DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Amendment
The amendment filed 04/28/2026 has been fully considered and entered into record. Claims 1-20 remain pending in the application. Claims 1, 2, 9, 10, 17 and 18 have been amended.
Response to Arguments
Applicant's arguments with respect to claims 1-20 have been considered but are moot because the present rejection constitutes a new ground of rejection. The present rejection no longer relies on Chintalapati for the disputed limitations, but instead relies on Trenholm and Kras, together with Badana and Dhillon, for teachings set forth in the rejection. Accordingly, Applicant’s arguments directed to the prior combination are not persuasive.
Applicant's amendment has overcome the rejection under 35 U.S.C 112(b). Accordingly, the rejection of claims 1, 9 and 17 under 35 U.S.C 112(b) (or pre-AIA 35 U.S.C. 112, second paragraph) is withdrawn.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claim 1-5, 8-13, and 16-20 are rejected under 35 U.S.C. §103 as being unpatentable over Trenholm et al.(US 20220058285 A1) [hereinafter "Trenholm"] in view of Badana et al. (US12126655B2) [hereinafter "Badana"] in view of Dhillon et al. (US 20130227700 A1) [hereinafter “Dhillon”] and in view of Kras et al.(US 20220210182 A1) [hereinafter “Kras”] and further in view of Stoler et al.(US 20200334371 A1) [hereinafter “Stoler”].
As per claim 1, Trenholm discloses a system for data access management using advanced computational models for data analysis and automated processing, ([Trenholm , [0075]” a system for performing secure data asset sharing and exchange using a computer-implemented data trust”) the system comprising: a processing device; ([Trenholm, [0032]” A computing device for use in a computer-implemented data trust for a data asset is provided herein”)a non-transitory storage device containing instructions when executed by the processing device, causes the processing device to perform the steps of : receive an interaction, ([Trenholm, [0069]” The systems and methods disclosed herein may provide automated and cost-effective data management and oversight. Data import, transfer, and access processes are automated and may occur across multiple technologies, including real-time interactions ”)wherein the interaction comprises a transfer of user metadata; ([Trenholm, [0069]” The system may optimize data transfer cycles to process high volumes of data with minimal delay (a low latency computer network). The system may include a maximized data update frequency. The maximized data update frequency may provide higher time-granularity analysis”) and wherein the guardian Al engine([Trenholm, [0173]” The application hooks may be on the AI engine 436. The policy chain maintained within the distributed ledger 454 may be interrogated or interacted with from the application hooks”) is separate from the [custodian Al engine]; ([Trenholm, [0182]” The AI engine 502 may be used by a data consumer”)
Trenholm does not explicitly disclose analyze, via a custodian artificial intelligence (AI) engine, the interaction; wherein the custodian Al engine is a short-term Al engine configured to be activated when the interaction is received, and wherein the short-term Al engine is configured to manage the interaction; analyze, via a guardian Al engine, the interaction, wherein the guardian Al engine is configured to provide guidelines for the interaction based on a user persona that indicates user preferences during the interaction, wherein the user preferences are based on historical user interactions,
configure the user metadata based on the custodian Al engine and the guardian Al engine wherein configuring the user metadata includes obfuscating at least a portion of the user metadata; and cause an execution of the interaction
However, Badana in the same field of endeavor discloses analyze, ([ Badana, Col.11 ln17-23]” The analyzer 322 performs authorization of the third-party content for permitting or denying access based on the policies from the categorizer 314. The third-party content categorized according to the risks and the policies is used for analysis by the analyzer 322 to either authorize or restrict the third-party content for access. Based on the analysis of the network traffic and the user profile, it is identified in the analyzer 322 whether the third-party content is authorized for installation”) via a custodian artificial intelligence (AI) engine, ([ Badana, Col.11 ln55-60]” The analyzer 322 includes an analysis engine 402, a scoring engine 404, a rule repository 406, a score threshold cache 408, a correlator 410, an advertisement engine 412, a risk calculator 414, an access provider 416, and a recommendation generator 418”) the interaction; ([ Badana, Col.4 ln20-25]” …the client device 102 routes some interaction… Based on the analysis of the network traffic and the user profile, it is identified in the analyzer 322 whether the third-party content is authorized for installation”)and wherein the short-term Al engine is configured to manage the interaction; analyze, via a guardian Al engine, the interaction, wherein the guardian Al engine is configured to provide guidelines for the interaction([ Badana, Col.4 ln23-27] “Under policy control, the client device 102 routes some interaction to the mid-link server 108 that hosts a controlled software environment for each end-user 106 to securely interact with the web server 104 and the service(s) 112 or enterprise tools in a way limited by specified policies.”, ” The policies control how the third-party content will be accessed on the browser or applications and provide functionalities. For example, some websites may be blocked, some may be permitted, and some may be permitted for a specific time of the day. The policies include time-based policies that restrict the usage of specific websites … end-user ([ Badana, Col.4 ln38-45] ….”