DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Claims 1-20 are pending.
Claims 1, 2, 5, 6, 8, 12, 13, 15, 19 and 20 have been amended.
Response to Arguments
Applicant's arguments filed 06-09-2026 have been fully considered.
Applicant with respect to rejection of claims under 35 USC 101 for being directed to abstract idea argues that “The limitations of claim are integrated into a practical application and are therefore eligible under Step 2A, Prong 2. In particular, the claimed invention provides a technical solution to a technical problem. Monitoring data volumes holding large datasets for evidence of exfiltration is a resource-intensive process: existing systems require separate queries for each individual data item, and monitoring services may charge per query, making per-item querying both computationally and financially impractical at enterprise scale (see Para. [0002] of Filed Specification)”.
Applicant further argues that “The invention recited in claim 1 solves this problem by employing an iterative semantic narrowing strategy, beginning with a broad natural language description applicable to a large set of data items, and progressively refining it to apply to smaller and smaller subsets, submitting subsequent queries only when a positive response is received at each level (see Paras. [0022], [0023] of Filed Specification). This approach dramatically reduces the number of queries required to identify exfiltrated data, yielding savings in computational resources and query costs (see Para. [0023] of Filed Specification). The claimed method thus improves computational efficiency, a recognized basis for patent eligibility. Enfish, LLC v. Microsoft Corp., 822 F.3d 1327, 1336-37 (Fed. Cir. 2016); MPEP 2106.04(d)(1). This is not a case of applying an abstract idea using generic computer components; the iterative semantic refinement loop is a specific technical mechanism for solving a problem that existing systems did not efficiently address, particularly for unstructured data such as design drawings, images, videos, and plain text that lack the key values on which prior art systems depend (see Para. [0002] of Filed Specification)”.
Applicant’s arguments are not persuasive. The claimed limitation when considered as whole, do not integrate the recited abstract idea into a practical application. Claim 1 for example recites generating a semantic description of data volume, querying the monitoring service with the semantic description,
refining the semantic description based on the results received from the monitoring service, quiring the monitoring service with the semantic description, determining if breach has occurred and upon determining initiating a mitigation action. These limitations primarily concern the collection, analysis and evaluation of information relating to data items and subsequent initiation of mitigation action. Merely specifying that the information is represented as a “semantic description” or a “natural language description” does not impose a technological improvement of the computer or monitoring service.
Further, even assuming that the claimed technique reduces the number of quarries or associated costs, the claim does not recite a particular improvement to the operation of the monitoring service, computer database, network, or other technology. Rather, the improvement is an improvement in the manner in which information is selected and queried. An improvement in the efficiency of an abstract information-processing technique, without a corresponding improvement to the functioning of the computer or another technology, does not by itself establish a practical application.
Further, Applicant’s reliance on Enfish is not persuasive. In Enfish, the claim were directed to specific self-referential database architecture that improved the way a computer stored and retrieved data and thereby improved the function of the computer itself. Here, in contrast, the claim does not recite a particular data structure, database architecture, monitoring architecture, or other technological mechanism that improves the operation of the computer or monitoring service. Here, the claim merely uses an iterative semantic-description and querying process to reduce the number of queries. The alleged improvement is therefore to the information-processing process, not to the computer or monitoring technology.
Applicant further argues that “dependent claim 2 as amended herein recites that the mitigation action includes shutting down user access to the data volume to prevent the spread of affected data (e.g., ransomware). This limitation cannot be performed in the human mind, and is therefore patent eligible under Step 2A, prong 1 of the eligibility analysis. The limitation also grounds the claimed method in a concrete, practical application: actively modifying system access controls in response to a detected breach (see Para. [0029] of Filed Specification). This is similar to the type of meaningful limitations that courts have recognized as integration into a practical application. See discussion of Diamond v. Diehr in MPEP 2106.05(e). The Applicant submits that dependent claim 2 is patent eligible for these additional reasons”.
Applicant’s argument is not persuasive. Although claim 2 recites shutting down user access to the data volume, this limitation merely recites the intended result of mitigation action which could be performed by a human. This additional element does not meaningfully limit how the underlying computer technology operates. Nor does the claim recite a particular technological mechanism for modifying access control. Accordingly, claim 2 does not integrate the recited abstract idea into a practical application under step 2A, Prong 2.
