DETAILED ACTION
This Office Action is with regard to the most recent papers filed 6/11/2026.
Response to Arguments
Applicant's arguments filed 6/11/2026 have been fully considered but they are not persuasive.
On pages 7-8, Applicant argues that Betzler does not disclose or suggest intercepting outbound network traffic from a client device requesting a network service to determine whether said traffic includes a stored data element(s). In support of this, Applicant proceeds to argue that Betzler performs operations “simple matches of worked-upon data to data stored in memory to prevent the registered sensitive data from leaving the computing system…and at most, the Betzler system performs simple matching to prevent sensitive data from leaving the system in response to requests for operations.” As can be seen in Figure 3, request 314 comes from a user, and would be outbound from a user device (client). Column 9, lines 56 to 60 provides that such request includes sensitive data, where such matching would occur. Meanwhile, it is unclear what distinguishes the claim limitations in question from simple matching, as elements of the traffic are being matched (compare) to stored data elements (as a note, Rogynskyy is cited as providing for the use of feature vectors to improve the matching aspect, and meet the generation of the vector embeddings).
On pages 9-10, Applicant argues the finding of Official Notice with regard to claims 6 and 17. First, it is noted that to adequately traverse such a finding, Applicant should state why the noticed fact is not well-known (i.e. that “it would have been well-known to one of ordinary skill in the art at the time of filing to link the request and response together (compare stored network session data), then generate the recipient dataset in a masked form, such that at least one element is unmasked for the user to view.”). Applicant does not even appear to state that this noticed fact is not considered to be well-known (where such a clear statement would be considered to be an adequate traversal, though MPEP 2144.03 C provides that an adequate traversal would include stating “why”). Instead, Applicant argues that the claim language has been improperly reduced to “linking inbound and outbound requests.” However, the steps of claim 6 would provide for such linking, as it serves to first store outbound traffic information (for later use), intercept inbound traffic, compare the inbound information to the outbound information, then generate and transmit the dataset based on the comparing. In this case, one cannot show nonobviousness by attacking references individually where the rejections are based on combinations of references (where the noticed fact would essentially be a reference). See In re Keller, 642 F.2d 413, 208 USPQ 871 (CCPA 1981); In re Merck & Co., 800 F.2d 1091, 231 USPQ 375 (Fed. Cir. 1986). The rejection below provided a rationale of how the linking of the request and response (by storing information of the outbound request and using this to later match to the inbound response) would have modified Betzler, while Applicant appears to argue the noticed fact, alone, with regard to the entirety of the subject matter introduced by claim 6.
Accordingly, the instant claims stand rejected for the reasons provided below.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over US 9,609,025 (Betzler) in view of US 2020/0280565 (Rogynskyy).
With regard to claim 1, Betzler discloses a system comprising:
a network communication interface; one or more processing units; and one or more memories storing (i) a plurality of vector embeddings corresponding to respective ones of a plurality of data elements, (ii) indications of data sensitivity policies applied to respective ones of the plurality of stored data elements, and (iii) instructions that, when executed via the one or more processing units (Betzler: Figure 6), cause the system to:
via the network communication interface, intercept outbound network traffic from a client device (Betzler: Figure 3), the outbound network traffic indicating a request to a network service from the client device (Betzler: Column 9, line 56 to Column 10, line 12. Traffic can be intercepted and analyzed, including requests to access data at a resource.);
apply one or more of the data sensitivity policies to the request to the network service based on whether the outbound network traffic includes at least one of the stored data elements (Betzler: Figure 1. Information on sensitive data is stored, then access to the sensitive data is identified based on the registration (such as via a stored rule), with an action being applied responsive to the detecting.).
Betzler fails to disclose, but Rogynskyy teaches generate one or more vector embeddings based on respective ones of one or more data elements included in the outbound network traffic; compare the one or more generated vector embeddings to the stored plurality of vector embeddings to determine whether the outbound network traffic includes at least one of the stored data elements (Rogynskyy: Paragraph [0073]. Feature vectors can be determined from communications and matched to a record object.).
Accordingly, it would have been obvious to one of ordinary skill in the art at the time of filing to generate (extract) one or more vector embeddings (such as feature vectors of the communication) based on data elements in the traffic, and compare the vectors to stored vector embeddings to determine if the traffic includes at least one of the stored data elements to better match electronic activity to particular records by ensuring that partial matches between the traffic and the sensitive data is determined and handled appropriately.
With regard to claim 2, Betzler in view of Rogynskyy teaches the instructions to apply the one or more of the data sensitivity policies include instructions to: select an approved network service for the request based on the one or more data sensitivity policies; and transmit an outbound dataset to the approved network service to service the request (Betzler: Column 6, lines 28-49. The traffic may be denied or approved, where if access is granted, the traffic is forwarded to the approved network service, with the requested network service would be the selected network service.).
