DETAILED ACTION
Response to Arguments
Applicant's arguments (“REMARKS”) filed 08 April 2026 have been fully considered, and they are partially persuasive as to the previous grounds of rejection.
Claims 1, 7-8, and 14 were amended. Claim 19 was canceled. Claim 21 is new. Claims 1, 8, and 15 are independent. Claims 1-18 and 21 are currently pending.
Re: Claim Rejections Under 35 U.S.C. §112(b)
The rejection of claim 19 under 35 U.S.C. §112(b) has been withdrawn in view of Applicant’s cancelation of claim 19 as indicated on pp.7-8 of the REMARKS.
Re: Claim Rejections Under 35 U.S.C. §103
Applicant’s arguments, indicated on pp.6-8 of the REMARKS, in response to the rejection of the claims under 35 U.S.C. §103 with respect to Eldefrawy et al., US 2022/0052835 A1 (hereinafter, “Eldefrawy ‘835”), Irwin, US 2014/0068265 A1 (hereinafter, “Irwin ‘265”), and Liu et al., US 2017/0006025 A1 (hereinafter, “Liu ‘025”) have been fully considered, and they are partially persuasive as to the previous grounds of rejection. In particular, Applicant argues that:
With respect to independent claims 1, 8, and 15, the cited references do not disclose the limitation “wherein the metadata comprises required instructions on how to open and identify the trusted data element”, as amended.
With respect to dependent claims 7, 14, and 21, the cited references do not disclose the limitation “determining that an access attempt to the unstructured dataset is not acceptable according to access control information; and dynamically updating a policy to revoke user access to the unstructured dataset in response to determining that the access attempt is not acceptable”, as amended.
In Response to Argument A
Applicant has amended the independent claims to incorporate the limitation “wherein the metadata comprises required instructions on how to open and identify the trusted data element”, previously recited in dependent claims 7 and 14, and argues that Eldefrawy ‘835, Irwin ‘265, and Liu ‘025 fail to disclose this limitation.
The Examiner respectfully disagrees. The Applicant’s argument is not persuasive.
As an initial matter, Applicant has not proposed any interpretations of the term “required instructions on how to open and identify the trusted data element”, and the Specification does not provide a specific definition. The Specification, at ¶10, states that the trusted data element may be encrypted using a specific key and that required instructions on how to open and identify the trusted data element are included in the metadata. This passage restates the claim language without specifically defining it. Thus, this limitation is being interpreted under the broadest reasonable interpretation in light of the Specification. “[R]equired instructions on how to open and identify the trusted data element” may be interpreted as metadata content sufficient to permit a recipient to recognize the protected element and to obtain and apply the means to decrypt it.
Eldefrawy ‘835, at ¶73, discloses that, as metadata for the encryption, one could add the encryption policy together with identifiers of the public keys of the attributes used for encryption. Eldefrawy ‘835, at ¶77, discloses that a recipient receives a ciphertext C = {C1, C2} encrypted under a policy P, and ¶78 discloses that the recipient must decrypt one of the clause-level ciphertexts to obtain the symmetric key kAES, and that in order to decrypt any terms the user must possess the right keys. Eldefrawy ‘835, at ¶80, discloses that, once kAES is recovered, the recipient decrypts C1 and recovers the actual data field. The encryption policy and the public key identifiers carried in the metadata are therefore the information that tells the recipient which of its keys must be applied, and in what combination, in order to open the encrypted data subgroup. Without the metadata, disclosed in ¶73, the decryption procedure of ¶¶77-80 could not be performed. Eldefrawy ‘835 further discloses at ¶97 that elements within the document are tagged as protected elements with specific security attributes or a security policy, and at ¶94 that the security attributes or security policy are applied as tags, such as XML tags or metadata, to the data subgroups, thereby identifying the protected element. Accordingly, the metadata of Eldefrawy ‘835 comprises the required instructions on how to open and identify the encrypted data subgroup (i.e., “required instructions on how to open and identify the trusted data element”).
Next, Applicant asserts on p.9 of the REMARKS that ‘Irwin ‘265 does not even mention metadata including required instructions’. The Examiner respectfully disagrees. Irwin ‘265, at ¶6, discloses that the metadata labels may include security instructions, and that the primary node may be configured to encrypt data based on those security instructions. Irwin ‘265 further discloses at ¶12 that the cryptographic binding may occur through the use of a local encryption key which may later be used to decode the message at the destination. Irwin ‘265, at ¶35, discloses that the message, the security metadata, and the binding are sent to the destination module, where the message is later decoded using the local encryption key. Irwin ‘265 therefore discloses metadata that both accompanies the protected message and carries the instructions and key material used to open the message at its destination.
The additional discussion of ¶6 of Irwin ‘265 and of paragraphs ¶¶77-80 of Eldefrawy ‘835, as discussed above, is provided in response to Applicant’s arguments to further clarify the findings previously made. It does not alter the basis of the rejection of the independent claims, and no new ground of rejection is entered against the independent claims.