([ Badana, Col.5 ln48-65, col.6 ln1-16] The risk can be associated with a user's browsing activity, user profile set by an administrator, and a category associated with the website like gaming, social media, religion, etc. Traffic monitoring can be performed to check traffic flow and determine the risk associated with the traffic flow. The Domain Name System (DNS)/Uniform Resource Locator (URL) associated with the website requested for access may be identified and the risk associated with the DNS/URL may be determined…aggregate score of 8.2” )based on a user persona that indicates user preferences during the interaction, ([Badana, Col.5 ln46-65, col.6 ln1-16]” As illustrated in Table 1, the policies are specified with respective third-party content and risk (also termed as an aggregate risk). The risk can be associated with a user's browsing activity, user profile set by an administrator, and a category associated with the website like gaming, social media, religion, etc. Traffic monitoring can be performed to check traffic flow and determine the risk associated with the traffic flow. The Domain Name System (DNS)/Uniform Resource Locator (URL) associated with the website requested for access may be identified and the risk associated with the DNS/URL may be determined…score of 8.2 wherein the user preferences are based on historical user interactions, ([Badana, col.4 ln19-27- col.6 ln1-16]” The client device(s) 102 uses content and processing from the web server 104 including content sites, for example, websites, plugins, streaming content, etc., and the service(s) 112 for example, SaaS tools, databases, cloud service providers, etc. Under policy control, the client device 102 routes some interaction to the mid-link server 108 that hosts a controlled software environment for each end-user 106 to securely interact with the web server 104 and the service(s) 112 or enterprise tools in a way limited by specified policies”…. As illustrated in Table 1, the policies are specified with respective third-party content and risk (also termed as an aggregate risk). The risk can be associated with a user's browsing activity, user profile set by an administrator, and a category associated with the website like gaming, social media, religion, etc. Traffic monitoring can be performed to check traffic flow and determine the risk associated with the traffic flow. The Domain Name System (DNS)/Uniform Resource Locator (URL) associated with the website requested for access may be identified and the risk associated with the DNS/URL may be determined…score of 8.2”).
Therefore, it would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to modify Trenholm to include wherein the short-term Al engine is configured to manage the interaction; analyze, via a guardian Al engine, the interaction, wherein the guardian Al engine is configured to provide guidelines for the interaction based on a user persona that indicates user preferences during the interaction, wherein the user preferences are based on historical user interactions as suggested by Badana. One of ordinary skill in the art would have been motivated to do so because Trenholm is directed to improving data privacy protection and implementing data trusts using distinct AI engines, and Badana provides a known technique for governing interactions with user data through policy-driven, risk-based analysis.
The references as combined above fails to disclose configure the user metadata based on the custodian Al engine and the guardian Al engine wherein configuring the user metadata includes obfuscating at least a portion of the user metadata; and cause an execution of the interaction.
However, Dhillon in the same field of endeavor discloses configure the user metadata based on the custodian Al engine and the guardian Al engine and cause an execution of the interaction. ([Dhillon, [0040]” User 158 may also restrict the account of user 148 by only permitting interactions with users meeting specific graduated trustworthiness levels. For example, a trust score minimum in a green range may only allow interactions with users from the same school and with a high trust score with a respective parent relationship. A trust score minimum in a yellow range may only allow interactions with users from the same school but may permit a less rigorous trust score with the respective parent relationship. A trust score minimum in a red range may allow unfettered interactions with any other user. Thus, an easy to understand sliding scale or color coded scale may be utilized to enable user 158 to specify a comfortable privacy level for user 148.”).
