Notice of Pre-AIA or AIA Status
1. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Continued Examination
2. A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 04/28/2026 has been entered.
DETAILED ACTION
3. This Office Action is in response to the filing with the office dated 04/28/2026.
Claims 21, 22, 27, 29, 30, 31 and 37-39 have been amended. Claims 1-20, 23-25 and 32-35 have been cancelled. Claims 21 and 30 are independent claims. Claims 21, 22, 26-31 and 36-39 are presented in this office action.
Response to amendment/arguments
4. Applicant’s amendment with respect to the claims 29 and 39 under 35 U.S.C. § 112 (b) have been fully considered. As a result the rejection has been withdrawn.
5. Applicant’s arguments with respect to the rejection of claims under 35 U.S.C. § 101 as the claimed invention is directed to a judicial exception (i.e., a law of nature, a natural phenomenon, or an abstract idea) without significantly more, have been fully considered. However, Examiner respectfully disagrees with the applicant’s argument. See response to arguments section. The rejection has been maintained.
6. Applicant’s arguments with respect to the rejection of claims under 35 U.S.C. § 102 (a)(i) and 103(a) have been fully considered but are moot in view of the new grounds of rejection. Please see the rejection below.
Response to 101 rejection
7. Applicants arguments regarding 101 rejection on page 11 states “The recited limitations cannot be practically performed in the human mind. In particular, the claim recites the use of a database system including computing device clusters, computing devices, and computing nodes that process queries on stored datasets, apply a redaction protocol, and generate and utilize a defined redaction character string that is unique to the database system during data retrieval. A human mind cannot receive and process database queries over stored datasets, dynamically mark data using system-defined character strings, and enforce access- level-based conditional retrieval within a database system. As such, the claimed invention does not recite a mental process and thus, is not directed to an abstract idea. The Applicant respectfully requests that the rejection over claims 21-39 be withdrawn”.
Examiner respectfully disagrees as the claim limitations “identify a sensitive portion of the data…”, determine whether the query includes sensitive information….”, “determine protection level for the sensitive portion of the data….”, “marking ….”, under its broadest reasonable interpretation, covers performance of the limitation in the mind. There is, nothing in the claim element precludes the steps from practically being performed by a human mentally or with pen and paper. These limitations, at the high level of generality as drafted, would encompass a user to receive a query, identify sensitive portion in the query in accordance with a redaction protocol, determine if the query includes sensitive information, determine protection level of the sensitive data in accordance with the user access privileges, mark the sensitive portion which is mentally performable as an evaluation or judgement. If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components, then it falls within the “Mental Processes” grouping of abstract ideas. Accordingly, the claim recites an abstract idea.
This judicial exception is not integrated into a practical application. In particular, the claim recites “system”, “device”, are recited at a high level of generality as generic computer components and additional elements such as “obtain a query…”, “retrieve a copy of data”, “providing the redacted data”, “logging the operation” are an insignificant extra-solution activity of a data gathering process. These additional elements amount to nothing more than mere instructions to apply the recited abstract idea on a computer, under MPEP 2106.05(f). The additional elements of “obtain a query…”, “retrieve a copy of data”, “providing the redacted data”, “logging the operation” amount to mere data outputting which are insignificant extra-solution activity. Combination of these additional elements is no more than mere instructions to apply the exception using series of steps and outputting the result of the mental process. Accordingly, even in combination, the additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea.
The claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the recitation of generic computing components is still mere instructions to apply the exception under MPEP 2106.05(f) and does not provide significantly more. The “obtain a query…”, “retrieve a copy of data”, “providing the redacted data”, “logging the operation” elements that was identified as insignificant extra-solution activity as mere data gathering when re-evaluated still does not provide significantly more, Considering the additional elements in combination and the claim as a whole does not change the analysis, and does not amount to significantly more. Thus the claims are abstract.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
8. Claims 21, 22, 26-31 and 36-39 are rejected under 35 U.S.C. 101 because the claimed invention is directed to a judicial exception (i.e., a law of nature, a natural phenomenon, or an abstract idea) without significantly more. Determining whether claims are statutory under 35 U.S.C. 101 involves a two-step analysis. Step 1 requires a determination of whether the claims are directed to the statutory categories of invention. Step 2 requires a determination of whether the claims are directed to a judicial exception without significantly more. Step 2 is divided into two prongs, with the first prong having a part 1 and part 2. See MPEP 2106; See 2019 Revised Patent Subject Matter Eligibility Guidance (2019 PEG).
