DETAILED ACTION
This is a Supplemental non-final Office Action to correct the PTOL-326 form in the prior non-final Office Action mailed on 09/09/2026.
Examiner’s Note: The PTOL-326 form “Disposition of Claims*” checkboxes 5) and 7) have been corrected to list the proper pending claims and rejected claims.
Claims 1-7, 9, 10, 12-18, and 20-23 are currently pending and have been considered as follows.
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicants’ submission filed on 06/09/2026 has been entered.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Response to Arguments
The nonstatutory obviousness-type double patenting rejection of Claims 1-10 and 12-20 is withdrawn in view of the terminal disclaimer filed on 05/11/2026.
Applicants’ arguments on pages 9 and 10 of the remarks filed on 06/09/2026 have been fully considered but are moot because the amendment necessitates new ground(s) of rejection where applicants’ arguments do not apply to the updated reference(s) for any teaching or matter specifically challenged in the argument.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention.
Claims 1-5, 7, 9, 10, 12-18, 20, 22, and 23 are rejected under 35 U.S.C. 103 as being unpatentable over CARD et al. (US 20150347751 A1, IDS submitted 08/28/2024, hereinafter Card) in view of Angus et al. (US 20160099969 A1, hereinafter Angus), and further in view of Tschiegg et al. (US 20030160818 A1, hereinafter Tschiegg).
As to Amended Claim 1:
Card discloses a system (e.g. Card “Systems and methods are provided which enable client environments, such as corporate and government enterprises, to adopt an integrated, strategic approach to governance, risk and compliance… An advanced security information and event management system, also referred to as an information assurance portal (IAP)” [Abstract]), comprising:
one or more processors (e.g. Card processor [0069]); and
computer-readable media storing computer-executable instructions (e.g. Card “Computer storage media may include volatile and non-volatile, removable and non-removable media implemented in any method or technology for storage of information, such as computer readable instructions, data structures, program modules” [0155]) that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:
generating an executable command to generate a ticket associated with the asset, the executable command including at least a portion of the risk data (e.g. Card “The leaf node 52, when located within the client environment 10 sends event objects in a secure manner over the internet 18 or other available communication connection to the hub 40. The hub 40 performs authentication and reporting services and communicates with a ticketing component 42 to identify, track, and resolve security threats, initiate remediation of a security breach, communicate with IT agents within the client environment 10, etc. The ticketing component 42 enables security analysts to be engaged in the monitoring and remediation and may also include automated processes, e.g., for communicating with the client environment 10 to identify threats, escalate threats, etc” [0060]; “At 108 the leaf node 52 detects a notification of a threat, generated in the processing performed at 106, and sends the notification to the hub 40 at 110. The hub 40 receives the notification at 112 and acknowledges receipt of the notification” [0070]);
providing the executable command to a second device (e.g. Card “The hub 40 may then authenticate the message at 114 and send the notification for ticketing at 116”” [0070]);
receiving, from the second device and in response to providing the executable command to the second device, a first ticket associated with the asset, the first ticket including a unique identifier (e.g. Card “The ticketing component 42 creates a ticket associated with the notification at 120 and enables the potential threat to be monitored at 122, e.g., by enabling a security analyst to access and view the ticket and/or be assigned to a ticket” [0070]; [0099] TABLE 5 “Message ID 16 UUID that uniquely identifies this particular message. Each message must have a UUID”);
But Card does not specifically disclose:
determining, based on a message from a first device, risk data identifying a software asset that will be out of compliance with a predetermined requirement within a period of time;
wherein determining the risk data includes accessing content via a hyperlink in a text of the message; and
outputting the unique identifier.