Therefore, it would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to modify the system created by combination of Trenholm’s governance rules 438 such that they are configured based on the custodian AI engine’s analysis of the interaction and the guardian AI engine’s persona-based guidelines suggested by Badana to further include configure the user metadata based on the custodian Al engine and the guardian Al engine and cause an execution of the interaction as taught by Dhillon using trust-score-based configuration mechanism. One of ordinary skill in the art would have been motivated to do so because Dhillon teaches that dynamically configured user trust metadata can be used to control whether and how interactions are permitted, restricted, or executed, thereby improving user privacy control and interaction safety. Incorporating Dhillon’s trust-score evaluation as an input to the AI governance process. In this modified system, the custodian AI engine and guardian AI engine would configure user metadata based on the evaluated trust level before permitting execution of the interaction. Doing so would improve privacy protection by ensuring that interactions are executed only when the applicable trust requirements are satisfied while maintaining automated AI-based governance of user interactions.
The combination of Trenholm, Badana and Dhillon does not disclose wherein configuring the user metadata includes obfuscating at least a portion of the user metadata.
However, Kras in the same field of endeavor discloses wherein configuring the user metadata ([Kras, [0068]” security awareness training system may use artificial intelligence (AI) and/or machine learning (ML) techniques to determine which criteria need to be marked protected and to decide how much user data should be obfuscated while displaying the user data. Thus, the security awareness portion([Kras, [0008]” then all of the users meeting the criteria are to have at least a portion of their information obfuscated for display”) of the user metadata.
Therefore, it would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to modify the system created by combination of Trenholm, Badana and Dhillon to further include wherein configuring the user metadata includes obfuscating at least a portion of the user metadata as suggested by Kras. One of ordinary skill in the art would have been motivated to do so because incorporating automatic obfuscation of at least a portion of user information in order to protect sensitive user information and improve user privacy while allowing the underlying system to continue processing and displaying user data.
The combination of Trenholm, Badana, Dhillon and Kras fails to explicitly disclose wherein the custodian Al engine is a short-term Al engine configured to be activated when the interaction is received;
However, Stoler in the same field of endeavor discloses wherein the custodian Al engine is a short-term ([Stoler, [0153]]” as instances 902a-902f themselves are dynamically spun up and spun down, secure access to them may be provided to particular clients 904”) Al engine configured to be activated when the interaction is received; ([Stoler, [0052]” the identifying of the request to provision the new virtualized execution instance occurs as part of monitoring requests to instantiate new virtual execution instances”).
Therefore, it would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to modify the system created by combination of Trenholm, Badana Dhillon and Kras to further include wherein the custodian Al engine is a short-term Al engine configured to be activated when the interaction is received as suggested by Stoler. One of ordinary skill in the art would have been motivated to do so because dynamically instantiating the AI engine only upon receipt of an interaction conserves computing resources by avoiding persistent execution, while providing the interaction-specific analysis and policy enforcement only for the duration needed to process the received interaction.
As per claim 2, Trenholm as modified above discloses the system of claim 1 . Trenholm, as
modified, lacks to disclose wherein executing the instructions further causes the processing device to: metadata and via historical interactions, and engine is configured in real-time based on the user persona and based on the interaction, but Badana teaches wherein executing the instructions further causes the processing device to: generate the user persona, wherein the user persona is generated via the user metadata and via historical interactions, ([Badana, Col.5 ln46-65, col.6 ln1-16]” The client device(s) 102 uses content and processing from the web server 104 including content sites, for example, websites, plugins, streaming content, etc., and the service(s) 112 for example, SaaS tools, databases, cloud service providers, etc. Under policy control, the client device 102 routes some interaction to the mid-link server 108 that hosts a controlled software environment for each end-user 106 to securely interact with the web server 104 and the service(s) 112 or enterprise tools in a way limited by specified policies”…. As illustrated in Table 1, the policies are specified with respective third-party content and risk (also termed as an aggregate risk). The risk can be associated with a user's browsing activity, user profile set by an administrator, and a category associated with the website like gaming, social media, religion, etc. Traffic monitoring can be performed to check traffic flow and determine the risk associated with the traffic flow. The Domain Name System (DNS)/Uniform Resource