Pursuant to Step 1, claim 21 recites a database system which are directed to the statutory category of a machine. Claim 30 recites a computer readable memory device, which are directed to a manufacture.
Pursuant to Step 2A, part 1, claims are analyzed to determine whether they are directed to an abstract idea. Under the 2019 PEG, claims are deemed to be directed to an abstract idea if they fall within one of the enumerated categories of (a) mathematical concepts, (b) certain methods of organizing human activity, and (c) mental processes. Here, claims 21 and 30 are directed to an abstract idea categorized under mental processes. Courts consider a mental process if it “can be performed in the human mind, or by a human using a pen and paper.” MPEP 2016(a)(2)(III). Courts also consider a mental process as one that can be performed in the human mind and is merely using a computer as a tool to perform the concept. MPEP 2016(a)(2)(III)(C)(3). Claim 21 recites actions of receiving query for execution, manipulating and storing the data, but is recited at a high level of generality that merely used computers as a tool to perform the processes. See MPEP 2106(a)(2)(III). For example, claim 21 recites limitations of “identify…”, “determine…”, “”mark…”, “retrieve data…” are recited at a high level of generality and do not place meaningful limits on the abstract idea which is a task that can be performed by a human with the use of the computer as a tool. These limitations are essentially steps of generating and manipulating data at a high level of generality, which can be performed by a person using a computer as a tool.
Pursuant to Step 2A, part 2, claims are analyzed to determine whether the recited abstract idea is integrated into a practical application. In this case, as explained above, claims 21 and 31 merely recite a mental process. The limitations “identify…”, “determine…”, “mark…”, are mental process. While claims 21 an 30 recite additional components in the form of “database system”, computing devices”, “computing nodes”,, “memory”, “obtain a query…”, “retrieve a copy of data”, “providing the redacted data”, “logging the operation”, these components are recited at a high level of generality, which do not add meaningful limits on the recited abstract idea to integrate it into a practical application by providing an improvement to the functioning of a computer or technology, implementing the abstract idea with a particular machine or manufacture that is integral to the claim, effecting a transformation or reduction of a particular article to a different state or thing, nor applying the abstract idea in some meaningful way beyond linking its use to computer technology. See 2019 PEG. The additional elements “obtain a query…”, “retrieve a copy of data”, “providing the redacted data”, “logging the operation” amount to mere data gathering steps which are insignificant extra-solution activity. Combination of these additional elements is no more than mere instructions to apply the exception using series of steps and outputting the result of the mental process. Accordingly, even in combination, the additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea.
Pursuant to Step 2B, claims are analyzed to determine whether they recite significantly more than the abstract idea. In other words, it is determined whether the claims provide an inventive concept. In this case, claims 1, 19 and 20 do not recite limitations that amount to significantly more than the abstract idea. The limitations are steps involving processes that can be practically performed by a human with the aid of pen and paper, or as explained above, using a computer as a tool to perform the concept. For example, a The “retrieving data” element that was identified as insignificant extra-solution activity as mere data gathering when re-evaluated still does not provide significantly more. Considering the additional elements in combination and the claim as a whole does not change the analysis, and does not amount to significantly more. Thus the claims are abstract.
The dependent claims 22, 26-29, 31 and 36-39 which impose additional limitations explained above also fail to claim patent-eligible subject matter because the limitations cannot be considered statutory. In reference to claim 21, these dependent claims have also been reviewed with the same analysis as independent claim 21. The dependent claim(s) have been examined individually and in combination with the preceding claims, however they do not cure the deficiencies of claim 21
Claim Rejections - 35 U.S.C. § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
9. Claims 21-39 are rejected under 35 U.S.C. 103 as being unpatentable over Bogatov; Dmytro (US 12367314 B1) in view of Jiang; Boxin (US 20230153455 A1) and in further view of Lim; Keng (US 20240064017 A1).