However, the analogous art Angus does disclose determining, based on a message from a first device, risk data identifying a software asset that will be out of compliance with a predetermined requirement within a period of time and outputting the unique identifier (e.g. Angus “receiving an authentication certificate in response to the compliance authenticator verifying the configuration information complies with the policy. The authentication certificate expires after a predetermined period of time” [Abstract]; “collects configuration data from the electronic device 102, which may include software… configuration data. In some embodiments, the software configuration data may include operating system information, such as the type of operating system, the version of the operating system, network settings for the operating system, security settings for the operating system, and/or the like. The software configuration data may also include application configuration data for an electronic device 102, such as which applications are installed on the device” [0035]; “compliance authenticator verifies that the configuration information complies with the policy, such as by comparing the configuration information with the requirements of the policy” [0038]; “verification actions may comprise determining applications installed on the electronic device… determine whether the configuration information is in compliance with the specifications of a policy” [0039]; [0040]; “the notification module 306 may send compliance check notifications… the notification module 306 presents a message that the authentication certificate… is about to expire, such that a user may prepare or perform an appropriate compliance action in order to receive a new authentication certificate, a new key, and/or extend the lifetime of the current authentication certificate” [0064]; “The access module 308 is configured to present the authentication certificate, including the public key for the authentication certificate, for the electronic device 102 to a secure resource of a computing system” [0065]; “The certificate module 206 is configured to receive an authentication certificate, and... a unique identifier” [0040]; [0050]; [0052]). Furthermore, the analogous art Tschiegg does disclose wherein determining the risk data includes accessing content via a hyperlink in a text of the message (e.g. Tschiegg “email is generated in response to updates to the risk management information. For example the database or an email notification application may generate the email in response to authorized updates to a segment of risk management information. The email is addressed to a user at an access terminal that has the appropriate authorizations. The email may contain a hyperlink to the updated information and/or to a document loaded in association with the segment” [0012]; “generating email indicating, to authorized users, updates to risk management information” [0016]; “The email may include an Internet link to the augmented information within the one segment. The buffer may automatically check with the database to ensure that a user accessing the link has authorized access to the augmented information. The system may include a graphics interface to collate risk management information from the database into a graphical display for an access computer coupled in network with the database” [0023]; “may be accessed immediately by interactively clicking the hyperlink via computer 14 receiving the email” [0039]). Card, Angus, and Tschiegg are analogous art because they are from the same field of endeavor in risk assessment.
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art, having the teachings of Card, Angus, and Tschiegg before him or her, to modify the disclosure of Card with the teachings of Angus and Tschiegg to include determining, based on a message from a first device, risk data identifying a software asset that will be out of compliance with a predetermined requirement within a period of time, wherein determining the risk data includes accessing content via a hyperlink in a text of the message, and outputting the unique identifier as claimed. First suggestion/motivation for doing so would have been in response to the problems and needs of authenticating devices by enforcing policy compliance on the devices (Angus [0004]). Second suggestion/motivation for doing so would have been to provide a seamless interface for real-time manipulation and management of risk management information over a network (Tschiegg [0002]). Therefore, it would have been obvious to combine Card, Angus, and Tschiegg to obtain the invention as specified in the instant claim(s).
As to Claim 2:
Card in view of Angus and Tschiegg discloses the system of claim 1, (e.g. Card “an information assurance portal (IAP), is described, which enables client customers to select various services such as threat and vulnerability management, asset classification and tracking, and business threat and risk assessments through a software-as-a-service portal” [Abstract]) wherein the unique identifier is output via a display operably connected to the one or more processors (e.g. Card “enabling a security analyst to access and view the ticket and/or be assigned to a ticket” [0070]; Angus FIG. 1 computer(s) 102 displays). The Examiner supplies the same rationale for the combination of references Card, Angus, and Tschiegg as in Claim 1 above.
As to Claim 3:
Card in view of Angus and Tschiegg discloses the system of claim 1, the operations further comprising: determining, based at least in part on the risk data, a user associated with the asset (e.g. Card “At this stage, event objects will be “enriched” with additional information that can be used by TRCE 226 later. This can include for example asset information, geo-IP location information, or identity information (the name of the user using the technology asset that generated the event)” [0076]); and transmitting at least one of the unique identifier or the first ticket to a third computing device associated with the user (e.g. Card “enabling a security analyst to access and view the ticket and/or be assigned to a ticket” [0070]; Angus FIG. 1 computer(s) 102 displays). The Examiner supplies the same rationale for the combination of references Card, Angus, and Tschiegg as in Claim 1 above.
