse of documents containing personal information (see Kurtin, paragraph 6).
Regarding claim 2, the combination of Barday and Kurtin discloses program instructions that, when executed on processors, cause the processors to implement the method further including: in addition to removing the detected sensitive data from the cloud-based services, the CASB providing the detected sensitive data to the particular consumer (Barday, paragraph 169, display personal data).
Regarding claim 5, the combination of Barday and Kurtin discloses program instructions that, when executed on processors, cause the processors to implement the method, wherein the sensitive data in the consumer data is personal data referenced by an identifier including name, identification number, location data, and online identifier (Barday, paragraph 183, unique subject identifier used to fulfill data subject access request, and paragraph 218, unique subject identifier is unique user ID, e-mail address, etc.).
Regarding claim 6, the combination of Barday and Kurtin discloses program instructions that, when executed on processors, cause the processors to implement the method further including: erasing any information directly or indirectly identified as related to an identifiable person corresponding to the right to be forgotten request appearing in records containing the detected sensitive data from the cloud-based services (Barday, paragraph 2, personal data includes PII).
Regarding claim 7, Barday discloses a method of responding to right to be forgotten requests (paragraph 163, right to be forgotten), the method including: a cloud access security broker (abbreviated CASB) controlling exfiltration of consumer data stored on cloud-based services by a service provider (paragraph 165, Subject Access Request Module, and paragraph 186, cloud-based servers); in response to receiving a right to be forgotten request from a particular consumer, the CASB identifying one or more locations on one or more of the cloud-based services at which consumer data for the particular consumer is stored, the one or more locations comprising document locations on the one or more cloud-based services (paragraph 165, request to delete personal data, and paragraph 166, identify database, server, etc., and paragraph 205, document of particular storage location); the CASB performing deep inspection of the consumer data stored at the identified locations, the performing the deep inspection including applying one or more content inspection rules to the consumer data stored at the identified locations to identify sensitive data related to the particular consumer, and detecting at least some sensitive data related to the particular consumer in the consumer data (paragraph 166, intelligent identity scanning, and paragraphs 137-141, scan storage locations to identify personal data); and the CASB fulfilling the right to be forgotten request by removing the detected sensitive data from the cloud-based services (paragraph 169, facilitate deletion of personal data).
Barday does not explicitly state performing the deep inspection at the identified document locations to identify the sensitive data. However, performing rule-based analysis on particular user documents in such a fashion was well known in the art as evidenced by Kurtin. Since the inventions encompass the same field of endeavor, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the system of Barday by adding the ability for performing the deep inspection at the identified document locations to identify the sensitive data as provided by Kurtin (see paragraphs 33-34, searches documents for personal identity information). One of ordinary skill in the art would have recognized the benefit that identifying and protecting a user’s sensitive data in this way would assist in preventing the misuse of documents containing personal information (see Kurtin, paragraph 6).
Regarding claim 8, the combination of Barday and Kurtin discloses the CASB providing the detected sensitive data to the particular consumer (Barday, paragraph 169, display personal data).
Regarding claim 9, the combination of Barday and Kurtin discloses wherein the sensitive data in the consumer data is personal data referenced by an identifier including name, identification number, location data, and online identifier (Barday, paragraph 183, unique subject identifier used to fulfill data subject access request, and paragraph 218, unique subject identifier is unique user ID, e-mail address, etc.).
Regarding claim 10, the combination of Barday and Kurtin discloses erasing any information directly or indirectly identified as related to an identifiable person corresponding to the right to be forgotten request appearing in records containing the detected sensitive data from the cloud-based services (Barday, paragraph 2, personal data includes PII).
Regarding claim 11, Barday discloses a system for responding to requests to be forgotten (paragraph 163, right to be forgotten), the system including a processor, memory coupled to the processor, and computer instructions loaded into memory that, when executed on processors, cause the processors to implement a method including: a cloud access security broker (abbreviated CASB) controlling exfiltration of consumer data stored on cloud-based services by a service provider (paragraph 165, Subject Access Request Module, and paragraph 186, cloud-based servers); in response to receiving a right to be forgotten request from a particular consumer, the CASB identifying one or more locations on one or more of the cloud-based services at which consumer data for the particular consumer is stored, the one or more locations comprising document locations on the one or more cloud-based services (paragraph 165, request to delete personal data, and paragraph 166, identify database, server, etc., and paragraph 205, document of particular storage location); the CASB performing deep inspection of the consumer data stored at the identified locations, the performing the deep inspection including applying one or more content inspection rules to the consumer data stored at the identified location to identify sensitive data related to the particular consumer, and detecting at least some sensitive data related to the particular consumer in the consumer data (paragraph 166, intelligent identity scanning, and paragraphs 137-141, scan storage locations to identify personal data); and the CASB fulfilling the right to be forgotten request by removing the detected sensitive data from the cloud-based services (paragraph 169, facilitate deletion of personal data).