Regarding independent claim 21, Bogatov; Dmytro (US 12367314 B1) teaches, a database system comprises: a plurality of computing device clusters (Col 7, Lines 53-55 (39) the database service 102 includes one or more clusters. Also see Col 5, Lines, 18-20 (31)), wherein a computing device cluster of the plurality of computing device clusters includes a plurality of computing devices (Fig. 1 (Col 7, Lines 55-59 (39) A cluster 120 can be made up of one or more compute nodes 126) , wherein a computing device of the plurality of computing devices includes pluralities of computing nodes; wherein a set of computing nodes of the pluralities of computing nodes is operable to (Col 8, Lines 44-51 (44) The leader node 124 and/or compute node(s) 126 of a cluster 120 can thus be executed by a single host computing device or by multiple host computing devices at a single location (e.g., rack, row, room, data center, building, AZ) or multiple such locations);
identify a first sensitive portion of data in accordance with a redaction protocol (Fig. 10, Col 19, Lines 6-10, Col 20, Lines 53-61 (100), (111) identifying various columns of a table such with different columns and redating the data according to the redaction protocol. (Examiner interprets different column as different portion of data));
determine a first protection level for the sensitive portion of the data in accordance with the redaction protocol and access privileges of the user (Fig. 8 Col 18, Lines 19-67 (94)-(99) discloses, retrieving the data based on the access level assigned to the role);
executing the query operation by: ( (Fig. 10, Col 19, Lines 6-10, Col 20, Lines 53-61 (100), (111) identifying various columns of a table such with different columns and redating the data according to the redaction protocol and provide the redacted copy to the user based on user access policy. (Examiner interprets different column as different portion of data));
Bogatov et al fails to explicitly teach, wherein a set of computing nodes of the pluralities of computing nodes is operable to: obtain a query operation regarding data, wherein execution of the query operation is requested by a user of the database system; prior to execution of the query operation: retrieve a copy of the data; determine whether the query operation includes sensitive information regarding the sensitive portion of the data; marking, the sensitive information of the query operation with the first system- defined redaction character string or a second system-defined redaction character string to produce a redacted query operation; and logging the redacted query operation in a database system log.
Jiang; Boxin (US 20230153455 A1) teaches,: obtain a query operation regarding data, wherein execution of the query operation is requested by a user of the database system (Paragraph [0025] discloses, receiving an user request/ query. Also see [0027]);
prior to execution of the query operation: retrieve a copy of the data (Paragraph [0032] discloses, prior to executing the query, retrieve the unredacted data);
determine whether the query operation includes sensitive information regarding the sensitive portion of the data (Paragraph [0033] discloses, determining/ identifying if a query includes sensitive information. Also see [0038]);
marking, the sensitive information of the query operation with the first system- defined redaction character string or a second system-defined redaction character string to produce a redacted query operation (TABLE-US-00001, Fig. 4, Paragraphs [0059]-[0063] discloses, marking the sensitive information of the query such as email, organization, credit card number….. with the system- defined redaction character string by replacing the sensitive character string with masked text <text>).
Therefore it would have been obvious to one of the ordinary skill in the art before the effective filing date of the claimed invention, to have modified the teachings of Bogatov et al by providing wherein a set of computing nodes of the pluralities of computing nodes is operable to: obtain a query operation regarding data, wherein execution of the query operation is requested by a user of the database system; determine whether the query operation includes sensitive information regarding the sensitive portion of the data; marking, the sensitive information of the query operation with the first system- defined redaction character string or a second system-defined redaction character string to produce a redacted query operation, as taught by Jiang et al (Paragraphs [0025], [0033], [0059]-[0063]).
One of the ordinary skill in the art would have been motivated to make this modification, by doing so, the embodiments described herein may reduce and/or minimize the data exchange utilized to perform redaction on sensitive data as taught by Jiang et al (Paragraph [0016]).
Bogatov et al and Jiang et al fails to explicitly teach, and logging the redacted query operation in a database system log.
Lim; Keng (US 20240064017 A1) teaches, and logging the redacted query operation in a database system log (Paragraph [0149] discloses, logging the query operation to the log server).
Therefore it would have been obvious to one of the ordinary skill in the art before the effective filing date of the claimed invention, to have modified the teachings of Bogatov et al and Jiang et al by logging the redacted query operation in a database system log, as taught by Lim et al (Paragraph [0149].
One of the ordinary skill in the art would have been motivated to make this modification, by doing so would, it protects the company's secrets and track all accesses, the company deployed a data access enforcer and a plurality of data access policies to control access to the data in the database and log requests as taught by Lim et al (Paragraph [0229].
Regarding dependent claim 22, Bogatov et al, Jiang et al and Lim et al teach, the database system of claim 21.
