DETAILED ACTION
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This action is responsive to communications: Preliminary amendment filed on 9/20/2024.
Claims 2-21 are pending. Claims 2, 9, and 16 are independent. Claim 1 was canceled.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/process/file/efs/guidance/eTD-info-I.jsp.
Claims 2-4, 6-8, 9-11, 13-15, 16-18, and 20-21 are rejected on the grounds of nonstatutory double patenting as being unpatentable over claims 1, 2, 4, 5, 9, 10-15, 19-22, 24, 25, and 30 of US Patent 12,061,685. Although the claims at issue are not identical, they are not patentably distinct from each other because both the current application and patent ‘865 are directed to a computer-implemented method of assessing risk factors of a data share request, scoring the risk factors, determining that the score exceeds a threshold, and escalating the share request.
Current Application
US12,061,865
2. A computer-implemented method comprising:
1. A computer-implemented method comprising:
Receiving, at a data share management system including one or more processors, one or more answers from a unified electronic form, wherein the unified electronic form presents questions assessing a plurality of risk factors and analysis silos associated with a set of data requested in a data share request, wherein the analysis silos are associated with organizational roles associated with the plurality of risk factors for the set of data, and wherein the one or more answers are associated with a requestor device requesting to share the set of data with a third party;
assessing a plurality of risk factors associated with a data share request, wherein the data share request represents a request from a requestor device to share a set of data with a third party, wherein the data share request is associated with a workflow, wherein the data is associated with risk factors and analysis silos, wherein the plurality of risk factors correspond to a plurality of risk types, and wherein the analysis silos are associated with organizational roles corresponding to the plurality of risk factors;
Dynamically assessing the plurality of risk factors associated with the data share request using a workflow with dynamic form logic using additional questions present to the requestor by way of the unified electronic form in response to the one or more answers, wherein the plurality of risk factors correspond to a plurality of risk types associated with the set of data, wherein risk factors are associated with validation endpoints, and wherein the validation endpoints are associated with analysis silos;
determining a score associated with one or more answers from a unified electronic form, wherein determining the score is based on the plurality of risk factors and the workflow, wherein the score is associated with a risk type, wherein the risk type corresponds to a validation endpoint of the workflow, and wherein the one or more answers are associated with the requestor device and are provided in response to one or more questions;
Determining a first score for a first silo associated with the one or more answers from the unified electronic form based on the plurality of risk factors, wherein the first score is associated with a first risk type;
Determining a second score for a second silo associated with the one or more answers from the unified electronic form based on the plurality of risk factors and the workflow, wherein the second score is associated with a second risk type;
determining, in association with the workflow, that the score exceeds a threshold determined in association with the workflow; and
Determining that the first score and the second score exceed a corresponding threshold, wherein the first risk type and the second risk type correspond to two or more different validation endpoints of the workflow; and
escalating the data share request based on a routing associated with the workflow.
Escalating the data share request based on a routing associated with the workflow and the determining that the first score and the second score exceed the corresponding threshold.
3. The computer-implemented method of claim 2, wherein the assessing the plurality of risk factors is based on the one or more answers
2. the method of claim 1, wherein assessing the plurality of risk factors comprises:
presenting a series of questions regarding the plurality of risk factors, wherein the questions are presented within the unified electronic form, and wherein assessing the plurality of risk factors is based on one or more answers to the series of questions.
The computer implemented method of claim 3, further comprising:
Determining that the validation endpoint has raised a challenge the one or more answers; and
Sending the data share request back to the requestor device.
4. The method of claim 2, further comprising: determining that the one or more validation endpoints has raised a challenge to one or more of the one or more answers; and
Sending the data share request back to the requestor device.
6. The computer implemented method of claim 2, wherein assessing the plurality of risk factors associated with the data share request comprises:
Determining that the data share request requires one or more modifications;
Allowing the requestor device to modify the data share request;
Receiving a modified data share request; and
Assessing the modified data share request.
5. The method of claim 1, wherein assessing the plurality of risk factors associated with the data share request comprises:
Determining that the data share request requires one or more modifications;
Allowing the requestor device to modify the data share request;
Receiving a modified data share request; and
Assessing the modified data share request.
7. The computer-implemented method of claim 2, where in the data share request is among a plurality of recurring data share requests, the method further comprising:
Re-evaluating the data share requests periodically.
9. The method of claim 1, wherein the data share request is among a plurality of recurring data share requests, and further comprising:
Re-evaluating the data share request periodically.
8. the method of claim 2, wherein the plurality of risk factors associated with the data share request includes at least one of: a category of the set of data, a method for how the set of data is to be shared, a form of encryption, a form of protection, a type of relationship with the third party, a contractual relationship with the third party, data quality, data usage, type of data access, and data requirements.