With respect to Liu ‘025, Applicant asserts that that Liu ‘025 does not disclose metadata comprising required instructions on how to open and identify the protected content. Liu ‘025, at ¶27, discloses that the metadata received with the protected media asset includes a key ID that is a globally unique identifier identifying the media content, together with a URL of the license server. Furthermore, ¶30 of Liu ‘025 discloses that the license server, identified through that URL, obtains the key ID and returns the content key necessary to decrypt the media asset. The metadata of Liu ‘025 thus both identifies the protected content and specifies where and how the key required to open that content is obtained.
The rejection of the independent claims is based on the combined teachings of Eldefrawy ‘835, Irwin ‘265, and Liu ‘025. Applicant addresses each reference individually and concludes that no single reference discloses the disputed limitation. Nonobviousness cannot be established by attacking references individually where the rejection is predicated on a combination of references. See In re Keller, 642 F.2d 413 (CCPA 1981); In re Merck & Co., 800 F.2d 1091 (Fed. Cir. 1986); MPEP § 2145(IV).
For at least these reasons, Applicant’s arguments directed to the independent claims are not persuasive, and the rejection of the independent claims under 35 USC §103 is maintained.
In Response to Argument B
Applicant argues, with respect to dependent claims 7, 14, and 21, that the cited references do not disclose the limitation “determining that an access attempt to the unstructured dataset is not acceptable according to access control information; and dynamically updating a policy to revoke user access to the unstructured dataset in response to determining that the access attempt is not acceptable”, as amended.
The Applicant’s argument is persuasive.
With respect to dependent claims 7, 14, and 21, Applicant’s arguments and amendments have necessitated new ground(s) of rejection presented in this Office Action. A new ground of rejection has been asserted over Indukuri et al., US 2019/0266347 A1 (hereinafter, “Indukuri ‘347”).
Indukuri ‘347 discloses a data anchor system for controlling use of sensitive data in which protected data is encrypted with a data key. The encrypted data key is stored in metadata of the protected data, and an access control layer checks the metadata for an access context before obtaining the key required to decrypt the protected data (Indukuri ‘347, ¶¶14, 73, 107). Indukuri ‘347 further discloses that access to protected data is revoked when a user attempts to access the data outside of specified areas (i.e., an access attempt fails to satisfy the governing access control criteria) (Indukuri ‘347, ¶93). The system revokes access whenever the applicable boundary is violated, even where the violation is discovered after the fact (Indukuri ‘347, ¶44). Access to the sensitive data may be removed if the security rules are broken at any point in time, and that the system dynamically combines rule-based access and revocation across time (Indukuri ‘347, ¶59). Indukuri ‘347 characterizes this operation as ‘dynamic revocation’, where the state of a user is toggled between accessible and revoked (Indukuri ‘347, ¶120). Indukuri ‘347 additionally discloses determining whether a requesting user device has exceeded an access control criteria threshold and, in response to that threshold being exceeded, adjusting the terms on which encryption keys are supplied to that device. (Indukuri ‘347, ¶¶17, 26, 53, 65, 74-75).
Thus, Indukuri ‘347 discloses, at least, the limitation “determining that an access attempt to the unstructured dataset is not acceptable according to access control information; and dynamically updating a policy to revoke user access to the unstructured dataset in response to determining that the access attempt is not acceptable”, as amended.
With respect to new dependent claim 21, Applicant’s argument is not persuasive with respect to the remaining limitations. The limitation “identify a controller to manage access to the individual data elements within the unstructured dataset” is disclosed by Liu ‘025, which discloses that metadata received with protected content includes a URL through which a license server is identified, and that the identified license server determines whether access to the protected content is authorized and supplies the content key required to decrypt it (Liu ‘025, ¶¶27, 30, 33). The limitation “manage the access to the individual data elements by utilizing the controller” is disclosed by Eldefrawy ‘835, which discloses a decryption service that receives a call from a user device together with the secret key associated with the requesting user, determines whether the user’s key attributes satisfy the security policy assigned to the individual data subgroups within the unstructured data container, and selectively decrypts those individual data subgroups for which the policy is satisfied (Eldefrawy ‘835, ¶¶22-23, 102-105).
Thus, for the reasons stated above, the rejection of claims 1-6, 8-13, 15-18, and 20 under 35 U.S.C. 103 is maintained. The new grounds of rejection entered with respect to claims 7, 14, and 21 are necessitated by Applicant's amendments.
See Claim Rejections – 35 USC §103 below for further details.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention.
Claims 1-6, 8-11, 13, 15-18, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Eldefrawy et al., US 2022/0052835 A1 (hereinafter, “Eldefrawy ‘835”), in view of Irwin, US 2014/0068265 A1 (hereinafter, “Irwin ‘265”), and further in view of Liu et al., US 2017/0006025 A1 (hereinafter, “Liu ‘025”).