Locator (URL) associated with the website requested for access may be identified and the risk associated with the DNS/URL may be determined…score of 8.2”) and configure the guardian AI engine based on the user persona, ([Badana, Col.5 ln46-65, col.6 ln1-16]” As illustrated in Table 1, the policies are specified with respective third-party content and risk (also termed as an aggregate risk). The risk can be associated with a user's browsing activity, user profile set by an administrator, and a category associated with the website like gaming, social media, religion, etc. Traffic monitoring can be performed to check traffic flow and determine the risk associated with the traffic flow. The Domain Name System (DNS)/Uniform Resource Locator (URL) associated with the website requested for access may be identified and the risk associated with the DNS/URL may be determined…score of 8.2 [0023]”) wherein the guardian AI engine is configured in real-time based on the user persona and based on the interaction. ([Badana, Col.5 ln46-65, col.6 ln1-16]” As illustrated in Table 1, the policies are specified with respective third-party content and risk (also termed as an aggregate risk). The risk can be associated with a user's browsing activity, user profile set by an administrator, and a category associated with the website like gaming, social media, religion, etc. Traffic monitoring can be performed to check traffic flow and determine the risk associated with the traffic flow. The Domain Name System (DNS)/Uniform Resource Locator (URL) associated with the website requested for access may be identified and the risk associated with the DNS/URL may be determined…score of 8.2 ….” The client device(s) 102 uses content and processing from the web server 104 including content sites, for example, websites, plugins, streaming content, etc., and the service(s) 112 for example, SaaS tools, databases, cloud service providers, etc. Under policy control, the client device 102 routes some interaction to the mid-link server 108 that hosts a controlled software environment for each end-user 106 to securely interact with the web server 104 and the service(s) 112 or enterprise tools in a way limited by specified policies[0017 ”).
Therefore, it would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to modify Trenholm system, as previously combined with Badana, Dhillon, and Kras to further configure the processing device to generate the user persona via the user metadata and via historical interactions, and configure the guardian AI engine in real-time based on the user persona and based on the interaction as taught by Badana. One of ordinary skill in the art would have been motivated to do so because such modification would have allowed Trenholm’s AI-driven interaction management to make policy decisions using dynamically generated user-specific context, rather than relying solely on generic interaction processing, thereby enabling interaction policies to be selected and enforced according to the user’s behavior, metadata, and current interaction while improving the accuracy and effectiveness of privacy and security controls.
As per claim 3, Trenholm, as modified above discloses the system of claim 1 Trenholm, as
modified, does not disclose wherein the custodian Al engine managing the interaction comprises dynamically configuring an interaction score, wherein the interaction score influences whether the interaction should be executed, but Badana teaches wherein the custodian AI engine managing the interaction comprises dynamically configuring an interaction score, wherein the interaction score influences whether the interaction should be executed. ([Badana, col.7 ln7-26]” Some embodiments have policies that selectively direct the third-party content to the mid-link server 108 based on the network traffic. The network traffic includes the traffic flow including requests for accessing the third-party content, and data transmitted or received from the third-party content. The traffic flow is continuously monitored in real-time or over some time. A category of third-party content such as gambling may fall under the category of dangerous content and hence may be blocked by the content. Another category such as religion may entail administrator permission for access. The administrator may also specify the specific time of the day, hours of the day or night, and limitations on the accessing abilities like home VPN, office VPN, WiFi network, or mobile/cellular network. By way of another example, websites of gaming may be permitted specifically for a few hours during the day and blocked during the night. Similarly, websites containing adult content may be blocked based on the user profile set by the administrator/parent. Also, websites including social media may be permitted for a few hours a day by the policy.”
Therefore, it would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to modify the system created by combination of Trenholm, Badana Dhillon and Kras to further include Badana’s dynamically configured interaction score into Trenholm’s custodian AI engine so that the AI engine could use the calculated interaction score to determine whether an interaction should be executed. One of ordinary skill in the art would have been motivated to do so because incorporating Badana’s interaction-scoring mechanism into Trenholm’s AI-based interaction decisions to be made based on dynamically evaluated risk associated with each interaction instead of uniformly processing all interactions, thereby improving the precision and effectiveness of automated policy enforcement.