As to Claim 4:
Card in view of Angus and Tschiegg discloses the system of claim 3, the operations further comprising: (e.g. Card “At this stage, event objects will be “enriched” with additional information that can be used by TRCE 226 later. This can include for example asset information, geo-IP location information, or identity information (the name of the user using the technology asset that generated the event)” [0076]) determining, based at least in part on the first ticket, a mitigation task that will bring the asset into compliance with the predetermined requirement (e.g. Card “the ticket is reviewed and the threat monitored. In this example it is assumed that the ticket status is moved to an escalation at 352 to highlight the potential vulnerability. For example, the analyst may review alerts, and if they are determined to be valid they are escalated to the client (client is notified of an incident taking place on their network). At this point, the analyst may follow up with the support client at 354, or an email or other communication may be sent automatically. The analyst and/or system may then wait for client feedback or a response confirming that the threat has been addresses, the system shut down, or other remediation is in progress” [0092]; “to ensure compliance with various industry regulation” [0051]); and causing a display of the third computing device to display the mitigation task in association with the unique identifier or the first ticket (e.g. Angus “the notification module 306 presents a message that the authentication certificate is expired, has expired, or is about to expire, such that a user may prepare or perform an appropriate compliance action in order to receive a new authentication certificate, a new key, and/or extend the lifetime of the current authentication certificate” [0064]; “a compliance notification that it is time to perform a new compliance action” [0079]; [0099] TABLE 5 “Message ID 16 UUID that uniquely identifies this particular message. Each message must have a UUID”). The Examiner supplies the same rationale for the combination of references Card, Angus, and Tschiegg as in Claim 1 above.
As to Claim 5:
Card in view of Angus and Tschiegg discloses the system of claim 4, the operations further comprising: receiving, from the third computing device, an indication that the mitigation task has been completed (e.g. Card “The analyst and/or system may then wait for client feedback or a response confirming that the threat has been addresses, the system shut down, or other remediation is in progress” [0092]); and providing the indication to the second device (e.g. Card feedback or a response confirming that the threat has been addressed [0092]).
As to Claim 7:
Card in view of Angus and Tschiegg discloses the system of claim 1, wherein the message is a first message, the operations further comprising:
determining, based on a second message from a third device, additional risk data indicating that a hardware asset will be out of compliance with a hardware requirement (e.g. Angus “the configuration information comprises… information associated with a hardware configuration of the electronic device” [0008]; “the verification module 204 collects configuration data from the electronic device 102, which may include… hardware configuration data” [0025]; “Hardware configuration data may include information regarding network interface controllers (NICs) that are installed on the device, processor information, memory information, information about physical access ports” [0035]), wherein the additional risk data is determined based at least in part on an additional document included in the second message (e.g. Tschiegg “The email may contain a hyperlink to the updated information and/or to a document loaded in association with the segment” [0012]). The Examiner supplies the same rationale for the combination of references Card, Angus, and Tschiegg as in Claim 1 above.
As to Amended Claim 9:
Card in view of Angus and Tschiegg discloses the system of claim 1, wherein the portion of the risk data comprises at least one of: an identifier associated with a user (e.g. Card “At this stage, event objects will be “enriched” with additional information that can be used by TRCE 226 later. This can include for example asset information, geo-IP location information, or identity information (the name of the user using the technology asset that generated the event)” [0076]; “The user object contains information relevant to the individual (e.g., name, contact information, etc.)” [0093]; [0097]); an indication that a type of the asset comprises a software asset; or a policy or a regulation associated with the predetermined requirement.
As to Amended Claim 10:
Card discloses a method (e.g. Card “methods are provided which enable client environments, such as corporate and government enterprises, to adopt an integrated, strategic approach to governance, risk and compliance… An advanced security information and event management system, also referred to as an information assurance portal (IAP)” [Abstract]), comprising:
generating an executable command to generate a ticket associated with the asset, the executable command including at least a portion of the risk data (e.g. Card “The leaf node 52, when located within the client environment 10 sends event objects in a secure manner over the internet 18 or other available communication connection to the hub 40. The hub 40 performs authentication and reporting services and communicates with a ticketing component 42 to identify, track, and resolve security threats, initiate remediation of a security breach, communicate with IT agents within the client environment 10, etc. The ticketing component 42 enables security analysts to be engaged in the monitoring and remediation and may also include automated processes, e.g., for communicating with the client environment 10 to identify threats, escalate threats, etc” [0060]; “At 108 the leaf node 52 detects a notification of a threat, generated in the processing performed at 106, and sends the notification to the hub 40 at 110. The hub 40 receives the notification at 112 and acknowledges receipt of the notification” [0070]);
providing the executable command to a second device (e.g. Card “The hub 40 may then authenticate the message at 114 and send the notification for ticketing at 116”” [0070]);
receiving, from the second device and in response to providing the executable command to the second device, a first ticket associated with the asset, the first ticket including a unique identifier (e.g. Card “The ticketing component 42 creates a ticket associated with the notification at 120 and enables the potential threat to be monitored at 122, e.g., by enabling a security analyst to access and view the ticket and/or be assigned to a ticket” [0070]; [0099] TABLE 5 “Message ID 16 UUID that uniquely identifies this particular message. Each message must have a UUID”);
But Card does not specifically disclose:
determining, based on a message from a first device, risk data identifying a software asset that will be out of compliance with a predetermined requirement within a period of time;
wherein determining the risk data includes accessing content via a hyperlink in a text of the message; and
outputting the unique identifier.