As per claim 1: Eldefrawy ‘835 discloses:
A computer implemented method for protecting individual data elements within an unstructured dataset (a computer-implemented method for selectively encrypting and protecting portions of data, i.e., data subgroups, within unstructured data containers such as Microsoft Word files, Microsoft Excel files, image files, PDF files, and the like [Eldefrawy ‘835, ¶¶3, 9, 24, 93; Figs. 1-3]), the method comprising:
encrypting a data element within an unstructured dataset comprising generating a trusted data element encrypted using a specific key (selectively encrypting one or more data subgroups within an unstructured data container using encryption keys, such as AES-256 or RSA keys, to generate an encrypted ciphertext, where the encrypted data subgroup corresponds to a “trusted data element” [Eldefrawy ‘835, ¶¶7, 9, 43, 55, 67-74, 97; Figs. 2-3])
wherein the trusted data element is encapsulated and (the encrypted data subgroups are encapsulated with security attributes or security policies that are applied as metadata, e.g., XML tags, to the data subgroups, where the security attributes/policies determine which users are entitled to decrypt and access the data based on whether their decryption keys satisfy the security policy [Eldefrawy ‘835, ¶¶21-23, 73, 91, 94, 97]); and
(as stated above, metadata comprising security attributes or security policies is associated with the encrypted data subgroups [Eldefrawy ‘835, ¶¶73, 94]),
wherein the encrypted data element and the metadata are (the data subgroups are encrypted using data encryption keys, such as AES keys or RSA keys, and are associated with metadata including encryption policy information [Eldefrawy ‘835, ¶¶55, 67-74, 82]),
wherein the metadata comprises required instructions on how to open and identify the trusted data element (metadata for the encryption includes the encryption policy with identifiers of the public keys of the attributes used for encryption, where the encryption policy and key identifiers provide the required instructions on how to open and identify the encrypted data subgroup [Eldefrawy ‘835, ¶¶73, 77-80]).
As stated above, while Eldefrawy ‘835 discloses encrypting data elements within unstructured data containers and associating the encrypted data with metadata containing security policy information to determine user entitlement, Eldefrawy ‘835 does not explicitly disclose the limitation “cryptographically bound” and “… metadata that identifies an access controller …”.
Irwin ‘265, however, discloses:
... wherein the trusted data element is encapsulated and cryptographically bound to metadata ... (a primary node configured to create a local encryption key to cryptographically bind metadata labels to data messages [Irwin ‘265, ¶¶6-7, 10, 12])
... cryptographically binding the encrypted data element to metadata ... (the security metadata is obtained and then cryptographically bound to the message using a local encryption key [Irwin ‘265, ¶¶6, 10, 12, 35])
... wherein the encrypted data element and the metadata are cryptographically bound using data encryption keys ... (the security metadata for the source node is obtained and then cryptographically bound to the message using a local encryption key, where the message is later decoded using the local encryption key [Irwin ‘265, ¶¶6-7, 10, 12, 35]).
Eldefrawy ‘835 and Irwin ‘265 are analogous art because they are from the same field of endeavor, namely that of protecting data through encryption and associating security metadata with data. Prior to the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art, having the teachings of Eldefrawy ‘835 and Irwin ‘265 before them, to modify the method in Eldefrawy ‘835 to include the teachings of Irwin ‘265, namely to implement the association between the encrypted data subgroups and the security policy metadata of Eldefrawy ‘835 using the cryptographic binding technique disclosed in Irwin ‘265, where the metadata is cryptographically bound to the data using encryption keys. A motivation for doing so would be to ensure that the metadata cannot be tampered with or separated from the data it protects, thereby maintaining the integrity of the security information associated with the protected data (see Irwin ‘265, ¶¶6-7, 27, 35).
As stated above, Eldefrawy ‘835 in view of Irwin ‘265 does not explicitly disclose the limitation “… metadata that identifies an access controller …”.
Liu ‘025, however, discloses:
... metadata that identifies an access controller (metadata received with protected media content includes a URL of a license server that acts as an access controller, where the license server is identified through the URL included in the metadata and determines whether access to the protected content is authorized [Liu ‘025, ¶¶27, 30, 33]) ...
Eldefrawy ‘835 (modified by Irwin ‘265) and Liu ‘025 are analogous art because they are from the same field of endeavor, namely that of protecting data through encryption and controlling access to protected content. Prior to the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art, having the teachings of Eldefrawy ‘835 (modified by Irwin ‘265) and Liu ‘025 before them, to modify the method in Eldefrawy ‘835 (modified by Irwin ‘265) to include the teachings of Liu ‘025, namely to include in the metadata associated with the encrypted data elements an identifier, such as a URL, that identifies the access controller responsible for managing access to the protected data, as disclosed in Liu ‘025. A motivation for doing so would be to enable the protected data elements to be properly routed to the correct access controller for authorization regardless of where the data travels, thereby ensuring consistent access control enforcement (see Liu ‘025, ¶¶27, 30).
