Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
Claims 1 – 20 are pending.
Any references to applicant’s specification are made by way of applicant’s U.S. pre-grant printed patent publication.
This action is in response to the communication filed on 5/8/26.
Claim Interpretation
The claim term “computer readable storage media” is interpreted as the plural form of “computer readable storage medium”. The applicant’s explicitly disavows signals per se from the scope of the term “computer readable storage medium” (e.g. Specification, par. 44). Thus, the examiner does not interpret the claimed “storage media”, simply the plurality of the term “storage medium”, as comprising signals per se.
Election/Restrictions
Claim 20 is withdrawn from further consideration pursuant to 37 CFR 1.142(b), as being drawn to a nonelected invention, there being no allowable generic or linking claim. Applicant timely traversed the restriction (election) requirement in the reply filed on 5/8//26.
Applicant's election with traverse of claims 1 - 19 in the reply filed on 5/8/26 is acknowledged. The traversal is on the grounds that:
“…The use of identity environments is already implicit in claim 1's rule-generation and enforcement steps and is made explicit in the Specification and dependent claims. …
Accordingly, claim 20 does not omit any functional step recited in claim 1 and does not introduce a different overall result, effect, or mode of operation. …
… Practicing claim 20 would necessarily practice the core steps of claim 1, and the claims are therefore not mutually exclusive. The Office Action's assertion that the inventions are "mutually exclusive in scope" is incorrect, as there is no technical or legal incompatibility between the claims.
…” (Remarks, pg. 8, 9)
This is not found persuasive because:
Applicant appears mistaken. Specifically, neither claim 1 nor any independent claim requires (or implies) the features of claim 20, including any of receiving business requirements from users, business requirements in the form of natural language, the parsing of the natural language so as to generate an access policy covering the business requirements, generating rules corresponding to one or more identity environments, and enforcing rules via an identity environment.
Furthermore, claim 20 does not require (nor imply) the features of claim 1, including determining a high-level requirement for accessing a data environment, mapping the high-level requirement to a defined access policy, generating rules to implement the policy, and enforcing the rules upon access requests to the data environment.
As such, the claims are clearly mutually exclusive in scope.
The requirement is still deemed proper and is therefore made FINAL.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claims 1, 2, 5 – 7, 14, 15, and 16 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Parthasarathy et al. (Parthasarathy), US 2019/0373021 A1.
Regarding claim 1, Parthasarathy discloses:
A method for enforcing access rules to data environments (e.g. Parthasarathy, Abstract; par. 33, 40, 71) , the method comprising:
determining a high-level requirement for access to the data environments (e.g. Parthasarathy, Abstract; fig. 4:304; par. 6, 22, 32, 33 – herein the system receives administrative definitions forming a tier of policy associations to be used for enforcing network access by computing entities);
defining an access policy that maps to the high-level requirement (e.g. Parthasarathy, fig. 1B; par. 23, 24, 33, 52 – individual policies are gathered or aggregated to create a reconciled policy, i.e. “defining an access policy”);
generating one or more rules to implement the access policy (e.g. Parthasarathy, Abstract; par. 33, 34, 52 – rules are determined for implementing the reconciled policy);
and enforcing the one or more rules on access requests to the data environments to satisfy the high-level requirement (e.g. Parthasarathy, fig. 2:258; fig. 6B:612,614,616,618; par. 82, 86, 93 – herein a controller enforces requests to storage using the created reconciled policy).
Regarding claim 2, Parthasarathy discloses:
determining the one or more rules do not conflict with one or more existing rules (e.g. Parthasarathy, Abstract; par. 36, 51);
and enforcing the one or more rules occurs in response to determining the one or more rules do not conflict with one or more existing rules (e.g. Parthasarathy, par. 51, 61, 68 – herein, rule conflicts are resolved and the policy is enforced).
Regarding claim 5, Parthasarathy discloses:
wherein each of the one or more rules is defined by a query, one or more conditions, and one or more actions (e.g. Parthasarathy, par. 60, 62, 67 –policy definitions, i.e. “one or more rules”) .
Regarding claim 6, Parthasarathy discloses:
wherein the query indicates a source entity with a relationship to a destination entity (e.g. Parthasarathy, par. 60, 62, 67 –policy definitions indicate a computing entity, i.e. “source entity” and permissible actions relative to a network, port, or storage, i.e. “destination entity”), the method comprising:
identifying a subset of the one or more rules having queries with relationships that overlap with existing queries from existing rules; and identifying conflicting rules in the subset that, when satisfied, result in conflicting actions being taken (e.g. Parthasarathy, par. 35, 51, 61, 68 – duplicate, i.e. overlapping, and conflicting rules are resolved and the policy is enforced).
Regarding claim 7, Parthasarathy discloses:
wherein existing rules are prioritized over the conflicting rules (e.g. Parthasarathy, par. 35, 51, 61, 68 – prior dominating rules are prioritized over conflicting rules).
.
Regarding claim 14, Parthasarathy discloses:
receiving exceptions to the one or more rules (e.g. Parthasarathy, par. 34 – a listener continuously monitors for event changes to the existing policy – i.e. one or more rule exceptions);
and in response to determining at least one exception of the exceptions can be implemented by modifying existing rules being enforced on the access requests, modifying one or more of the existing rules to implement the at least one exception (e.g. Parthasarathy, par. 34, 42, 43, 48, 50).