However, the analogous art Angus does disclose determining, based on a message from a first device, risk data identifying a software asset that will be out of compliance with a predetermined requirement within a period of time and outputting the unique identifier (e.g. Angus “receiving an authentication certificate in response to the compliance authenticator verifying the configuration information complies with the policy. The authentication certificate expires after a predetermined period of time” [Abstract]; “collects configuration data from the electronic device 102, which may include software… configuration data. In some embodiments, the software configuration data may include operating system information, such as the type of operating system, the version of the operating system, network settings for the operating system, security settings for the operating system, and/or the like. The software configuration data may also include application configuration data for an electronic device 102, such as which applications are installed on the device” [0035]; “compliance authenticator verifies that the configuration information complies with the policy, such as by comparing the configuration information with the requirements of the policy” [0038]; “verification actions may comprise determining applications installed on the electronic device… determine whether the configuration information is in compliance with the specifications of a policy” [0039]; [0040]; “the notification module 306 may send compliance check notifications… the notification module 306 presents a message that the authentication certificate… is about to expire, such that a user may prepare or perform an appropriate compliance action in order to receive a new authentication certificate, a new key, and/or extend the lifetime of the current authentication certificate” [0064]; “The access module 308 is configured to present the authentication certificate, including the public key for the authentication certificate, for the electronic device 102 to a secure resource of a computing system” [0065]; “The certificate module 206 is configured to receive an authentication certificate, and... a unique identifier” [0040]; [0050]; [0052]). Furthermore, the analogous art Tschiegg does disclose wherein determining the risk data includes accessing content via a hyperlink in a text of the message (e.g. Tschiegg “email is generated in response to updates to the risk management information. For example the database or an email notification application may generate the email in response to authorized updates to a segment of risk management information. The email is addressed to a user at an access terminal that has the appropriate authorizations. The email may contain a hyperlink to the updated information and/or to a document loaded in association with the segment” [0012]; “generating email indicating, to authorized users, updates to risk management information” [0016]; “The email may include an Internet link to the augmented information within the one segment. The buffer may automatically check with the database to ensure that a user accessing the link has authorized access to the augmented information. The system may include a graphics interface to collate risk management information from the database into a graphical display for an access computer coupled in network with the database” [0023]; “may be accessed immediately by interactively clicking the hyperlink via computer 14 receiving the email” [0039]). Card, Angus, and Tschiegg are analogous art because they are from the same field of endeavor in risk assessment.
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art, having the teachings of Card, Angus, and Tschiegg before him or her, to modify the disclosure of Card with the teachings of Angus and Tschiegg to include determining, based on a message from a first device, risk data identifying a software asset that will be out of compliance with a predetermined requirement within a period of time, wherein determining the risk data includes accessing content via a hyperlink in a text of the message, and outputting the unique identifier as claimed. First suggestion/motivation for doing so would have been in response to the problems and needs of authenticating devices by enforcing policy compliance on the devices (Angus [0004]). Second suggestion/motivation for doing so would have been to provide a seamless interface for real-time manipulation and management of risk management information over a network (Tschiegg [0002]). Therefore, it would have been obvious to combine Card, Angus, and Tschiegg to obtain the invention as specified in the instant claim(s).
As to Amended Claim 12:
Card in view of Angus and Tschiegg discloses the method of claim 10, wherein the portion of the risk data comprises at least one of: an identifier associated with a user (e.g. Card “At this stage, event objects will be “enriched” with additional information that can be used by TRCE 226 later. This can include for example asset information, geo-IP location information, or identity information (the name of the user using the technology asset that generated the event)” [0076]; “The user object contains information relevant to the individual (e.g., name, contact information, etc.)” [0093]; [0097]); an indication that a type of the asset corresponds to software; or a policy or a regulation associated with the risk data.