As per claim 4, Trenholm, as modified above discloses the system of claim 1. Trenholm, as
modified, does not disclose wherein the guardian Al engine providing guidelines for the interaction
comprises dynamically configuring an interaction score, wherein the interaction score influences
whether the interaction should be executed, but Badana discloses wherein the guardian AI engine providing guidelines for the interaction comprises dynamically configuring an interaction score, wherein the interaction score influences whether the interaction should be executed ([Badana, col.5 ln4-29]]” A policy enforcement preference is set for a set of policies. The policy enforcement preference assigns enforcement levels such as strict level or moderate level. For example, the strict level may be defined for a kid under 17 years of age for a gambling site whereas for a kid above 17 years, the enforcement level may be moderate for the gambling site. Priority levels are also assigned to the policies. The priority levels may be set by the administrator based on the end-user 106. The policies are enforced based on priority levels. For example, the policies for educational content during the daytime may have a higher priority level over policies for social media. The priority levels are assigned for each of the policies. The enforcement levels include a strict level with higher priority and a moderate level with lower priority. The policies with higher priority levels are assigned a strict level for a kid and those having lower priority levels are assigned a moderate level such as an adult or a team. The priority levels are ML-generated based on the user profile of the end-user 106, Uniform Resource Locator (URL) score, and policy enforcement preference. The policy enforcement preference per end-user 106 depends on various attributes. The attributes include the time of the day to access or block the access and cumulative access time on a given site(s)/category permitted or blocked. An example of the policies is illustrated in Table 1 discussed below.”).
Therefore, it would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to modify the system created by combination of Trenholm, Badana Dhillon and Kras to further configure an interaction score, wherein the interaction score influences whether the interaction should be executed as taught by Badana. Incorporating Badana’s policy enforcement preferences, including dynamically generated priority and enforcement levels based on user profile and content risk, into Trenholm’s guardian AI engine would have enabled the guardian AI engine to tailor its guidance according to the evaluated risk associated with each interaction rather than providing uniform guidance for all interactions, thereby improving the accuracy, consistency, and effectiveness of automated interaction policy enforcement.
As per claim 5, Trenholm, as modified above discloses the system of claim 4. Trenholm, as modified, does not disclose wherein the interaction score comprises : a trust score, wherein the trust score comprises the ability to trust a party associated with the interaction ; a usage score, wherein the usage score comprises the party's proposed use of the user metadata; and a downstream score, wherein the downstream score comprises analyzing third parties associated with the party to determine how the user metadata will be used by the third parties, but Dhillon teaches wherein the interaction score comprises: a trust score, wherein the trust score comprises the ability to trust a party associated with the interaction; ([Dhillon, Abstract]” a trust score with a high degree of confidence may be provided for establishing and verifying online relationships”).
Therefore, it would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to modify Badana’s interaction score, which is ML-generated based on the profile, URL score, and policy enforcement preference and which influences whether the interaction should be executed ([Badana, col.5 ln4-29]), such that one of the factors comprising the interaction score is a trust score to include a trust score, wherein the trust score comprises the ability to trust a party associated with the interaction as suggested by Dhillon. One of ordinary skill in the art would have been motivated to do so because Dhillon teaches that validating only at a single point in time, provides a higher degree of safety, reliability, and control for online interaction.
Trenholm, as modified above does not disclose a usage score, wherein the usage score comprises the party's proposed use of the user metadata; and a downstream score, wherein the downstream score comprises analyzing third parties associated with the party to determine how the user metadata will be used by the third parties.
However, Badana discloses a usage score, wherein the usage score comprises the party's proposed use of the user metadata;([ Badana, Col.5 ln48-65, col.6 ln18-25]]” The risk can be associated with a user's browsing activity, user profile set by an administrator, and a category associated with the website like gaming, social media, religion, etc. Traffic monitoring can be performed to check traffic flow and determine the risk associated with the traffic flow. The Domain Name System (DNS)/Uniform Resource Locator (URL) associated with the website requested for access may be identified and the risk associated with the DNS/URL may be determined. An aggregate risk takes into consideration the risk associated with the category of the website or application or the third-party content like gaming, social media, or adult and the risk associated with the DNS/URL in the traffic flow. The risk associated with the category of the website specifies a corresponding risk policy. The aggregate risk further considers the user profile for determining the risk…. aggregate score of 8.2” and “These policies associated with websites are set based on several factors. The factors include the user profile set by the administrator(s) (for example, parents), risks associated with the third-party content determined through the traffic flow from the client device 102 for example, adult content websites, gambling, and the browsing activities of the end-user 106 on the client device 102. The policies are set by an administrator/parent/family member of the end-user 106 based on the factors. Multiple administrators may be there like the father and mother holding separate accounts for the end-user 106… applied”) and a downstream score, wherein the downstream score comprises analyzing third parties associated with the party to determine how the user metadata will be used by the third parties. ([Badana, col.6 ln1-16, col.7 ln7-26]” The client device(s) 102 uses content and processing from the web server 104 including content sites, for example, websites, plugins, streaming content, etc., and the service(s) 112 for example, SaaS tools, databases, cloud service providers, etc. Under policy control, the client device 102 routes some interaction to the mid-link server 108 that hosts a controlled software environment for ….the third-party content specify a manner in which the third-party content is to be accessed by the end-user(s) 106” and “Some embodiments have policies that selectively direct the third-party content to the mid-link server 108 based on the network traffic. The network traffic includes the traffic flow including requests for accessing the third-party content, and data transmitted or received from the third-party content. The traffic flow is continuously monitored in real-time or over some time. A category of third-party content such as gambling may fall under the category of dangerous content and hence may be blocked by the content…by the policy”[0027]).