Barday does not explicitly state performing the deep inspection at the identified document locations to identify the sensitive data. However, performing rule-based analysis on particular user documents in such a fashion was well known in the art as evidenced by Kurtin. Since the inventions encompass the same field of endeavor, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the system of Barday by adding the ability for performing the deep inspection at the identified document locations to identify the sensitive data as provided by Kurtin (see paragraphs 33-34, searches documents for personal identity information). One of ordinary skill in the art would have recognized the benefit that identifying and protecting a user’s sensitive data in this way would assist in preventing the misuse of documents containing personal information (see Kurtin, paragraph 6).
Regarding claim 12, the combination of Barday and Kurtin discloses wherein the computer instructions further cause the processors to implement the method, the method further including: in addition to removing the detected sensitive data from the cloud-based services, the CASB providing the detected sensitive data to the particular consumer (Barday, paragraph 169, display personal data).
Regarding claim 13, the combination of Barday and Kurtin discloses wherein the sensitive data in the consumer data is personal data referenced by an identifier including name, identification number, location data, and online identifier (Barday, paragraph 183, unique subject identifier used to fulfill data subject access request, and paragraph 218, unique subject identifier is unique user ID, e-mail address, etc.).
Regarding claim 14, the combination of Barday and Kurtin discloses wherein the computer instructions further cause the processors to implement the method, the method further including: erasing any information directly or indirectly identified as related to an identifiable person corresponding to the right to be forgotten request appearing in records containing the detected sensitive data from the cloud-based services (Barday, paragraph 2, personal data includes PII).
Regarding claim 15, the combination of Barday and Kurtin discloses program instructions that, when executed on processors, cause the processors to implement the method further including, removing records referenced by the identifier of the particular consumer from the identified document locations response to identification of the sensitive data using the one or more content inspection rules (Barday, paragraph 169, facilitate deletion of personal data).
Regarding claim 16, the combination of Barday and Kurtin discloses removing records referenced by the identifier of the particular consumer (Barday, paragraph 169, facilitate deletion of personal data).
Regarding claim 17, the combination of Barday and Kurtin discloses wherein the computer instructions further cause the processors to implement the method, the method further including: removing records referenced by the identifier of the particular consumer (Barday, paragraph 169, facilitate deletion of personal data).
Regarding claim 18, the combination of Barday and Kurtin discloses wherein the identified document locations comprise at least one folder of a cloud-hosted email service or at least one folder of a cloud storage service (Kurtin, paragraph 33, cloud storage folders).
Regarding claim 19, the combination of Barday and Kurtin discloses wherein the applying of the one or more content inspection rules is performed by a data loss prevention (DLP) engine of the CASB (Barday, paragraph 137, intelligent identity scanning module).
Regarding claim 20, the combination of Barday and Kurtin discloses wherein the identified document locations comprise at least one folder of a cloud-hosted email service or at least one folder of a cloud storage service (Kurtin, paragraph 33, cloud storage folders).
Regarding claim 21, the combination of Barday and Kurtin discloses wherein the applying of the one or more content inspection rules is performed by a data loss prevention (DLP) engine of the CASB (Barday, paragraph 137, intelligent identity scanning module).
Regarding claim 22, the combination of Barday and Kurtin discloses wherein to perform the deep inspection, the computer instructions cause the CASB to apply the one or more content inspection rules using a data loss prevention (DLP) engine of the CASB (Barday, paragraph 137, intelligent identity scanning module).
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Victor Lesniewski whose telephone number is (571)272-2812. The examiner can normally be reached Monday thru Friday, 9am to 5pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Carl Colin can be reached at 571-272-3862. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/Victor Lesniewski/Primary Examiner, Art Unit 2493