As to Claim 13:
Card in view of Angus and Tschiegg discloses the method of claim 10, further comprising: determining, based at least in part on the risk data, a user associated with the asset (e.g. Card “At this stage, event objects will be “enriched” with additional information that can be used by TRCE 226 later. This can include for example asset information, geo-IP location information, or identity information (the name of the user using the technology asset that generated the event)” [0076]); and transmitting at least one of the unique identifier or the first ticket to a third computing device associated with the user (e.g. Card “enabling a security analyst to access and view the ticket and/or be assigned to a ticket” [0070]; Angus FIG. 1 computer(s) 102 displays). The Examiner supplies the same rationale for the combination of references Card, Angus, and Tschiegg as in Claim 10 above.
As to Claim 14:
Card in view of Angus and Tschiegg discloses the method of claim 10, further comprising: determining, based at least in part on the risk data, a user associated with the asset (e.g. Card “At this stage, event objects will be “enriched” with additional information that can be used by TRCE 226 later. This can include for example asset information, geo-IP location information, or identity information (the name of the user using the technology asset that generated the event)” [0076]); determining, based at least in part on the first ticket, a mitigation task that will bring the asset into compliance with the predetermined requirement, the predetermined requirement comprising a policy or a regulation (e.g. Card “the ticket is reviewed and the threat monitored. In this example it is assumed that the ticket status is moved to an escalation at 352 to highlight the potential vulnerability. For example, the analyst may review alerts, and if they are determined to be valid they are escalated to the client (client is notified of an incident taking place on their network). At this point, the analyst may follow up with the support client at 354, or an email or other communication may be sent automatically. The analyst and/or system may then wait for client feedback or a response confirming that the threat has been addresses, the system shut down, or other remediation is in progress” [0092]; “to ensure compliance with various industry regulation” [0051]); and causing a display of a third device associated with the user to display the mitigation task (e.g. Angus “the notification module 306 presents a message that the authentication certificate is expired, has expired, or is about to expire, such that a user may prepare or perform an appropriate compliance action in order to receive a new authentication certificate, a new key, and/or extend the lifetime of the current authentication certificate” [0064]; “a compliance notification that it is time to perform a new compliance action” [0079]). The Examiner supplies the same rationale for the combination of references Card, Angus, and Tschiegg as in Claim 10 above.
As to Claim 15:
Card in view of Angus and Tschiegg discloses the method of claim 14, further comprising: receiving, from the third device, an indication that the mitigation task has been completed (e.g. Card “The analyst and/or system may then wait for client feedback or a response confirming that the threat has been addresses, the system shut down, or other remediation is in progress” [0092]); and sending the indication to the second device (e.g. Card feedback or a response confirming that the threat has been addressed [0092]).
As to Amended Claim 16:
Card discloses a method (e.g. Card “methods are provided which enable client environments, such as corporate and government enterprises, to adopt an integrated, strategic approach to governance, risk and compliance… An advanced security information and event management system, also referred to as an information assurance portal (IAP)” [Abstract]), comprising:
determining, by a processor, and based on a message from a first device received by an application (e.g. Card “an information assurance portal (IAP), is described, which enables client customers to select various services such as threat and vulnerability management, asset classification and tracking, and business threat and risk assessments through a software-as-a-service portal” [Abstract]; “The customer data 70 in this example is stored within the IAP 12 environment and a batch processor” [0069]), risk data associated with a software asset that is out of compliance with a predetermined requirement (e.g. Card “The IAP may also facilitate compliance by providing enhanced information security controls, online real-time information, and comprehensive reporting to ensure compliance with various industry regulations. The IAP can also enable improved operational efficiency by providing more effective management and monitoring of a security environment with real-time views of the efficiencies/inefficiencies of information security systems, allowing key stakeholders to identify where and how performance can be improved. Various other advantages include, without limitation, proactive management to improve processes for identifying and remediating technical vulnerabilities before they impact your business, cost savings to reduces costs (e.g. for staffing, training, maintenance, and infrastructure) associated with securing information assets, and enhanced security posture, which ensures proactive risk management and improves an organization's overall security posture by gaining a deeper knowledge of potential problems and allowing senior leadership to make decisions faster and more effectively” [0051]; “The leaf node 52, when located within the client environment 10 sends event objects in a secure manner over the internet 18 or other available communication connection to the hub 40. The hub 40 performs authentication and reporting services and communicates with a ticketing component 42 to identify, track, and resolve security threats, initiate remediation of a security breach, communicate with IT agents within the client environment 10, etc. The ticketing component 42 enables security analysts to be engaged in the monitoring and remediation and may also include automated processes, e.g., for communicating with the client environment 10 to identify threats, escalate threats, etc” [0060]; “At 108 the leaf node 52 detects a notification of a threat, generated in the processing performed at 106, and sends the notification to the hub 40 at 110. The hub 40 receives the notification at 112 and acknowledges receipt of the notification” [0070]);