10. the method of claim 1, wherein the plurality of risk factors associated with the data share request includes at least one of: a category of the set of data, a method for how the set of data is to be shared, a form of encryption, a form of protection, a type of relationship with the third party, data quality, data usage, type of data access, and data requirements.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 2-21 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 2A Prong 1
Claims 2 recites:
assessing a plurality of risk factors associated with a data share request, wherein the data share request represents a request from a requestor device to share a set of data with a third party, wherein the data share request is associated with a workflow, wherein the data is associated with risk factors and analysis silos, wherein the plurality of risk factors correspond to a plurality of risk types, and wherein the analysis silos are associated with organizational roles corresponding to the plurality of risk factors;
determining a score associated with one or more answers from a unified electronic form, wherein determining the score is based on the plurality of risk factors and the workflow, wherein the score is associated with a risk type, wherein the risk type corresponds to a validation endpoint of the workflow, and wherein the one or more answers are associated with the requestor device and are provided in response to one or more questions;
determining, in association with the workflow, that the score exceeds a threshold determined in association with the workflow; and
escalating the data share request based on a routing associated with the workflow.
The broadest reasonable interpretation of the bolded limitations above are directed to a mental process able to be performed in the human mind or by a human using pen and paper. A human can assess a request form, determine a score based on answers on the request form, determine the score exceeds a threshold, and decide to escalate the request mentally or with a pen and paper.
Step 2A, Prong 1 (yes).
Step 2A, Prong 2
The additional elements in this claim are “computer-implemented”. This element is recited at a high level of generality and this is a generic computer component performing computer functions. Thus these are mere instructions to apply the exception using a generic computer component. See MPEP 2106.05(f)
Even when viewed in combination the additional element does not integrate the recited judicial exception into a practical application.
Step 2A, Prong 2 (No).
Step 2B
As explained with respect to Step 2A, the only additional element is “computer-implemented” which at best is mere instructions to apply the abstract ideas and cannot provide an inventive concept, even when considered in combination. See MPEP 2106.05(f).
Step 2B (No).
Claim 1 is ineligible.
With respect to claims 9 and 16,
These claims are similar in scope to Claim 1 and are rejected under similar rationale. The processors and memory recited in these claims are also generic computing components.
Claims 9 and 16 are ineligible.
Dependent Claims:
Claims 3-8, 10-15, and 17-21: these claims recite further abstract ideas (mental processes) and thus are ineligible.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 2-21 and is/are rejected under 35 U.S.C. 103 as being unpatentable over Singh et al. (“A Risk-Benefit Driven Architecture for Personal Data Release”) as made of reference in IDS dated 7/03/2024 in view of Mamorsky (US7,921,045) and Peeler et al. (US2014/0129457).
In regards to claim 2, Singh et al. discloses a computer-implemented method comprising:
assessing a plurality of risk factors associated with a data share request, wherein the data share request represents a request from a requestor device to share a set of data with a third party, wherein the plurality of risk factors correspond to a plurality of risk types (Singh et al. pg45 section IV para1, assesses risks and benefits of access request);
determining a score associated with one or more answers from a unified electronic form, wherein determining the score is based on the plurality of risk factors and the workflow, wherein the score is associated with a risk type(Singh et al. pg47 section V para5-6, determines a risk score for data share request);
determining, in association with the workflow, that the score exceeds a threshold determined in association with the workflow (Singh et al. pg47 section V para5-6, determines if the risk score exceeds a corresponding threshold (benefits) associated with the data share request); and
Singh et al. does not explicitly disclose escalating the data share request based on a routing associated with the workflow.
However Mamorsky discloses escalating the data share request based on a routing associated with the workflow (Mamorsky col7 ln35-62, routes request to corresponding endpoints).
It would have been obvious to one of ordinary skill in the art before the filing date of the invention to have combined the risk analysis method of Singh et al. with the information gathering method of Mamorsky in order to identify risk while maintaining confidentiality (Mamorsky col1 ln62 to col2 ln4).
Singh et al. does not explicitly disclose wherein the data share request is associated with a workflow, wherein the data is associated with risk factors and analysis silos, and wherein the analysis silos are associated with organizational roles corresponding to the plurality of risk factors;
wherein the risk type corresponds to a validation endpoint of the workflow, and wherein the one or more answers are associated with the requestor device and are provided in response to one or more questions;
wherein the data is associated with risk factors and analysis silos, wherein the plurality of risk factors correspond to a plurality of risk types, and wherein the analysis silos are associated with organizational roles corresponding to the plurality of risk factors.