Applicant’s argument with respect to rejection of claims under 35 USC § 103 are moot in view of a new ground of rejection.
Claim Rejections - 35 USC § 112
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112:
The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention.
Claim 1 is rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention.
The limitation in claim 1 reciting “the semantic description comprising a natural language description categorizing a set of data items in the data volume…natural language description categorizing a subset of data items”, is not adequately supported by the specification. Although paragraph 31 of the specification describes generating a natural language description for a portion of data items within a data volume, the specification does not describe the natural language description as categorizing or classifying the data items or subset of data items from the set of data items, or otherwise disclose a relationship in which the natural language description serves to categorize as set of data items or subset of data items.
For example, paragraph 31 states that a generated semantic description may include a natural language description of a portion of data items, such as “design documents relating to self-driving cars mase by X company.” This disclosure describes characteristics of a portion of the data items, but does not reasonably convey that the natural language description categorizes the data items and subset of data items as required by the claim. The specification therefore does not reasonably convey to a person of ordinary skill in the art that at the time of filing, the inventor was in possession of a semantic description comprising natural language description that categorizes a set and subset of data items. Accordingly, the claim is rejected under 35 U.S.C. 112(a), for lack of adequate written description.
Independent claims 8 and 15 include limitations similar to the limitations of claim 1 and are rejected under 35 U.S.C. 112(a) as failing to comply with the written description requirement.
Dependent claims 2-7, 9-14 and 16-20 are rejected under 35 U.S.C. 112(a) based on their dependencies on the independent claims.
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claim 1 rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claim recites “the semantic description comprising a natural language description categorizing a set of data items in the data volume…refine the semantic description to a more specific natural language description categorizing a subset of data items…query the monitoring service with the semantic description”.
In particular, it is unclear what is meant by natural language description “categorizing” the set of data items and natural language description “categorizing” a subset of data items. The claim does not specify how natural language description categorizes the data items, what characteristics of the data items are used for the categorization of a set of data items and subset of data items from the set of data items, or what constitutes a category of data items.
Further, it is unclear whether the limitation of “query the monitoring service with the semantic description” after refining step of the claim, refers to semantic description “comprising a natural-language description categorizing as set of data items…” or it is referring to the refined “semantic description to a more specific natural language description categorizing a subset of data items”. Thus, the metes and bounds of the claimed subject matter cannot be ascertained with reasonable certainty.
Independent claims 8 and 15 include limitations similar to the limitations of claim 1 and are rejected under 35 U.S.C. 112(b) as failing to comply with the written description requirement.
Dependent claims 2-7, 9-14 and 16-20 are rejected under 35 U.S.C. 112(b) based on their dependencies on the independent claims.
Claim Rejections - 35 USC § 101
835 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
The claims when analyzed under 2019 Revised Patent Subject Matter Eligibility Guidance, are directed to abstract idea. Claim 1 for example, recites a method and, therefore, is a process. The claim recites the limitation of: “…generating a semantic description of a data volume, the semantic description comprising natural language description…; querying a monitoring service with the semantic description; determining, based on results received from the monitoring service, to iteratively, until determining that a breach occurred: refine the semantic description to be more specific natural language description categorizing a subset of data items…; query the monitoring service with the semantic description, and determine whether the breach occurred based on results received from the monitoring service in response to the semantic description; and upon determining that the breach occurred, initiating a mitigation action.…”. These limitations, under broadest reasonable interpretation are directed performance of the limitation in a human mind. That is, nothing in the claim element precludes the step from practically being performed in the mind. For example, the claim encompasses a human/person simply transforming a data to a different form (semantic description), refining/modifying the semantic description to be more specific, querying another person with the semantic description, receiving from the other person a result on a piece of paper or via an electronic mail, by looking at the result, determining if a breach occurred, and initiation a mitigation action. For example, the steps of determining whether a breach occurred based on results and initiating mitigation action is directed to abstract idea.