Therefore, it would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to modify Badana’s interaction score, which is ML-generated based on the profile, URL score, and policy enforcement preference and which influences whether the interaction should be executed ([Badana, col.5 ln4-29]), such that one of the factors comprising the interaction score is a trust score to a usage score, wherein the usage score comprises the party's proposed use of the user metadata; and a downstream score, wherein the downstream score comprises analyzing third parties associated with the party to determine how the user metadata will be used by the third parties. One of ordinary skill in the art would have been motivated to do so because Badana teaches that aggregate risk scoring, which incorporates the risk associated with the category of content being accessed, the traffic flow to third-party content, and manner in which such content is accessed by the end-user, provides a more comprehensible and accurate basis for determining whether an interaction should be permitted.
As per claim 8, the references as combined above disclose the system of claim 1. Badana further discloses wherein executing the instructions further causes the processing device to: analyze([Badana, Col.19, ln45-50]” analyze the user activities to identify patterns in the user activities, most viewed content, most viewed, or streamed content, or browsed content on the client device 102 and check compliance with the policies.”)a policy database, ([Badana, Col.10, ln50-55]”The categorizer 314 receives the list of third-party content from the browsing history log 312 and sorts it according to the list of policies from the policy database 304”)wherein the policy database comprises rules associated with the interaction; ([Badana, col.11 ln4-14]” The third-party content that is newly requested for access and does not have past usage is categorized as new. The third-party content may also be subcategorized as blocked in case the third-party content was blocked in the past. The categorizer 314 flags an alert to the IT module 214 or the end-user 106 of the client device 102 for re-authorization via the router 302. The categorization is based on machine learning algorithms. The categorizer 314 continuously monitors and updates the categories of the third-party content based on the browsing history logs from the browsing history log 312.”).Badana does not disclose configure the guardian AI engine based on the policy database.
However, Dhillon in the same field of endeavor discloses configure the guardian AI engine based on the policy database. ([Dhillon, [0013]-[0014]])” accepts trust score requests concerning a particular user, calculates a present trust score using all data concerning that user from various resources consolidated into platform database 118, and responds to the request by providing the present trust score.[0013]” and that “…users are divided into three conceptual categories depending on usage of authentication platform 116 and online service 126. Global users 160 may encompass all possible users, including users that do not utilize authentication platform 116 or online service 126. Thus, user 161 may lack user accounts with both authentication platform 116 and online service 126 …. Platform users 162 include all users that utilize authentication platform 116… Service users 164 include all users that utilize online service 126[0014]”).
Therefore, it would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to complete Badana’s policy database by configuring the guardian AI engine based on the policy database as taught by Dhillon. One of ordinary skill in the art would have been motivated to do so because configuring the guardian AI engine using the policy database enables the AI engine to apply the policy rules maintained in the policy database when evaluating user interactions.
As per claim 9, Trenholm discloses a computer program product for data access management using advanced computational models for data analysis and automated processing, the computer program product comprising a non-transitory computer-readable medium comprising code causing an apparatus to: receive an interaction([Trenholm, [0069]” The systems and methods disclosed herein may provide automated and cost-effective data management and oversight. Data import, transfer, and access processes are automated and may occur across multiple technologies, including real-time interactions ”)wherein the interaction comprises a transfer of user metadata; ([Trenholm, [0069]” The system may optimize data transfer cycles to process high volumes of data with minimal delay (a low latency computer network). The system may include a maximized data update frequency. The maximized data update frequency may provide higher time-granularity analysis”) and wherein the guardian Al engine([Trenholm, [0173]” The application hooks may be on the AI engine 436. The policy chain maintained within the distributed ledger 454 may be interrogated or interacted with from the application hooks”) is separate from the [custodian Al engine]; ([Trenholm, [0182]” The AI engine 502 may be used by a data consumer”).