generating, by the processor and based at least in part on receiving an input, an executable command to generate a ticket associated with the asset, the command including at least a portion of the risk data (e.g. Card “At 108 the leaf node 52 detects a notification of a threat, generated in the processing performed at 106, and sends the notification to the hub 40 at 110. The hub 40 receives the notification at 112 and acknowledges receipt of the notification. The hub 40 may then authenticate the message at 114 and send the notification for ticketing at 116. The ticketing component 42 creates a ticket associated with the notification at 120 and enables the potential threat to be monitored at 122, e.g., by enabling a security analyst to access and view the ticket and/or be assigned to a ticket. The hub 40 may also enable reporting at 118, the reporting including details of the notification received at 112” [0070]);
receiving, by the processor and from a second device and in response to sending the command to the second device, a first ticket associated with the asset, the first ticket including a unique identifier (e.g. Card “The ticketing component 42 creates a ticket associated with the notification at 120 and enables the potential threat to be monitored at 122, e.g., by enabling a security analyst to access and view the ticket and/or be assigned to a ticket” [0070]; “Message ID 16 UUID that uniquely identifies this particular message” [0099] Table 5);
But Card does not specifically disclose:
wherein determining the risk data includes accessing content via a hyperlink in a text of the message; and
outputting, by the processor and via the application, at least the unique identifier.
However, the analogous art Angus does disclose outputting, by the processor and via the application, at least the unique identifier (e.g. Angus “the notification module 306 may send compliance check notifications… the notification module 306 presents a message that the authentication certificate… is about to expire, such that a user may prepare or perform an appropriate compliance action in order to receive a new authentication certificate, a new key, and/or extend the lifetime of the current authentication certificate” [0064]; “The access module 308 is configured to present the authentication certificate, including the public key for the authentication certificate, for the electronic device 102 to a secure resource of a computing system” [0065]; “The certificate module 206 is configured to receive an authentication certificate, and... a unique identifier” [0040]; [0050]; [0052]; “Modules may also be implemented in software for execution by various types of processors” [0082]). Furthermore, the analogous art Tschiegg does disclose wherein determining the risk data includes accessing content via a hyperlink in a text of the message (e.g. Tschiegg “email is generated in response to updates to the risk management information. For example the database or an email notification application may generate the email in response to authorized updates to a segment of risk management information. The email is addressed to a user at an access terminal that has the appropriate authorizations. The email may contain a hyperlink to the updated information and/or to a document loaded in association with the segment” [0012]; “generating email indicating, to authorized users, updates to risk management information” [0016]; “The email may include an Internet link to the augmented information within the one segment. The buffer may automatically check with the database to ensure that a user accessing the link has authorized access to the augmented information. The system may include a graphics interface to collate risk management information from the database into a graphical display for an access computer coupled in network with the database” [0023]; “may be accessed immediately by interactively clicking the hyperlink via computer 14 receiving the email” [0039]). Card, Angus, and Tschiegg are analogous art because they are from the same field of endeavor in risk assessment.
It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art, having the teachings of Card, Angus, and Tschiegg before him or her, to modify the disclosure of Card with the teachings of Angus and Tschiegg to include wherein determining the risk data includes accessing content via a hyperlink in a text of the message, and outputting, by the processor and via the application, at least the unique identifier as claimed. First suggestion/motivation for doing so would have been in response to the problems and needs of authenticating devices by enforcing policy compliance on the devices (Angus [0004]). Second suggestion/motivation for doing so would have been to provide a seamless interface for real-time manipulation and management of risk management information over a network (Tschiegg [0002]). Therefore, it would have been obvious to combine Card, Angus, and Tschiegg to obtain the invention as specified in the instant claim(s).