Claim is further analyzed in step 2A prong 2, to evaluate whether the claim as a whole integrates the recited judicial exception into a practical application of the exception. This evaluation is performed by identifying whether there are any additional elements recited in the claim beyond the judicial exception, and evaluating those additional elements individually and in combination to determine whether the claim as a whole integrates the exception into a practical application. However, each of the remaining limitation do not constitute meaningful limitations that would amount to significantly more than the abstract idea. The combination of additional element is no more than generic computer functions. Thus, even in combination, the additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limitations on practicing the abstract idea.
Claim is additionally analyzed under Step 2B to evaluates whether the claim as a whole amount to significantly more than the recited exception, whether any additional element, or combination of additional elements, adds an inventive concept to the claim. When claims evaluated under step 2B, it is no more than what is well-understood, routine, conventional activity in the field. The specification does not provide any indication anything other than a generic computer component. The mere “…generating a semantic description… querying a monitoring service with the semantic description…refine the semantic description to be more specific…query the monitoring service with the semantic description, and determine whether the breach occurred… [and] initiating a mitigation action.……” is a well-understood, routing and conventional function when it is claimed in a merely generic manner as it is here.
Independent claims 8 and 15 include limitations similar to the limitations of claim 1 and are rejected under 35 U.S.C. 101 as being directed to abstract idea for the same reasons discussed above with respect to claim 1.
Dependent claims 2-7, 9-14 and 16-20 do not recite nor impart any further limitation(s) that would bring the invention in conformance with 35 U.S.C. §101 as patentable subject matter.
Claims 2, 9 and 16 recite additional element of performing mitigation action comprises verifying that the breach occurred by using one or more of a hash value and a key value. This is additional data checking and comparison, which is part of the same abstract information-processing and does not include inventive concept, such as improving computer functionality itself or creating a technical solution. Claim also recite the additional element of shutting down user access to the data volume could be performed by human. This additional element does not meaningfully limit how the underlying computer technology operates. Accordingly, claim does not integrate the recited abstract idea into a practical application.
Claims 3 10 and 17, further narrows the verifying step recited in claim 2. The verifying step includes generating the hash value, querying the monitoring service to determine if the hash value matches corresponding hash value of any of a plurality of exfiltrated data items, and receiving an indication of a match. These steps recite particular way of comparing data values, but they remain conventional data generation, quarrying, and matching operations and do not integrate the abstract idea into a practical application because they do not impose meaningful limits on practicing the abstract idea.
Claims 4 11 and 18, recite the verifying step recited in claim 2 includes identifying a key value in the data item, querying the monitoring service to indicate if the key value has been exfiltrated in the breach, and receiving an indication that the key value has been exfiltrated in the breach. This further narrows the type of information compared, but still amounts to querying and comparing data values using a generic computer, and does not include inventive concept, such as improving computer functionality itself or creating a technical solution.
Claims 5, 12 and 19 adds the generating the semantic description includes reading a plurality of data items in the data volume, and generating a natural language description applicable to portion of the plurality of data items. This specifies how the abstract “semantic description” is generated, but it is still generation of a semantic description of data time and does not include inventive concept, such as improving computer functionality itself or creating a technical solution.
Claims 6, 13 and 20, recites additional element of the set of data items comprise one or more of :documents, images, videos, or unstructured text, which amount to mere data gathering, which is a form of insignificant extra-solution activity. Insignificant extra-solution activity does not amount to an inventive concept, particularly when the activity is well-understood or conventional. Accordingly, these additional elements do not integrate the abstract idea into a practical application because they do not impose meaningful limits on practicing the abstract idea.
Claims 7 and 14, recite the generating semantic description includes querying an enterprise system that owns the data volume for the semantic description of the data volume and receiving the semantic description generated by the enterprise system. This is still uses conventional querying of a system, and does not include inventive concept, such as improving computer functionality itself or creating a technical solution.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 5-8, 12-15, 19 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Baskaran et al. (US Patent No.11,392,605), hereinafter Baskaran in view of Korn et al. (US Patent No.12,360,962), further in view of Chen et al. (US Publication No. 2020/0410000), hereinafter Chen.