However Peeler et al. discloses wherein the data share request is associated with a workflow, wherein the data is associated with risk factors and analysis silos, and wherein the analysis silos are associated with organizational roles corresponding to the plurality of risk factors (Peeler para[0156], implementing a business rules engine that provides integrated workflow and rules experience, para[0090], In embodiments involving compliance functionality, there may be defined roles for managing, using, and otherwise interacting with the compliance application);
wherein the risk type corresponds to a validation endpoint of the workflow, and wherein the one or more answers are associated with the requestor device and are provided in response to one or more questions (Peeler et al. para[0078], receive answers associated with requestor device in response to question from decision tree);
wherein the data is associated with risk factors and analysis silos, wherein the plurality of risk factors correspond to a plurality of risk types, and wherein the analysis silos are associated with organizational roles corresponding to the plurality of risk factors (Peeler para[0080], requests are routed to analysis locations based on risk factors involved).
It would have been obvious to one of ordinary skill in the art before the filing date of the invention to have combined the risk analysis method of Singh et al. with the compliance facilitation method of Peeler et al. in order to determine how to process requests according to policy (Peeler para[0005]).
In regards to claim 3, Singh et al. as modified by Mamorsky and Peeler discloses the computer-implemented method of claim 2, wherein assessing the plurality of risk factors comprises presenting the one or more questions within the unified electronic form and wherein assessing the plurality of risk factors is based on the one or more answers (Peeler para[0078], assessing security risk according to decision tree, the next question or instruction varies depending on the response to the previous question).
In regards to claim 4, Singh et al. as modified by Mamorsky and Peeler discloses the computer-implemented method of claim 3, further comprising:
determining that the validation endpoint has raised a challenge the one or more answers (Singh et al. pg45 section IV para1, After measuring the risk and benefit, Algorithm 1 compares the two values); and
sending the data share request back to the requestor device (Singh et al. pg45 section IV para1, Otherwise algorithm 1 asks the data owner for a decision).
In regards to claim 5, Singh et al. as modified by Mamorsky and Peeler discloses the computer-implemented method of claim 2, further comprising notifying the requestor device of the determination that the score exceeds the threshold and routing the data share request in real-time to the validation endpoint (Singh et al. pg44 section III para11-12, user receives notification that benefits exceed risk threshold).
In regards to claim 6, Singh et al. as modified by Mamorsky and Peeler discloses the computer-implemented method of claim 2, wherein assessing the plurality of risk factors associated with the data share request comprises:
determining that the data share request requires one or more modifications (Mamorsky et al. col7 ln9-17, if there are deficiencies then the deficiencies are reported in a report deficiencies operation);
allowing the requestor device to modify the data share request (Mamorsky et al. col7 ln18-29, the auditor and operator may then work to resolve any deficiencies reported);
receiving a modified data share request (Mamorsky et al. col7 ln18-29, ultimately a second determination is made to the extent a recommendation can be made); and
assessing the modified data share request (Mamorsky et al. col7 ln30-34, Determines that deficiencies are resolved).
It would have been obvious to one of ordinary skill in the art before the filing date of the invention to have combined the risk analysis method of Singh et al. with the information gathering method of Mamorsky in order to identify risk while maintaining confidentiality (Mamorsky col1 ln62 to col2 ln4).
In regards to claim 7, Singh et al. as modified by Mamorsky and Peeler discloses the computer-implemented method of claim 2, wherein the data share request is among a plurality of recurring data share requests, the method further comprising:
re-evaluating the data share request periodically (Mamorsky et al. col12 ln37-45, the performance of the volatility index and decision tree is periodically reviewed by the plan fiduciary and management team in a periodic review operation).
It would have been obvious to one of ordinary skill in the art before the filing date of the invention to have combined the risk analysis method of Singh et al. with the information gathering method of Mamorsky in order to identify risk while maintaining confidentiality (Mamorsky col1 ln62 to col2 ln4).
In regards to claim 8, Singh et al. as modified by Mamorsky and Peeler discloses the computer-implemented method of claim 2, wherein the plurality of risk factors associated with the data share request includes at least one of:
a category of the set of data, a method for how the set of data is to be shared, a form of encryption, a form of protection, a type of relationship with the third party, a contractual relationship with the third party, data quality, data usage, type of data access, and data requirements (Singh et al. pg47 section V para4, we see risk estimation as a function depending on data consumer and requested data).
Claims 9-15 recites substantially similar limitations as claims 2-8. Thus claims 9-15 are rejected along the same rationale as claims 2-8.
Claims 16-21 recites substantially similar limitations as claims 2-6 and 8. Thus claims 16-21 are rejected along the same rationale as claims 2-6 and 8.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to NICHOLAS HASTY whose telephone number is (571)270-7775. The examiner can normally be reached Monday-Friday 8:30am-5:00pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Matt Ell can be reached at (571)270-3264. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/N.H/Examiner, Art Unit 2141
/TAN H TRAN/Primary Examiner, Art Unit 2141