With regard to claim 3, Betzler in view of Rogynskyy teaches that the network service is an intended network service indicated by the request, and wherein the approved network service is the intended network service (Betzler: Column 6, lines 28-49. The traffic may be denied or approved, where if access is granted, the traffic is forwarded to the approved network service, with the requested network service would be the selected network service.).
With regard to claim 4, Betzler in view of Rogynskyy teaches that in response to determining that the outbound network traffic includes at least one of the stored data elements, the system is configured to apply the one or more of the data sensitivity policies to the request by blocking the request to the network service (Betzler: Column 6, lines 28-49. A potential action is to reject the access.).
With regard to claim 5, Betzler in view of Rogynskyy teaches that in response to determining that the outbound network traffic includes at least one of the stored data elements, the instructions to apply the one or more of the data sensitivity policies to the request include instructions to: generate an outbound dataset based on the outbound network traffic, the outbound dataset redacting the at least one of the stored data elements included in the outbound network traffic; and transmit the outbound dataset to an approved network service (Betzler: Column 6, lines 28-49. The data may be masked such that only portions of the data that is marked as accessible may be visible to a user (redacting).).
With regard to claim 6, Betzler in view of Rogynskyy fails to teach, but knowledge possessed by one of ordinary skill in the art at the time of filing teaches that based on determining that the outbound network traffic includes at least one of the stored data elements, the system is further configured to: store network session data indicating the outbound network traffic and the outbound dataset; subsequent to transmitting the outbound dataset, intercept inbound network traffic from the approved network service via the network communication interface; compare the inbound network traffic to the stored network session data; based upon the comparing of the inbound network traffic to the stored network session data, generate a recipient dataset based on the inbound network traffic, wherein the recipient dataset includes the at least one of the stored data elements included in the outbound network traffic; and transmit the recipient dataset to the client device via the network communication interface (More specifically, Betzler teaches actions to be taken on the response to the access (Betzler: Column 6, lines 28-49. The presented data can be masked.), where Official Notice is taken that it would have been well-known to one of ordinary skill in the art at the time of filing to link the request and response together (compare stored network session data), then generate the recipient dataset in a masked form, such that at least one element is unmasked for the user to view.). The suggestion/motivation for doing so would have been that by linking the inbound and outbound traffic, the system would be able to effectively apply the policy to properly mask the provided data. Further, linking inbound and outbound requests by matching the traffic to stored network session data would allow additional functions to be performed, such as logging the traffic associated with the session in an efficient manner.
With regard to claim 7, Betzler in view of Rogynskyy teaches that the instructions, when executed via the one or more processing units, further cause the system to generate the plurality of vector embeddings in response to receiving respective indications of one or more data payloads generated via an enterprise (Betzler: Column 2 ,lines 24-35 and Rogynskyy: Paragraph [0073]. Policies may be provided (indications of one or more payloads generated via an enterprise), which would result in the generation of the vector embeddings to enforce such policies.).
With regard to claim 8, Betzler in view of Rogynskyy teaches that the one or more data sensitivity policies include a policy limiting usage of the network service based on an identity of a user of the client device (Betzler: Column 8, lines 38-63. The rules can be based on the user.).
With regard to claim 9, Betzler in view of Rogynskyy teaches that the one or more data sensitivity policies include a policy limiting usage of the network service based on an intent associated with the request (Betzler: Column 8. Ines 14-38. Lacking detail of how the intent is identified or applied, the limiting usage would be at least based on the intent to access the resource. As a note, Betzler also provides different types of access, such as read, write, or modify (Betzler: Column 2, lines 38-47), where the “securely accessing” can refer to one of these, where such would also provide an “intent” in as much detail as required by the instant claim.).
With regard to claim 10, Betzler in view of Rogynskyy teaches that the one or more data sensitivity policies include a policy configured to expire after a predetermined lifetime or upon receiving an indication of an occurrence of a particular event in an enterprise (Betzler: Column 5, lines 44-61. The instant claim presents two options for the expiration of the policy, where only one of the two options is required to teach the instant claim, as a whole. In the case of Betzler, the policies may be changed, where a particular event of changing the policy would cause the previous policy to expire and be replaced with a new policy.).
With regard to claim 11, Betzler in view of Rogynskyy teaches that the one or more data sensitivity policies include a policy limiting usage of the network service based on whether a second at least one of the stored data elements is included in the outbound network traffic (Rogynskyy: Paragraph [0073]. Multiple matching conditions would need to be met to link the activity.).
With regard to claims 12-19, the instant claims are similar to claims 1-7 and 10, respectively, and are rejected for similar reasons.
With regard to claim 20, the instant claim is similar to claim 1, and is rejected for similar reasons.
Conclusion
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SCOTT B CHRISTENSEN whose telephone number is (571)270-1144. The examiner can normally be reached Monday through Friday, 6AM to 2PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, John Follansbee can be reached at (571) 272-3964. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
SCOTT B. CHRISTENSEN
Examiner
Art Unit 2444
/SCOTT B CHRISTENSEN/Primary Examiner, Art Unit 2444