As per claim 1, 8 and 15, Baskaran discloses a method of operating a data protection service, comprising: generating a semantic description of a data volume (column 67, lines 21-23 and column 70, lines 9-10, “transformed data stream”); querying a monitoring service with the semantic description (column 67,lines 51-52, “process the transformed data stream”, column 70, lines 36-37, “the transformed data stream is analyzed”); determining, based on results received from the monitoring service, to iteratively, until determining that a breach occurred (column 70, lines 48-50, “The anomaly model may be continually executed with continually received portions of the data stream”): query the monitoring service with the semantic description, and determine whether the breach occurred based on results received from the monitoring service in response to the semantic description (column 67, lines 51-53, the analyzer processes the transformed data stream, column 70, lines 44-48, “features from the data points in the data stream 1310 are extracted and used as input to the anomaly model, the output of the anomaly model is the analysis results. For example, the output may be whether an anomaly is detected”), and upon determining that the breach occurred, initiating mitigation (column 54, lines 55-62, column 55, lines 15-17, alert is generated when anomalous incidents is detected).
Baskaran does not explicitly disclose, refine the semantic description to be more specific. However, in an analogous art, Koran discloses, refine the semantic description to be more specific (column 17, lines 17-22, “determine…second description for the fields of the first data, the second descriptions have a finer level of detail in describing the files than the filed that the first description”).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Baskaran with Koran. This would have been obvious because one of the ordinary skill in the art would have been motivated to improve variety of descriptions in order to detect malicious activities.
Baskaran in view of Koran does not explicitly disclose, the semantic description comprising a natural language description categorizing a set of data items in the data volume; and natural language description categorizing a subset of data items from the set of data items, wherein the subset of data items is smaller than the set of data items. However, in an analogous art, Chen discloses, the semantic description comprising a natural language description categorizing a set of data items in the data volume (paragraph [0078] the dataset 603 is associated with a description 605, the description 605 represent natural language description, paragraph -[0079], “the one or more categories maybe associated with dataset 603 as a whole”); and natural language description categorizing a subset of data items from the set of data items, wherein the subset of data items is smaller than the set of data items (paragraph [0079], “The one or more categories may be associated with the dataset 603 based on a portion of the dataset 603”).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Baskaran and Koran with Chen. This would have been obvious because one of ordinary skill in the art would have been motivated to improve reliability and performance of systems that perform dataset categorization and validation.
As per claim 5, 12, and 19, Chen furthermore discloses, wherein the generating the semantic description comprises: reading a plurality of data items in the data volume; and generating a natural language description applicable to a portion of the plurality of data items (paragraph [0078]-[0079], description 605 represent natural language representation of a row or column of the dataset 603). The motivation is similar to the motivation provided in claim 1.
As per claims 6, 13 and 20, Chen furthermore discloses, wherein the set of data items comprise one or more of: documents, images, video, or unstructured text (paragraph [0076], “The dataset 603 may
include various types of data including, for example, numeric data, textual data, image data, audio data, and the like”). The motivation is similar to the motivation provided in claim 1.
As per claim 7 and 14, Korn furthermore discloses wherein the generating the semantic description comprises: querying an enterprise system for the semantic description of the data volume, wherein the enterprise system owns the data volume; and receiving the semantic description, the semantic description being generated by the enterprise system (column 11, lines 15-17 and 65-66, semantic data model sending a request for field descriptions to the large language model, the large language model sending field descriptions to the semantic data model). The motivation is similar to the motivation provided in claim 1.
Claims 2-4, 9-11 and 16-18 are rejected under 35 U.S.C. 103 as being unpatentable over Baskaran, in view of Korn and Chen, further in view of Fridman et al. (US Patent No.10,498,748).