As per claim 2: Eldefrawy ‘835 in view of Irwin ‘265, and further in view of Liu ‘025 discloses all limitations of claim 1, as stated above, from which claim 2 is dependent upon. Furthermore, Eldefrawy ‘835 discloses:
further comprising detecting an access attempt to the dataset (a decryption service receives a call from a user device to selectively decrypt one or more data subgroups within an encrypted document, where the call corresponds to detecting an access attempt to the dataset [Eldefrawy ‘835, ¶¶102-104]); and
determining whether the access attempt is acceptable according to access control information (the decryption service determines whether the user’s decryption keys satisfy the security policy assigned to the encrypted data subgroups, where decryption is possible only when the key attributes satisfy the security policy, i.e., the access control information [Eldefrawy ‘835, ¶¶22-23, 102-105]).
As per claim 3: Eldefrawy ‘835 in view of Irwin ‘265, and further in view of Liu ‘025 discloses all limitations of claims 1-2, as stated above, from which claim 3 is dependent upon. Furthermore, Eldefrawy ‘835 discloses:
further comprising denying the access attempt responsive to determining the access attempt is not acceptable according to the access control information (decryption is possible only when the key attributes satisfy the security policy; if the user’s decryption keys do not satisfy the security policy assigned to the encrypted data subgroups, the decryption service outputs an error and the data remains encrypted, thereby denying access to the data [Eldefrawy ‘835, ¶¶22-23, 31, 36-37, 42, 105]).
As per claim 4: Eldefrawy ‘835 in view of Irwin ‘265, and further in view of Liu ‘025 discloses all limitations of claims 1-2, as stated above, from which claim 4 is dependent upon. Furthermore, Eldefrawy ‘835 discloses:
further comprising allowing the access attempt responsive to determining the access attempt is acceptable according to the access control information (when the user’s decryption keys satisfy the security policy assigned to the encrypted data subgroups, the decryption service selectively decrypts the data and provides the selectively decrypted document to the requesting user device, thereby allowing access to the data [Eldefrawy ‘835, ¶¶22-23, 105-106]).
As per claim 5: Eldefrawy ‘835 in view of Irwin ‘265, and further in view of Liu ‘025 discloses all limitations of claim 1, as stated above, from which claim 5 is dependent upon. Furthermore, Eldefrawy ‘835 discloses:
wherein the encrypted data element and the metadata are (the actual data is encrypted using a standardized symmetric encryption scheme, e.g., AES 256, where AES-256 is an industry standard encryption scheme [Eldefrawy ‘835, ¶¶7, 43, 55, 81]).
As stated above, Eldefrawy ‘835 does not explicitly disclose the limitation “… cryptographically bound …”.
Irwin ‘265, however, discloses:
... wherein the encrypted data element and the metadata are cryptographically bound ... (a primary node configured to create a local encryption key to cryptographically bind metadata labels to data messages [Irwin ‘265, ¶¶6-7, 10, 12, 35])
Eldefrawy ‘835 and Irwin ‘265 are analogous art because they are from the same field of endeavor, namely that of protecting data through encryption and associating security metadata with data. For the reasons stated in claim 1, prior to the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art, having the teachings of Eldefrawy ‘835 (modified by Liu ‘025) and Irwin ‘265 before them, to modify the method in Eldefrawy ‘835 (modified by Liu ‘025) to include the teachings of Irwin ‘265.
As per claim 6: Eldefrawy ‘835 in view of Irwin ‘265, and further in view of Liu ‘025 discloses all limitations of claim 1, as stated above, from which claim 6 is dependent upon. Furthermore, Eldefrawy ‘835 discloses:
wherein the trusted data element corresponds to the data element containing confidential information (the encrypted data subgroups correspond to sensitive data requiring protection, such as information associated with clearance levels like TOP SECRET, SECRET, or CONFIDENTIAL, or fine-grained confidential information such as costs and fees [Eldefrawy ‘835, ¶¶4, 6, 21, 24]).
As per claims 8-11: Claims 8-11 define a computer program product that recites substantially similar subject matter as the method of claims 1-4, respectively. Specifically, claims 8-11 are directed to a computer program product comprising one or more computer readable storage media and program instructions stored on the one or more computer readable storage media, the program instructions comprising instructions to perform the computer-implemented method of claims 1-4, respectively. Thus, the rejection of claims 1-4 is equally applicable to claims 8-11, respectively.
As per claim 13: Eldefrawy ‘835 in view of Irwin ‘265, and further in view of Liu ‘025 discloses all limitations of claims 8-9, as stated above, from which claim 13 is dependent upon. Furthermore, Eldefrawy ‘835 discloses:
wherein the trusted data element corresponds to the data element containing confidential information (the encrypted data subgroups correspond to sensitive data requiring protection, such as information associated with clearance levels like TOP SECRET, SECRET, or CONFIDENTIAL, or fine-grained confidential information such as costs and fees [Eldefrawy ‘835, ¶¶4, 6, 21, 24]).