As to Claim 17:
Card in view of Angus and Tschiegg discloses the method of claim 16, wherein the application comprises an information technology asset management application (e.g. Card “an information assurance portal (IAP), is described, which enables client customers to select various services such as threat and vulnerability management, asset classification and tracking, and business threat and risk assessments through a software-as-a-service portal” [Abstract]) and wherein the unique identifier is output via a display of the first device (e.g. Card “enabling a security analyst to access and view the ticket and/or be assigned to a ticket” [0070]; Angus FIG. 1 computer(s) 102 displays). The Examiner supplies the same rationale for the combination of references Card, Angus, and Tschiegg as in Claim 16 above.
As to Claim 18:
Card in view of Angus and Tschiegg discloses the method of claim 16, wherein the message is a first message, the method further comprising:
determining, by the processor and based on a second message from an additional device, additional risk data indicating that a hardware asset will be out of compliance (e.g. Angus “the configuration information comprises… information associated with a hardware configuration of the electronic device” [0008]; “the verification module 204 collects configuration data from the electronic device 102, which may include… hardware configuration data” [0025]; “Hardware configuration data may include information regarding network interface controllers (NICs) that are installed on the device, processor information, memory information, information about physical access ports” [0035]), wherein the additional risk data is determined based at least in part on an additional document included in the second message (e.g. Tschiegg “The email may contain a hyperlink to the updated information and/or to a document loaded in association with the segment” [0012]). The Examiner supplies the same rationale for the combination of references Card, Angus, and Tschiegg as in Claim 16 above.
As to Amended Claim 20:
Card in view of Angus and Tschiegg discloses the method of claim 16, wherein the risk data: is further determined based at least in part on a document included in the message (e.g. Tschiegg “The email may contain a hyperlink to the updated information and/or to a document loaded in association with the segment” [0012]), and comprises one or more of an asset identifier, an asset user identifier associated with a user (e.g. Card “At this stage, event objects will be “enriched” with additional information that can be used by TRCE 226 later. This can include for example asset information, geo-IP location information, or identity information (the name of the user using the technology asset that generated the event)” [0076]; “The user object contains information relevant to the individual (e.g., name, contact information, etc.)” [0093]; [0097]), or a deadline associated with compliance. The Examiner supplies the same rationale for the combination of references Card, Angus, and Tschiegg as in Claim 16 above.
As to Claim 22:
Card in view of Angus and Tschiegg discloses the system of claim 1, wherein the risk data: comprises one or more of:
an asset identifier, a user identifier associated with a user responsible for the asset, a reason associated with the determination that the asset will be out of compliance (e.g. Angus “presents a message that the authentication certificate is… about to expire, such that a user may prepare or perform an appropriate compliance action” [0064]), or a deadline associated with compliance (e.g. Angus “the expiration date” [0026]), and is further determined based at least in part on a document in the message (e.g. Tschiegg “The email may contain a hyperlink to the updated information and/or to a document loaded in association with the segment” [0012]). The Examiner supplies the same rationale for the combination of references Card, Angus, and Tschiegg as in Claim 1 above.
As to Claim 23:
Card in view of Angus and Tschiegg discloses the system of claim 1, the operations further comprising: updating a report to include an identifier (e.g. Angus “a unique identifier” [0040]) of the software asset and the risk data; and presenting, on a user interface associated with an additional device, the report (e.g. Tschiegg “data is updated in database 20 for transmission to remotely located persons (e.g., at terminals 24) who may review the report” [0038]; “Reports are sent to database 108 for direct update by messenger 110, an Internet e-mail software (client/server) application that segregates the report into data components for storage into interim database 111; database 111 stores data results of risk assessments” [0083]; “authorized users who (a) have access to view that document and (b) have chosen to subscribe to e-mail notification that they have new information to view on the website” [0084]; “Changes to specific data sets 128, namely the comments, status, intent, target dates, etc., are ported directly back to database 111 for update and future access” [0086]). The Examiner supplies the same rationale for the combination of references Card, Angus, and Tschiegg as in Claim 1 above.
Allowable Subject Matter
Claims 6 and 21 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicants’ disclosure.
HOOVER et al. (US 20160155069 A1)
Nicodemus et al. (US 20170201545 A1)
White (US 20190182289 A1)
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Kenneth Chang whose telephone number is (571)270-7530. The examiner can normally be reached Monday - Friday 9:30am-5:30pm EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Taghi Arani can be reached at 571-272-3787. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/KENNETH W CHANG/Primary Examiner, Art Unit 2438
PNG
media_image1.png
35
280
media_image1.png
Greyscale
09.08.2026