Bogatov et al further teaches, wherein the set of computing nodes is further operable to: identify a second sensitive portion of the data in accordance with the redaction protocol; determine the first protection level for the second sensitive portion in accordance with the redaction protocol (Fig. 10, Col 19, Lines 6-10, Col 20, Lines 53-61 (100), (111) identifying various columns of a table such with different columns and redating the data according to the redaction protocol (Examiner interprets different columns as different portions of the data));
mark in accordance with the first protection level, the second sensitive portion of the copy of the data with the first system-defined redaction character string to produce a second redacted copy of the data; provide the redacted copy of the data to the user; mark second sensitive information of the query operation with the first system-defined redaction character string or a second system-defined redaction character string to produce a redacted query operation (Fig. 10, Col 19, Lines 6-10, Col 20, Lines 53-61 (100), (111) identifying various columns of a table such with different columns and redating the data according to the redaction protocol (Examiner interprets different columns as different portions of the data));
Jiang et al also teaches, mark in accordance with the first protection level, the second sensitive portion of the copy of the data with the first system-defined redaction character string to produce a second redacted copy of the data; provide the redacted copy of the data to the user; mark second sensitive information of the query operation with the first system-defined redaction character string or a second system-defined redaction character string to produce a redacted query operation (TABLE-US-00001, Fig. 4, Paragraphs [0059]-[0063] discloses, marking the sensitive information of the query such as email, organization, credit card number….. with the system- defined redaction character string by replacing the sensitive character string with masked text <text>) (Examiner interprets logging redacted query operations in a database system log as replacing the sensitive parameters with placeholder before executing the command).
Lim et al further teaches, and log the redacted Query operation in a database system log (Fig. 9, Col 19, Lines. 6-67 Paragraph (100)-(104) discloses, accessing the redaction logfile based on the user role).
Regarding dependent claim 26, Bogatov et al, Jiang et al and Lim et al teach, the database system of claim 21.
Bogatov et al further teaches, wherein the database system is configured to store, for each protection level of the redaction protocol, a corresponding redacted version of the data in a respective log file, and wherein access to each log file is determined based on an access level associated with a request to retrieve data from the log file (Fig. 9, Col 19, Lines. 6-67 Paragraph (100)-(104) discloses, accessing the redaction logfile based on the user role).
Regarding dependent claim 27, Bogatov et al, Jiang et al and Lim et al teach, the database system of claim 21.
Bogatov et al further teaches, wherein the first and second system-defined redaction characters are maintained internally by the database system and are not user-modifiable (Col 13, Lines, 62-67, Col 7, Lines, 1-11 (68) discloses, system defined redaction characters based on the role of the user).
Regarding dependent claim 28, Bogatov et al, Jiang et al and Lim et al teach, the database system of claim 21.
Bogatov et al further teaches, wherein the set of computing nodes is further operable to sanitize the data to remove user-supplied instances of the system-defined redaction characters (Col 17, Lines, 30-44 (90) discloses, sanitizing the data by rewriting the query based on the user role and provide the redacted data associated with the user role (Examiner interprets remove user-supplied instances of the system-defined redaction characters as not including the data which does not belong to the user role and policy).
Regarding dependent claim 29, Bogatov et al, Jiang et al and Lim et al teach, the database system of claim 21.
Bogatov et al further teaches, wherein the data includes at least one of is stored data; incoming data; data being processed; data of a query; and data of a dataset (Col 10, Lines, 19-24 (53) storing the masking policy with the associated data).
Regarding independent claim 21, Bogatov; Dmytro (US 12367314 B1) teaches, a computer readable memory device that comprises: a first memory section that stores operational instructions that, when executed by a set of computing nodes of pluralities of computing nodes of pluralities of computing devices of a plurality of computing device clusters of a database system (Col 8, Lines 44-51 (44) The leader node 124 and/or compute node(s) 126 of a cluster 120 can thus be executed by a single host computing device or by multiple host computing devices at a single location (e.g., rack, row, room, data center, building, AZ) or multiple such locations), causes the set of computing nodes to: identify a sensitive portion of the data in accordance with a redaction protocol (Fig. 10, Col 19, Lines 6-10, Col 20, Lines 53-61 (100), (111) identifying various columns of a table such with different columns and redating the data according to the redaction protocol. (Examiner interprets different column as different portion of data));
determine a first protection level for the sensitive portion of the data in accordance with the redaction protocol and access privileges of the user (Fig. 8 Col 18, Lines 19-67 (94)-(99) discloses, retrieving the data based on the access level assigned to the role);
a second memory section that stores operational instructions that, when executed by the set of computing nodes causes the set of computing nodes to: execute the query operation by: ( (Fig. 10, Col 19, Lines 6-10, Col 20, Lines 53-61 (100), (111) identifying various columns of a table such with different columns and redating the data according to the redaction protocol and provide the redacted copy to the user based on user access policy. (Examiner interprets different column as different portion of data));
Bogatov et al fails to explicitly teach, obtain a query operation regarding data, wherein execution of the query operation is requested by a user of the database system; prior to execution of the query operation: retrieve a copy of the data; determine whether the query operation includes sensitive information regarding the sensitive portion of the data; marking, the sensitive information of the Query operation with the first system- defined redaction character string or a second system-defined redaction character string to produce a redacted query operation; and logging the redacted query operation in a database system log.