As per claim 15: Eldefrawy ‘835 discloses:
A computer system, the computer system comprising: one or more computer processors; one or more computer-readable storage media; program instructions stored on the computer-readable storage media for execution by at least one of the one or more processors, the program instructions comprising instructions to: (a computer system 500 comprising one or more processors 510a-510n coupled to a system memory 520, where the system memory 520 stores program instructions 522 executable by the processor 510 to implement the described methods [Eldefrawy ‘835, ¶¶124, 126, 129; Fig.5])
encrypt a data element within an unstructured dataset comprising generating a trusted data element encrypted using a specific key (selectively encrypting one or more data subgroups within an unstructured data container using encryption keys, such as AES-256 or RSA keys, to generate an encrypted ciphertext, where the encrypted data subgroup corresponds to a “trusted data element” [Eldefrawy ‘835, ¶¶7, 9, 43, 55, 67-74, 97; Figs.2-3]),
the trusted data element corresponding to the data element containing confidential information (the encrypted data subgroups correspond to sensitive data requiring protection, such as information associated with clearance levels like TOP SECRET, SECRET, or CONFIDENTIAL, or fine-grained confidential information such as costs and fees [Eldefrawy ‘835, ¶¶4, 6, 21, 24]),
wherein the trusted data element is encapsulated and (the encrypted data subgroups are encapsulated with security attributes or security policies that are applied as metadata, e.g., XML tags, to the data subgroups, where the security attributes/policies determine which users are entitled to decrypt and access the data based on whether their decryption keys satisfy the security policy [Eldefrawy ‘835, ¶¶21-23, 73, 91, 94, 97]); and
(as stated above, metadata comprising security attributes or security policies is associated with the encrypted data subgroups [Eldefrawy ‘835, ¶¶73, 94]),
wherein the encrypted data element and the metadata are (the data subgroups are encrypted using data encryption keys, such as AES keys or RSA keys, and are associated with metadata including encryption policy information [Eldefrawy ‘835, ¶¶55, 67-74, 82]) that are user defined (users select document fields to encrypt and specify decryption policy, i.e., which attributes should be used for each field, where encryption keys are generated for each user-specified attribute; accordingly, the encryption keys are user defined in the sense that they are determined based on user-specified attributes and policies [Eldefrawy ‘835, ¶¶48, 66, 91]), and
the metadata comprises required instructions on how to open and identify the trusted data element (metadata for the encryption includes the encryption policy with identifiers of the public keys of the attributes used for encryption, where the encryption policy and key identifiers provide the required instructions on how to open and identify the encrypted data subgroup [Eldefrawy ‘835, ¶¶73, 77-80]).
As stated above, while Eldefrawy ‘835 discloses encrypting data elements within unstructured data containers and associating the encrypted data with metadata containing security policy information to determine user entitlement, Eldefrawy ‘835 does not explicitly disclose the limitations “cryptographically bound” and “… metadata that identifies an access controller …”.
Irwin ‘265, however, discloses:
… wherein the trusted data element is encapsulated and cryptographically bound to metadata … (a primary node configured to create a local encryption key to cryptographically bind metadata labels to data messages [Irwin ‘265, ¶¶6-7, 10, 12])
… cryptographically bind the encrypted data element to metadata … (the security metadata is obtained and then cryptographically bound to the message using a local encryption key [Irwin ‘265, ¶¶6, 10, 12, 35])
… wherein the encrypted data element and the metadata are cryptographically bound using data encryption keys … (the security metadata for the source node is obtained and then cryptographically bound to the message using a local encryption key, where the message is later decoded using the local encryption key [Irwin ‘265, ¶¶6-7, 10, 12, 35]).
Eldefrawy ‘835 and Irwin ‘265 are analogous art because they are from the same field of endeavor, namely that of protecting data through encryption and associating security metadata with data. For the reasons stated in claim 1, prior to the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art, having the teachings of Eldefrawy ‘835 and Irwin ‘265 before them, to modify the method in Eldefrawy ‘835 to include the teachings of Irwin ‘265.
As stated above, Eldefrawy ‘835 in view of Irwin ‘265 does not explicitly disclose the limitation “… metadata that identifies an access controller …”.
Liu ‘025, however, discloses:
… metadata that identifies an access controller (metadata received with protected media content includes a URL of a license server that acts as an access controller, where the license server is identified through the URL included in the metadata and determines whether access to the protected content is authorized [Liu ‘025, ¶¶27, 30, 33]) …
Eldefrawy ‘835 (modified by Irwin ‘265) and Liu ‘025 are analogous art because they are from the same field of endeavor, namely that of protecting data through encryption and controlling access to protected content. For the reasons stated in claim 1, prior to the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art, having the teachings of Eldefrawy ‘835 (modified by Irwin ‘265) and Liu ‘025 before them, to modify the method in Eldefrawy ‘835 (modified by Irwin ‘265) to include the teachings of Liu ‘025.
As per claims 16-18: Claims 16-18 define a computer system that recites substantially similar subject matter as the method of claims 2-4, respectively. Specifically, claims 16-18 are directed to a computer system comprising one or more computer processors, one or more computer-readable storage media, and program instructions stored on the computer-readable storage media for execution by at least one of the one or more processors, the program instructions comprising instructions to perform the computer-implemented method of claims 2-4, respectively. Thus, the rejection of claims 2-4 is equally applicable to claims 16-18, respectively.