As per claim 2, 9 and 16, Baskaran as modified does not explicitly disclose, but in an analogous art, Fridman discloses, performing the mitigation action, wherein the performing the mitigation action comprises verifying that the breach occurred for a data item in the data volume using one or more of a hash value associated with the data item and a key value associated with the data item (column 8, lines 46-57, “ detection cluster 54, using the key 65, applies the same forward hash function to the data content
to be examined. The detection cluster 54 then search the data content in the hashed data files using the search index to detect for matched content… in the event that matched data content in the hashed data files is found and the matched data content is deemed to be in violation of the enterprise's security policy, the detection cluster 54 may generates a warning flag or an alert in the detection result indicating potential violations”, column 9, lines 1-3, “if the last name and the social security number of a data record are found in a data being examined, then violation is flagged”), and shutting down user access to the data volume to prevent a spread of affected data ( column 3, lines 9, “The enterprise employs the cloud based DLP system of the present invention to perform inspection of the enterprise’s network data content using the search index to prevent enterprise’s sensitive data to be accessed in a manner in violation of the enterprise’s security policy”).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the modified Baskaran with Fridman. This would have been obvious because one of ordinary skill in the art would have been motivated to detect data loss in network data content belonging to an enterprise.
As per claim 3,10 and 17, Fridman furthermore discloses, wherein the verifying that the breach occurred comprises: generating the hash value associated with the data item; querying the monitoring service with a request to determine if the hash value matches a corresponding hash value of any of a plurality of exfiltrated data items; and receiving, from the monitoring service, an indication that one of the plurality of exfiltrated data items has a matching hash value (column 7, lines 3-7, “the database 62 is forward hashed or encoded using a hasher 64 on the premises of the enterprise data network to generate a pre-index. The hasher 64 uses a key 65 belonging to or controlled by the enterprise. The hasher 64 applies a forward hash function to the database 62”, column 8, lines 43-52, “used by the enterprise to perform forward hashing of the database 62. The detection cluster 54, using the key 65, applies the same forward hash function to the data content to be examined. The detection cluster 54 then search the data content in the hashed data files using the search index to detect for matched content. The detection cluster 54 performs detection in accordance with the enterprise's security policy and generates detection results that are provided to the enterprise”). The motivation is similar to the motivation provided in claim 2.
As per claim 4, 11 and 18, Fridman furthermore discloses wherein the verifying that the breach occurred comprises: identifying the key value in the data item; querying the monitoring service with a request to indicate if the key value has been exfiltrated in the breach; and receiving, from the monitoring service, an indication that the key value has been exfiltrated in the breach (column 9, lines 1-3, “if the last name and the social security number of a data record are found in a data being examined, then violation is flagged”). The motivation is similar to the motivation provided in claim 2.
References Cited, Not Used
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Dey et al. (US Publication No. 2022/0327352) discloses, systems, apparatuses, and methods for providing natural language explanation to black-box algorithm generated outcome. The system is configured to determine a regression coefficient for each of the plurality of attributes based regression analysis, determine a decision tree based on the input data and the output data and a decision path of a select data item in the decision tree, generate natural language explanation of a categorization of the select data item based on the relevant attributes and regression coefficients associated with each of the relevant attributes, wherein the natural language explanation identifies at least one relevant attribute and an effect of the at least one relevant attribute of the data item on the categorization, and transmit to a user interface device for display, the categorization of the select data item along with the natural language explanation of the categorization of the select data.
Zoppas et al. (US Patent No. 8,255,370) discloses, a method and apparatus for scanning structured data from a data repository having an arbitrary data schema and for applying a policy to the data of the data repository are described. In one embodiment, the structured data is converted to unstructured text data to allow a schema-independent policy to be applied to the text data in order to detect a policy violation in the data repository regardless of the data schema used by the data repository.
Fineis et al. (US Publication No.2018/0060703) discloses, a platform may receive multivariate data from an asset in an original coordinate space and transform the data in the original coordinate space to a transformed coordinate space. Additionally, the platform may standardize the data in the transformed coordinate space and modify the standardized data. Thereafter, the platform may inversely transform the modified data back to the original coordinate space and perform an analysis to detect anomalies.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Ali Abyaneh whose telephone number is (571) 272-7961. The examiner can normally be reached on Monday-Friday from (8:00-5:00). If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached on (571) 270-5143. can be reached on (571) 272-4063. The fax phone numbers for the organization where this application or proceeding is assigned as (571) 273-8300 Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free).
/ALI S ABYANEH/Primary Examiner, Art Unit 2437