DETAILED ACTION
This office action has been issued in response to communications received on 4/15/2026. Claims 1, 6, 11 and 16 were amended. No claims were cancelled and no new claims were added. Claims 1-20 are presented for examination. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 4/15/2026 has been entered.
Response to Arguments
Applicant’s remarks regarding the rejection of the claims under 103 have been considered, but are found unpersuasive.
Applicant’s arguments filed 4/15/2026, with respect to the rejection of claims 1-20 under 35 USC § 103(a) have been fully considered but are moot because newly added claim limitations requiring “executing a secure data processing application to perform real-time encryption of user data” require new grounds of rejection necessitated by amendments.
The remaining arguments fail to comply with 37 C.F.R. § 1.111(b) because they amount to a general allegation that the claims define a patentable invention without specifically pointing out how the language of the claims patentably distinguishes them from the references.
Accordingly, the rejection of the claims under 35 USC 103 is sustained.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention.
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Claims 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Weingarten (US 2023/0148446) in view of Pottier (US 2022/0229918).
Regarding claim 1, Weingarten discloses the limitations of claim 1 substantially as follows:
A method comprising:
configuring a plurality of Wi-Fi networks to support data collection and to work in a connected manner (paras. [0064]-[0065], [0078], [0083], [0118], [0142]: configuring a safe environment with elastic network of different networks and subnetworks, systems and end devices by collecting behavioral characteristics and controlling access to network connections, where communications over the networks may be wired or wireless);
executing a cloud-based server for centralized control over the plurality of Wi-Fi networks (paras. [0033], [0065], [0067], [0102], [0111]: central server of a cloud-based system for centralized control over subnetworks, endpoints and other elements within the safe environment in order to collect behavioral characteristics);
executing a secure data processing application to perform real-time (paras. [0067]-[0068], [0091], [0146], [0153]-[0154], [0174]: executing agents (i.e. secure data processing application) to collect, parse and analyze behavioral characteristics of endpoints in real-time to modify files (i.e. modifying user data) to generate classifications and identifications of malicious behavior);
enabling secure storage and management of the encrypted (paras. [0077], [0102], [0128], [0131], [0174], [0179]: storing and managing on agents encrypted data collected from endpoint devices and generated by agents thru endpoint device systems); and
configuring the access management application to allow a transfer of the encrypted user data to one or more authorized data requester upon one or more preconditions being met (paras. [0068], [0074], [0077], [0086], [0088], [0101], [0174]: agents and endpoint device systems enable network access requests, including data collected by agents and encrypted via certificates, to be transmitted to authenticated requesters upon rules and network management polices being met (i.e. preconditions to granting or requests)).
Weingarten does not explicitly disclose the remaining limitations of claim 1 as follows:
executing a secure data processing application to perform real-time encryption of user data;
allow a transfer of the encrypted user data to one or more authorized data requester, each authorized data requester being a third party, upon one or more user-configured preconditions being met.
However, in the same field of endeavor, Pottier discloses the remaining limitations of claim 1 as follows:
executing a secure data processing application to perform real-time encryption of user data (paras. [0014], [0016], [0023], [0029]: data controller/consent management system performs encryption based on real-time determination of consent to access user data);
allow a transfer of the encrypted user data to one or more authorized data requester, each authorized data requester being a third party, upon one or more user-configured preconditions being met (paras. [0014], [0016], [0019]-[0020], [0023]: allowing transfer of encrypted user data to one or more authorized third parties upon the requested operations by the third parties being included in the user-defined permitted operations for the user data or the third-party is specifically identified in the consent as being permitted to access the user data (i.e. upon user-configured preconditions being met)).
Pottier and Weingarten are combinable because both are from the same field of endeavor of protecting user data collected from user devices from access by unauthorized parties. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to integrate Pottier’s method of encrypting based on real consent data including metadata describing who is authorized, and what the user data can be used for with the system of Weingarten in order “to implement user security preferences in a granular manner and reduce the likelihood of unauthorised access and use by unauthorised entities.” (Pottier, para. [0029]).
Regarding claims 2 and 12, Weingarten and Pottier teach the limitations of the method of claim 1 and the system of claim 11.
Weingarten teaches the limitations of claims 2 and 12 as follows:
utilizing one or more of access points, mesh nodes, repeaters, and devices within the plurality of Wi-Fi networks as data transmission terminals (paras. [0093], [0114]: using access points, repeaters and endpoints (i.e. devices within the plurality of networks) with agents to transmit collected data about the endpoints (i.e. as data transmission terminals)).
Regarding claims 3 and 13, Weingarten and Pottier teach the limitations of the method of claim 1 and the system of claim 11.