As per claim 20: Eldefrawy ‘835 in view of Irwin ‘265, and further in view of Liu ‘025 discloses all limitations of claims 15-16, as stated above, from which claim 20 is dependent upon. Furthermore, Eldefrawy ‘835 discloses:
further comprising instructions to (in response to determining that the user’s key attributes satisfy the security policy, allowing access to the data by decrypting the data subgroups for the authorized user [Eldefrawy ‘835, ¶¶22-23, 102-106]).
As stated above, Eldefrawy ‘835 does not explicitly disclose the limitation “… notify an external system to allow access …”.
Irwin ‘265, however, discloses:
... notify an external system to allow access to the data element ... (in response to determining that the external interface security metadata and source security metadata are compatible, the message is sent to the external interface, thereby notifying the external system to allow access [Irwin ‘265, ¶¶31-32, 34])
Eldefrawy ‘835 (modified by Liu ‘025) and Irwin ‘265 are analogous art because they are from the same field of endeavor, namely that of protecting data through encryption and controlling access based on security metadata. Prior to the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art, having the teachings of Eldefrawy ‘835 (modified by Liu ‘025) and Irwin ‘265 before them, to modify the method in Eldefrawy ‘835 (modified by Liu ‘025) to include the teachings of Irwin ‘265, namely to implement the access control system of Eldefrawy ‘835 to notify an external system or interface when access is determined to be acceptable, as disclosed in Irwin ‘265. A motivation for doing so would be to enable the protected data elements to be accessed through external systems or interfaces while maintaining consistent access control enforcement across distributed system components (see Irwin ‘265, ¶¶6-7, 32).
Claims 7, 14, and 21 are rejected under 35 U.S.C. 103 as being unpatentable over Eldefrawy ‘835, in view of Irwin ‘265, and further in view of Liu ‘025, and further in view of Indukuri et al., US 2019/0266347 A1 (hereinafter, “Indukuri ‘347”).
As per claim 7: Eldefrawy ‘835 in view of Irwin ‘265, and further in view of Liu ‘025 discloses all limitations of claim 1, as stated above, from which claim 7 is dependent upon. Furthermore, Eldefrawy ‘835 discloses:
further comprising: determining that an access attempt to the unstructured dataset is not acceptable according to access control information (the decryption service determines whether the user’s decryption keys satisfy the security policy assigned to the encrypted data subgroups, where decryption is possible only when the key attributes satisfy the security policy, i.e., the access control information; if the user’s decryption keys do not satisfy the security policy, the decryption service outputs an error and the data remains encrypted [Eldefrawy ‘835, ¶¶22-23, 31, 36-37, 42, 102-105]); and
wherein the data encryption keys are user defined (users select document fields to encrypt and specify decryption policy, i.e., which attributes should be used for each field, where encryption keys are generated for each user-specified attribute; accordingly, the encryption keys are user defined in the sense that they are determined based on user-specified attributes and policies [Eldefrawy ‘835, ¶¶48, 66, 91]).
As stated above, Eldefrawy ‘835 in view of Irwin ‘265, and further in view of Liu ‘025 does not explicitly disclose the limitation “dynamically updating a policy to revoke user access to the unstructured dataset in response to determining that the access attempt is not acceptable”.
Indukuri ‘347, however, discloses:
… dynamically updating a policy to revoke user access to the unstructured dataset in response to determining that the access attempt is not acceptable (a data anchor system in which protected data is encrypted using a data key, where an encrypted data key is stored in metadata of the protected data, and where an access control layer checks the metadata for an access context before obtaining the key required to decrypt the protected data [Indukuri ‘347, ¶¶14, 73, 107]; access to the protected data is revoked when a user attempts to access the data outside of specified areas, i.e., when the access attempt does not satisfy the governing access control criteria [Indukuri ‘347, ¶93]; access is revoked whenever the applicable boundary is violated, even where the violation is discovered after the fact, and access to the sensitive data is removed if the security rules are broken at any point in time, where the system dynamically combines rule-based access and revocation across time rather than determining access only at the instance of authentication [Indukuri ‘347, ¶¶44, 59]; the system determines whether a requesting user device has exceeded an access control criteria threshold and, in response to the threshold being exceeded, adjusts the terms upon which encryption keys are supplied to the user device, including by adjusting the allowed data quota or throughput downward [Indukuri ‘347, ¶¶17, 26, 53, 65, 74-75]; the resulting operation is a dynamic revocation by which the state of a user is toggled between accessible and revoked [Indukuri ‘347, ¶120])
Eldefrawy ‘835 (modified by Irwin ‘265 and Liu ‘025) and Indukuri ‘347 are analogous art because they are from the same field of endeavor, namely that of protecting sensitive data through encryption and controlling access to the protected data using access control information associated with the data as metadata. Prior to the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art, having the teachings of Eldefrawy ‘835 (modified by Irwin ‘265 and Liu ‘025) and Indukuri ‘347 before them, to modify the method in Eldefrawy ‘835 (modified by Irwin ‘265 and Liu ‘025) to include the teachings of Indukuri ‘347, namely to implement the access control determination of Eldefrawy ‘835, in which the decryption service determines whether a user’s key attributes satisfy the security policy assigned to the encrypted data subgroups, such that a determination that the access attempt does not satisfy the governing access control criteria causes the applicable policy to be dynamically updated to revoke that user’s access to the protected data, as disclosed in Indukuri ‘347. A motivation for doing so would be to prevent a user who has been determined to fail the governing access control criteria from continuing to attempt access to the protected data, and to remove access to sensitive data at any point in time at which the security rules are broken, rather than determining access solely at the instance of authentication (see Indukuri ‘347, ¶¶44, 59, 63, 120).