Jiang; Boxin (US 20230153455 A1) teaches, obtain a query operation regarding data, wherein execution of the query operation is requested by a user of the database system (Paragraph [0025] discloses, receiving an user request/ query. Also see [0027]);
prior to execution of the query operation: retrieve a copy of the data (Paragraph [0032] discloses, prior to executing the query, retrieve the unredacted data);
determine whether the query operation includes sensitive information regarding the sensitive portion of the data (Paragraph [0033] discloses, determining/ identifying if a query includes sensitive information. Also see [0038]);
marking, the sensitive information of the Query operation with the first system- defined redaction character string or a second system-defined redaction character string to produce a redacted query operation (TABLE-US-00001, Fig. 4, Paragraphs [0059]-[0063] discloses, marking the sensitive information of the query such as email, organization, credit card number….. with the system- defined redaction character string by replacing the sensitive character string with masked text <text>).
Therefore it would have been obvious to one of the ordinary skill in the art before the effective filing date of the claimed invention, to have modified the teachings of Bogatov et al by providing wherein a set of computing nodes of the pluralities of computing nodes is operable to: obtain a query operation regarding data, wherein execution of the query operation is requested by a user of the database system; determine whether the query operation includes sensitive information regarding the sensitive portion of the data; marking, the sensitive information of the query operation with the first system- defined redaction character string or a second system-defined redaction character string to produce a redacted query operation, as taught by Jiang et al (Paragraphs [0025], [0033], [0059]-[0063]).
One of the ordinary skill in the art would have been motivated to make this modification, by doing so, the embodiments described herein may reduce and/or minimize the data exchange utilized to perform redaction on sensitive data as taught by Jiang et al (Paragraph [0016]).
Bogatov et al and Jiang et al fails to explicitly teach, and logging the redacted query operation in a database system log.
Lim; Keng (US 20240064017 A1) teaches, and logging the redacted query operation in a database system log (Paragraph [0149] discloses, logging the query operation to the log server).
Therefore it would have been obvious to one of the ordinary skill in the art before the effective filing date of the claimed invention, to have modified the teachings of Bogatov et al and Jiang et al by logging the redacted query operation in a database system log, as taught by Lim et al (Paragraph [0149].
One of the ordinary skill in the art would have been motivated to make this modification, by doing so would, it protects the company's secrets and track all accesses, the company deployed a data access enforcer and a plurality of data access policies to control access to the data in the database and log requests as taught by Lim et al (Paragraph [0229].
Regarding dependent claim 31, Bogatov et al, Jiang et al and Lim et al teach, the computer readable memory device of claim 30.
wherein the instructions further cause the set of computing nodes to: identify a second sensitive portion of the data in accordance with the redaction protocol; determine the first protection level for the second sensitive portion in accordance with the redaction protocol (Fig. 10, Col 19, Lines 6-10, Col 20, Lines 53-61 (100), (111) identifying various columns of a table such with different columns and redating the data according to the redaction protocol (Examiner interprets different columns as different portions of the data));
mark in accordance with the first protection level, the second sensitive portion of the copy of the data with the first system-defined redaction character string to produce a second redacted copy of the datwith the first system-defined redaction character string or a second system-defined redaction character string to produce a redacted query operation (Fig. 10, Col 19, Lines, 64-67, Col 20, Lines 1-15 (105) discloses, marking the protection level based on the policy/ role);
Jiang et al also teaches, mark in accordance with the first protection level, the second sensitive portion of the copy of the data with the first system-defined redaction character string to produce a second redacted copy of the dat(TABLE-US-00001, Fig. 4, Paragraphs [0059]-[0063] discloses, marking the sensitive information of the query such as email, organization, credit card number….. with the system- defined redaction character string by replacing the sensitive character string with masked text <text>) (Examiner interprets logging redacted query operations in a database system log as replacing the sensitive parameters with placeholder before executing the command).