Regarding claim 15, Parthasarathy discloses:
comparing the one or more rules to existing rules being enforced on the access requests (e.g. Parthasarathy, par. 36, 50, 51 – herein when new policy rules are created, such as by an aggregator in response to event changes from a listener, the aggregator repeats the process of conflict resolution of new rules to existing rules);
and in response to determining the existing rules can be modified to enforce the one or more rules rather than adding the one or more rules to the existing rules, modifying the existing rules (e.g. Parthasarathy, par. 34, 35, 36, existing policies can be changed, i.e. “modified”, rather than replaced by new policies).
Regarding claim 16, it is an apparatus claim essentially corresponding to the method claims above, and it is rejected, at least, for the same reasons. Furthermore, because Parthasarathy discloses storage media, a processing system, and program instructions (e.g. Parthasarathy, claim 19).
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 3, 4, 12, 13, 17, and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Parthasarathy et al. (Parthasarathy), US 2019/0373021 A1 in view of Rungta et al. (Rungta), US 2022/0191253 A1.
Regarding claim 3, Parthasarathy discloses:
determining a second high-level requirement for access to the data environments; defining a second access policy that maps to the second high-level requirement; generating one or more second rules to implement the second access policy (e.g. Parthasarathy, Abstract; claim 1; par. 50). Herein, Parthasarathy discloses a repeatable method for generating any number (“first”, “second”, “third”, …etc.) of reconciled policies. These limitations are rejected, at least, for the same reasons as noted within claims 1 and 2.
Furthermore, Parthasarathy does not appear to disclose, but Rungta does disclose notifying users when policy rules cannot be enforced (e.g. Rungta, par. 23).
It would have been obvious to one of ordinary skill in the art to notify a user when policy rules cannot be enforced as taught by Rungta within the system of Parthasarathy for enabling an administrator to create and update policies. This would have been obvious because one of ordinary skill in the art would have been motivated by the teachings that such notifications can alert a user when his intentions cannot be followed thus providing valuable feedback (e.g. Rungta, par. 23).
Thus, the combination enables:
and in response to determining the one or more second rules conflict with at least one of the one or more existing rules, notifying a user that the second high-level requirement cannot be enforced (e.g. Rungta, par. 23).
Regarding claim 4, it is rejected, at least, for the same reasons as claim 3, and furthermore because the combination enables:
determining a second high-level requirement for access to the data environments; defining a second access policy that maps to the second high-level requirement; generating one or more second rules to implement the second access policy (e.g. Parthasarathy, Abstract; claim 1; par. 50); and in response to identifying an inconsistency in the one or more second rules, notifying a user that the second high-level requirement cannot be enforced (e.g. Rungta, par. 22, 23).
Regarding claim 12, it is rejected, at least, for the same reasons as claims 3 and/or4, and furthermore because the combination enables:
receiving exceptions to the one or more rules (e.g. Rungta, par. 22, 23); determining at least one exception of the exceptions overlaps with other exceptions (e.g. Parthasarathy, par. 35, 51, 61, 68); and notifying a user that the at least one exception cannot be enforced (e.g. Rungta, par. 22, 23).
Regarding claim 13, the combination enables:
wherein notifying the user comprises: providing to the user a recommendation for creating a disjoint exception to replace the at least one exception (e.g. Parthasarathy, par. 35, 51, 61, 68; e.g. Rungta, par. 22, 23 – a user can be notified so as to allow the user to allow only a separated subset, i.e. “a disjoint”, of all conflicts, i.e. exceptions).
Regarding claims 17 and 19, they are apparatus claims essentially corresponding to the method claims above, and it is rejected, at least, for the same reasons.
Claims 8 – 11 and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Parthasarathy et al. (Parthasarathy), US 2019/0373021 A1 in view of Miriyala et al. (Miriyala), US 2021/0306338 A1.
Regarding claim 8, Parthasarathy does not appear to disclose, but Miriyala does disclose proposing policy rules to a user and receiving confirmation from the user before enforcing policy rules (e.g. Miriyala, par. 66).
It would have been obvious to one of ordinary skill in the art to allow an administrator to confirm policy creation/changes as taught by Miriyala within the system of Parthasarathy for enabling an administrator to create and update policies. This would have been obvious because one of ordinary skill in the art would have been motivated by the teachings that sometimes an administrator would like to review policies before they are implemented by the system, thus flexibly giving an administrator a level of control over the system they administrate (e.g. Miriyala, par. 49).
Thus, the combination enables:
prior to enforcing the one or more rules, proposing the one or more rules to a user, wherein the user provides confirmation that the one or more rules appear to satisfy the high-level requirement (e.g. Parthasarathy, par. 50; Miriyala, par. 49, 66).
Regarding claim 9, the combination enables:
comprising: after receiving the confirmation, applying the one or more rules to the access requests and informing the user of a subset of the access requests that would satisfy the one or more rules had the one or more rules been enforced (e.g. Parthasarathy, par. 50; Miriyala, par. 49, 64 - 66).
Regarding claim 10, Parthasarathy discloses:
after informing the user, receiving direction from the user to enforce the one or more rules on the subset (e.g. Miriyala, par. 49, 64 - 66).
Regarding claim 11, Parthasarathy discloses:
after receiving the direction, receiving an instruction from the user to automatically enforce the one or more rules on subsequent requests of the access requests (e.g. Parthasarathy, par. 50; Miriyala, par. 49, 64 - 66).
Regarding claim 18, it is an apparatus claim essentially corresponding to the method claims above, and it is rejected, at least, for the same reasons.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure:
See Notice of References Cited.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to JEFFERY L WILLIAMS whose telephone number is (571)272-7965. The examiner can normally be reached on 7:30 am - 4:00 pm.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Farid Homayounmehr can be reached on 571-272-3739. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/JEFFERY L WILLIAMS/Primary Examiner, Art Unit 2495