As per claim 14: Claim 14 defines a computer program product that recites substantially similar subject matter as the method of claim 7. Specifically, claim 14 is directed to a computer program product comprising one or more computer readable storage media and program instructions stored on the one or more computer readable storage media, the program instructions comprising instructions to perform the computer-implemented method of claim 7. Thus, the rejection of claim 7 is equally applicable to claim 14.
As per claim 21: Eldefrawy ‘835 in view of Irwin ‘265, and further in view of Liu ‘025 discloses all limitations of claim 15, as stated above, from which claim 21 is dependent upon. Furthermore, Eldefrawy ‘835 discloses:
further comprising instructions to: determine that an access attempt to the unstructured dataset is not acceptable according to access control information (the decryption service determines whether the user’s decryption keys satisfy the security policy assigned to the encrypted data subgroups, where decryption is possible only when the key attributes satisfy the security policy, i.e., the access control information; if the user’s decryption keys do not satisfy the security policy, the decryption service outputs an error and the data remains encrypted [Eldefrawy ‘835, ¶¶22-23, 31, 36-37, 42, 102-105]);
(a decryption service manages access to the individual data subgroups within the unstructured data container by determining whether the requesting user’s key attributes satisfy the security policy assigned to those data subgroups [Eldefrawy ‘835, ¶¶22-23, 102-105]); and
manage the access to the individual data elements by utilizing the controller (a decryption service receives a call from a user device together with the secret key associated with the requesting user, determines whether the user’s key attributes satisfy the security policy assigned to the individual data subgroups within the unstructured data container, and selectively decrypts those individual data subgroups for which the security policy is satisfied [Eldefrawy ‘835, ¶¶22-23, 102-105]).
As stated above, Eldefrawy ‘835 does not explicitly disclose the limitations “dynamically update a policy to revoke user access to the unstructured dataset in response to determining that the access attempt is not acceptable” and “identify a controller to manage access to individual data elements within the unstructured dataset”.
Liu ‘025, however, discloses:
… ;
identify a controller to manage access to individual data elements within the unstructured dataset … (metadata received with protected media content includes a URL of a license server that acts as an access controller, where the license server is identified through the URL included in the metadata and determines whether access to the protected content is authorized [Liu ‘025, ¶¶27, 30, 33])
Eldefrawy ‘835 (modified by Irwin ‘265) and Liu ‘025 are analogous art because they are from the same field of endeavor, namely that of protecting data through encryption and controlling access to protected content. For the reasons stated in claim 1, prior to the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art, having the teachings of Eldefrawy ‘835 (modified by Irwin ‘265) and Liu ‘025 before them, to modify the method in Eldefrawy ‘835 (modified by Irwin ‘265) to include the teachings of Liu ‘025.
As stated above, Eldefrawy ‘835 in view of Irwin ‘265, and further in view of Liu ‘025 does not explicitly disclose the limitation “dynamically update a policy to revoke user access to the unstructured dataset in response to determining that the access attempt is not acceptable”.
Indukuri ‘347, however, discloses:
… dynamically update a policy to revoke user access to the unstructured dataset in response to determining that the access attempt is not acceptable (a data anchor system in which protected data is encrypted using a data key, where an encrypted data key is stored in metadata of the protected data, and where an access control layer checks the metadata for an access context before obtaining the key required to decrypt the protected data [Indukuri ‘347, ¶¶14, 73, 107]; access to the protected data is revoked when a user attempts to access the data outside of specified areas, i.e., when the access attempt does not satisfy the governing access control criteria [Indukuri ‘347, ¶93]; access is revoked whenever the applicable boundary is violated, even where the violation is discovered after the fact, and access to the sensitive data is removed if the security rules are broken at any point in time, where the system dynamically combines rule-based access and revocation across time rather than determining access only at the instance of authentication [Indukuri ‘347, ¶¶44, 59]; the system determines whether a requesting user device has exceeded an access control criteria threshold and, in response to the threshold being exceeded, adjusts the terms upon which encryption keys are supplied to the user device [Indukuri ‘347, ¶¶17, 26, 53, 65, 74-75]; the resulting operation is a dynamic revocation by which the state of a user is toggled between accessible and revoked [Indukuri ‘347, ¶120]) …
Eldefrawy ‘835 (modified by Irwin ‘265 and Liu ‘025) and Indukuri ‘347 are analogous art because they are from the same field of endeavor, namely that of protecting sensitive data through encryption and controlling access to the protected data using access control information associated with the data as metadata. For the reasons stated in claim 7, prior to the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art, having the teachings of Eldefrawy ‘835 (modified by Irwin ‘265 and Liu ‘025) and Indukuri ‘347 before them, to modify the method in Eldefrawy ‘835 (modified by Irwin ‘265 and Liu ‘025) to include the teachings of Indukuri ‘347.