Weingarten teaches the limitations of claims 3 and 13 as follows:
generating an access management interface on a client device, the access management interface configured to enable a user to set the one or more preconditions for the one or more data requesters (paras. [0074], [0077], [0180], Fig. 13: user interface on endpoint configured to enable a user to manually set access restrictions for the endpoints requesting access).
Regarding claims 4 and 14, Weingarten and Pottier teach the limitations of the method of claim 1 and the system of claim 11.
Weingarten teaches the limitations of claims 4 and 14 as follows:
implementing a consent management module configured to enable users to manage consent settings for data usage transfer (paras. [0106]-[0108], [0180]: enabling users to manually adjust control settings for data access/transfer).
Regarding claims 5 and 15, Weingarten and Pottier teach the limitations of the method of claim 1 and the system of claim 11.
Weingarten teaches the limitations of claims 5 and 15 as follows:
executing a user profile creation module configured to create profiles for data requesters, wherein each profile includes access rights (paras. [0072], [0092], [0132], [0183]: determining historical browsing histories and patterns and baseline usage (i.e. profiles) for users and endpoint devices and set access rights for the users and endpoint devices)).
Regarding claims 6 and 16, Weingarten and Pottier teach the limitations of the method of claim 1 and the system of claim 11.
Weingarten and Pottier teach the limitations of claims 6 and 16 as follows:
configuring a data delivery module to securely transmit the encrypted user data to authorized data requesters (Weingarten, paras. [0101], [0162], [0174]: securely transmitting data collected by the agents and encrypted by certificates for transmission to the management system and requesters of searches of the collected information), wherein the transmission includes user-defined encryption protocols and authentication mechanisms that are dynamically adjustable based on the data requester’s security profile (Pottier, paras. [0014], [0016], [0019]-[0020]: transmission of user data is based upon encryption that is requester-specific (i.e. based on data requester’s security profile) and the encryption is based upon third parties identified specifically by the user (i.e. user-defined encryption protocols and authentication mechanisms)).
The same motivation to combine utilized in claims 1 and 11 is equally applicable in the instant claims.
Regarding claim 7, Weingarten and Pottier teach the limitations of the method of claim 1.
Weingarten teaches the limitations of claim 7 as follows:
configuring a transaction module to maintain records of data access transactions, including one or more of a data requester identification, a time and/or date of request, and data requested (paras. [0153], [0169], [0178]-[0179], [0183], Fig. 9: maintaining records identifying the particular endpoint performing an action (i.e. data requester) and data and time actions are performed)).
Regarding claim 17, Weingarten and Pottier teach the limitations of the system of claim 11.
Weingarten teaches the limitations of claim 17 as follows:
configuring a transaction module to maintain records of data access transactions, including one or more of a data requester identification, a time and/or date of request, and specific data requested (paras. [0153], [0169], [0178]-[0179], Fig. 9: maintaining records identifying the particular endpoint performing an action (i.e. data requester) and data and time actions are performed)).
Regarding claim 8, Weingarten and Pottier teach the limitations of the method of claim 1.
Weingarten and Pottier teaches the limitations of claim 8 as follows:
executing a key management module configured to manage encryption keys for data requesters, including their generation, distribution (Weingarten, paras. [0101]: managing certificates for encrypting and decrypting user content), and revocation (Pottier, paras. [0023], [0026]: managing encryption keys for requesters of user data by generating new encryption keys and distributing when a new encryption key is required (i.e. when the old encryption key is revoked).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to integrate Pottier’s method of generating and sending new encryption keys when an old encryption key is out-of-day with the system of Weingarten in order managing encryption keys with the system of Weingarten in order to ensure that encryption keys accurately reflect whether a requester is authorized at the time they receive the user data.
Regarding claim 18, Weingarten and Pottier teach the limitations of the system of claim 11.
Weingarten and Pottier teach the limitations of claim 18 as follows:
executing a key management module configured to manage modification keys for data requesters, including their generation, distribution, and revocation (Weingarten, paras. [0101]: managing certificates for encrypting and decrypting user content), and revocation (Pottier, paras. [0023], [0026]: managing encryption keys for requesters of user data by generating new encryption keys and distributing when a new encryption key is required (i.e. when the old encryption key is revoked).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to integrate Pottier’s method of generating and sending new encryption keys when an old encryption key is out-of-day with the system of Weingarten in order managing encryption keys with the system of Weingarten in order to ensure that encryption keys accurately reflect whether a requester is authorized at the time they receive the user data.
Regarding claims 9 and 19, Weingarten and Pottier teach the limitations of the method of claim 1 and the system of claim 11.