Lim et al further teaches, and log the redacted Query operation in a database system log (Fig. 9, Col 19, Lines. 6-67 Paragraph (100)-(104) discloses, accessing the redaction logfile based on the user role).
Regarding dependent claim 36, Bogatov et al, Jiang et al and Lim et al teach, the computer readable memory device of claim 30.
Bogatov et al further teaches, wherein the database system is configured to store, for each protection level of the redaction protocol, a corresponding redacted version of the data in a respective log file, and wherein access to each log file is determined based on an access level associated with a request to retrieve data from the log file (Fig. 9, Col 19, Lines. 6-67 (100)-(104) discloses, accessing the redaction logfile based on the user role).
Regarding dependent claim 37, Bogatov et al, Jiang et al and Lim et al teach, the computer readable memory device of claim 30.
Bogatov et al further teaches, wherein the first and second system-defined redaction characters are maintained internally by the database system and are not user-modifiable (Col 13, Lines, 62-67 (68) discloses, system defined redaction characters based on the role of the user which is maintained by the database system).
Regarding dependent claim 38, Bogatov et al, Jiang et al and Lim et al teach, the computer readable memory device of claim 30.
Bogatov et al further teaches, wherein the second memory section further stores operational instructions that, when executed by the set of computing nodes, causes the computing nodes to: remove user-supplied instances of the system- defined redaction characters (Col 17, Lines, 30-44 (90) discloses, sanitizing the data by rewriting the query based on the user role and provide the redacted data associated with the user role (Examiner interprets remove user-supplied instances of the system-defined redaction characters as not including the data which does not belong to the user role and policy).
Regarding dependent claim 39, Bogatov et al, Jiang et al and Lim et al teach, the computer readable memory device of claim 30.
Bogatov et al further teaches, wherein the data includes at least one of stored data; incoming data; data being processed; data of a query; and data of a dataset (Col 10, Lines, 19-24 (53) storing the masking policy with the associated data).
Closest Prior Art
10. The prior art made of record and not relied upon is considered pertinent to the applicant’s disclosure.
Ho; Min-Hank (US 20130144901 A1) teaches, [0037] In one embodiment, whenever a redaction policy is initially established in database 102, the redaction policy is analyzed to determine all of the columns to which the redaction policy potentially applies. In such an embodiment, each column to which a redaction policy applies has a bit or flag associated with that column responsively set to "true" to indicate that some redaction policy applies to that column. Consequently, the insertion of the masking operators into the internal representation of the query during semantic analysis is quickened, since the internal database semantic analysis code can quickly determine, by reference to the value of each column's associated bit or flag, whether the internal database semantic analysis code needs to search for redaction policies that could cause the internal database semantic analysis code to insert one or more masking operators for that particular column; columns whose associated bit or flag has not been set are known not to need any masking operators.
11. Examiner has pointed out particular references contained in the prior arts of record in the body of this action for the convenience of the applicant. Although the specified citations are representative of the teachings in the art and are applied to the specific limitations within the individual claim, other passages and Figures may apply as well. It is respectfully requested from the applicant, in preparing the response, to consider fully the entire references as potentially teaching all or part of the claimed invention, as well as the context of the passage as taught by the prior arts or disclosed by the examiner. It is noted that any citation to specific pages, columns, figures, or lines in the prior art references any interpretation of the references should not be considered to be limiting in any way. A reference is relevant for all it contains and may be relied upon for all that it would have reasonably suggested to one having ordinary skill in the art. In re Heck, 699 F.2d 1331-33, 216 USPQ 1038-39 (Fed. Cir. 1983) (quoting In re Lemelson, 397 F.2d 1006, 1009, 158 USPQ 275, 277 (CCPA 1968))).
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SUMAN RAJAPUTRA whose telephone number is (571) 272-4669. The examiner can normally be reached between 8:00 AM - 5:00 PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Tony Mahmoudi (571) 272-4078 can be reached. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/ patents/ apply/ patent-center for more information about Patent Center and https://www.uspto.gov/ patents/ docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/S. R./
Examiner, Art Unit 2163
/ALEX GOFMAN/Primary Examiner, Art Unit 2163