Claim 12 is rejected under 35 U.S.C. 103 as being unpatentable over Eldefrawy ‘835, in view of Irwin ‘265, and further in view of Liu ‘025, and further in view of Madden, US 2021/0258167 A1 (hereinafter, “Madden ‘167”).
As per claim 12: Eldefrawy ‘835 in view of Irwin ‘265, and further in view of Liu ‘025 discloses all limitations of claim 8, as stated above, from which claim 12 is dependent upon. Furthermore, Eldefrawy ‘835 discloses:
wherein the encrypted data element and the metadata are (the data subgroups are encrypted using data encryption keys, such as AES keys or RSA keys, and are associated with metadata including encryption policy information [Eldefrawy ‘835, ¶¶55, 67-74, 82]).
As stated above, Eldefrawy ‘835 does not explicitly disclose the limitations “cryptographically bound” and “data encryption keys that are stored in keystores and are protected internally in a key hierarchy”.
Irwin ‘265, however, discloses:
... wherein the encrypted data element and the metadata are cryptographically bound using data encryption keys ... (a primary node configured to create a local encryption key to cryptographically bind metadata labels to data messages [Irwin ‘265, ¶¶6-7, 10, 12, 35])
Eldefrawy ‘835 (modified by Liu ‘025) and Irwin ‘265 are analogous art because they are from the same field of endeavor, namely that of protecting data through encryption and associating security metadata with data. For the reasons stated in claim 8, prior to the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art, having the teachings of Eldefrawy ‘835 (modified by Liu ‘025) and Irwin ‘265 before them, to modify the method in Eldefrawy ‘835 (modified by Liu ‘025) to include the teachings of Irwin ‘265.
As stated above, Eldefrawy ‘835 in view of Irwin ‘265 does not explicitly disclose the limitation “data encryption keys that are stored in keystores and are protected internally in a key hierarchy”.
Madden ‘167, however, discloses:
... data encryption keys that are stored in keystores and are protected internally in a key hierarchy (an untrusted keystore stores keys in keyblocks; the keys are protected internally in a key hierarchy with a root key block protection key (KBPK) having one or more class KBPKs, and each class KBPK having one or more keyblock KBPKs, such that keys at each level of the hierarchy are protected by encryption using keys from the level above [Madden ‘167, ¶¶39-41, 46, 49, 54])
Eldefrawy ‘835 (modified by Irwin ‘265 and Liu ‘025) and Madden ‘167 are analogous art because they are from the same field of endeavor, namely that of secure key management for cryptographic operations. Prior to the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art, having the teachings of Eldefrawy ‘835 (modified by Irwin ‘265 and Liu ‘025) and Madden ‘167 before them, to modify the method in Eldefrawy ‘835 (modified by Irwin ‘265 and Liu ‘025) to include the teachings of Madden ‘167, namely to store the data encryption keys in keystores and to protect the keys internally using a key hierarchy, as disclosed in Madden ‘167. A motivation for doing so would be to provide secure key management with limited secure storage requirements, where the hierarchical structure enables verification that no keys have been removed or added while minimizing the amount of secure storage needed (see Madden ‘167, ¶¶2-3, 61).
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Wong et al., US 20160148021 A1: A method for sharing encrypted data and encryption keys through a system comprised of the following data types, but not limited to a; 1) Record and its encryption key, 2) RecordSet and its encryption key, and 3) Entity and its encryption key. A Record is encrypted using an encryption key.
Feng et al., US 20170104762 A1: parse a file into a plurality of nodes. The computing device may associate, based on the parsing, at least a first encryption policy with a first node of the plurality of nodes. The computing device may associate, based on the parsing, at least a second encryption policy with a second node of the plurality of nodes.
Negrea et al., US 20150096053 A1: a method and corresponding content protection server for managing access to electronic content comprise retrieving access policies, or permissions, associated with a content item from a corresponding content sharing application, or rights issuer.
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to ALAN L KONG whose telephone number is (571)272-2646. The examiner can normally be reached Monday-Friday 8:00am-4:30pm EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, JUNG (JAY) KIM can be reached on (571)272-3804. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/ALAN L KONG/Examiner, Art Unit 2494
/KAVEH ABRISHAMKAR/Primary Examiner, Art Unit 2494