Weingarten teaches the limitations of claims 9 and 19 as follows:
enabling, via an access management interface, a user to select one or more requesters to add to a consent list (paras. paras. [0107]-[0108], [0179]-[0180], Fig. 13: user interface that enables manual designation of endpoints/requesters that have or have not violated access restrictions and manual modification of access restrictions).
Regarding claims 10 and 20, Weingarten and Pottier teach the limitations of the method of claim 1 and the system of claim 11.
Pottier teaches the limitations of claims 10 and 20 as follows:
configuring the secure data processing application to enable users to select a degree of anonymization for their data via an access management interface (Pottier, paras. [0023], [0029], [0031]-[0032], [0036]: enabling users to apply a granular method of security for their user data by defining different user security preferences for different pieces of user data using a user interface to specify who specifically can access user data and how).
The same motivation to combine utilized in claims 1 and 11 is equally applicable in the instant claims.
Regarding claim 11, Weingarten teaches the limitations substantially as follows:
A system comprising:
one or more computers comprising one or more processors and one or more non-transitory computer readable media, the one or more non-transitory computer readable media including program instructions stored thereon that when executed cause the one or more computers to:
configure a plurality of Wi-Fi networks to support data collection and to work in a connected manner (paras. [0064]-[0065], [0078], [0083], [0118], [0142]: configuring a safe environment with elastic network of different networks and subnetworks, systems and end devices by collecting behavioral characteristics and controlling access to network connections, where communications over the networks may be wired or wireless);
configure a cloud-based server for centralized control over the plurality of Wi-Fi networks (paras. [0033], [0065], [0067], [0102], [0111]: central server of a cloud-based system for centralized control over subnetworks, endpoints and other elements within the safe environment in order to collect behavioral characteristics);
execute a secure data processing application to perform real-time (paras. [0067]-[0068], [0091], [0146], [0153]-[0154], [0174]: executing agents (i.e. secure data processing application) to collect, parse and analyze behavioral characteristics of endpoints in real-time to modify files (i.e. modifying user data) to generate classifications and identifications of malicious behavior); and
execute an access management application enabling secure storage and management of the encrypted (paras. [0077], [0102], [0128], [0131], [0174], [0179]: storing and managing on agents encrypted data collected from endpoint devices and generated by agents thru endpoint device systems);
wherein the access management application is configured to allow a transfer of encrypted user data to one or more authorized data requester upon one or more preconditions being met (paras. [0068], [0074], [0077], [0086], [0088], [0101], [0174]: agents and endpoint device systems enable network access requests, including data collected by agents and encrypted via certificates, to be transmitted to authenticated requesters upon rules and network management polices being met (i.e. preconditions to granting or requests)).
Weingarten does not explicitly disclose the remaining limitations of claim 18 as follows:
executing a secure data processing application to perform real-time encryption of user data;
allow a transfer of the encrypted user data to one or more authorized data requester, each authorized data requester being a third party, upon one or more user-configured preconditions being met.
However, in the same field of endeavor, Pottier discloses the remaining limitations of claim 18 as follows:
executing a secure data processing application to perform real-time encryption of user data (paras. [0014], [0016], [0023], [0029]: data controller/consent management system performs encryption based on real-time determination of consent to access user data);
allow a transfer of the encrypted user data to one or more authorized data requester, each authorized data requester being a third party, upon one or more user-configured preconditions being met (paras. [0014], [0016], [0019]-[0020], [0023]: allowing transfer of encrypted user data to one or more authorized third parties upon the requested operations by the third parties being included in the user-defined permitted operations for the user data or the third-party is specifically identified in the consent as being permitted to access the user data (i.e. upon user-configured preconditions being met)).
Pottier and Weingarten are combinable because both are from the same field of endeavor of protecting user data collected from user devices from access by unauthorized parties. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to integrate Pottier’s method of encrypting based on real consent data including metadata describing who is authorized, and what the user data can be used for with the system of Weingarten in order “to implement user security preferences in a granular manner and reduce the likelihood of unauthorised access and use by unauthorised entities.” (Pottier, para. [0029]).
Prior art not relied upon but applied/considered includes:
1) Nicolas (US 2014/0215638) teaches a method for enabling a third party to search for user data that might be of value to them in an anonymous manner and then enables the user to grant permission to release their user data to the third party upon receiving financial compensation (paras. [0072]-[0082]).
Conclusion
For the above reasons, claims 1-20 are rejected.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SHARON S LYNCH whose telephone number is (571)272-4583. The examiner can normally be reached on 10AM-6PM.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Taghi T Arani can be reached on 571-272-3787. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/SHARON S LYNCH/Primary Examiner, Art Unit 2438