Trenholm does not explicitly disclose analyze, via a custodian artificial intelligence (AI) engine, the interaction; wherein the custodian Al engine is a short-term Al engine configured to be activated when the interaction is received, and wherein the short-term Al engine is configured to manage the interaction; analyze, via a guardian Al engine, the interaction, wherein the guardian Al engine is configured to provide guidelines for the interaction based on a user persona that indicates user preferences during the interaction, wherein the user preferences are based on historical user interactions,
configure the user metadata based on the custodian Al engine and the guardian Al engine wherein configuring the user metadata includes obfuscating at least a portion of the user metadata; and cause an execution of the interaction
However, Badana in the same field of endeavor discloses analyze, ([ Badana, Col.11 ln17-23]” The analyzer 322 performs authorization of the third-party content for permitting or denying access based on the policies from the categorizer 314. The third-party content categorized according to the risks and the policies is used for analysis by the analyzer 322 to either authorize or restrict the third-party content for access. Based on the analysis of the network traffic and the user profile, it is identified in the analyzer 322 whether the third-party content is authorized for installation”) via a custodian artificial intelligence (AI) engine, ([ Badana, Col.11 ln55-60]” The analyzer 322 includes an analysis engine 402, a scoring engine 404, a rule repository 406, a score threshold cache 408, a correlator 410, an advertisement engine 412, a risk calculator 414, an access provider 416, and a recommendation generator 418”) the interaction; ([ Badana, Col.4 ln20-25]” …the client device 102 routes some interaction… Based on the analysis of the network traffic and the user profile, it is identified in the analyzer 322 whether the third-party content is authorized for installation”)and wherein the short-term Al engine is configured to manage the interaction; analyze, via a guardian Al engine, the interaction, wherein the guardian Al engine is configured to provide guidelines for the interaction([ Badana, Col.4 ln23-27] “Under policy control, the client device 102 routes some interaction to the mid-link server 108 that hosts a controlled software environment for each end-user 106 to securely interact with the web server 104 and the service(s) 112 or enterprise tools in a way limited by specified policies.”, ” The policies control how the third-party content will be accessed on the browser or applications and provide functionalities. For example, some websites may be blocked, some may be permitted, and some may be permitted for a specific time of the day. The policies include time-based policies that restrict the usage of specific websites … end-user ([ Badana, Col.4 ln38-45] ….”([ Badana, Col.5 ln48-65, col.6 ln1-16] The risk can be associated with a user's browsing activity, user profile set by an administrator, and a category associated with the website like gaming, social media, religion, etc. Traffic monitoring can be performed to check traffic flow and determine the risk associated with the traffic flow. The Domain Name System (DNS)/Uniform Resource Locator (URL) associated with the website requested for access may be identified and the risk associated with the DNS/URL may be determined…aggregate score of 8.2” )based on a user persona that indicates user preferences during the interaction, ([Badana, Col.5 ln46-65, col.6 ln1-16]” As illustrated in Table 1, the policies are specified with respective third-party content and risk (also termed as an aggregate risk). The risk can be associated with a user's browsing activity, user profile set by an administrator, and a category associated with the website like gaming, social media, religion, etc. Traffic monitoring can be performed to check traffic flow and determine the risk associated with the traffic flow. The Domain Name System (DNS)/Uniform Resource Locator (URL) associated with the website requested for access may be identified and the risk associated with the DNS/URL may be determined…score of 8.2 wherein the user preferences are based on historical user interactions, ([Badana, col.4 ln19-27- col.6 ln1-16]” The client device(s) 102 uses content and processing from the web server 104 including content sites, for example, websites, plugins, streaming content, etc., and the service(s) 112 for example, SaaS tools, databases, cloud service providers, etc. Under policy control, the client device 102 routes some interaction to the mid-link server 108 that hosts a controlled software environment for each end-user 106 to securely interact with the web server 104 and the service(s) 112 or enterprise tools in a way limited by specified policies”…. As illustrated in Table 1, the policies are specified with respective third-party content and risk (also termed as an aggregate risk). The risk can be associated with a user's browsing activity, user profile set by an administrator, and a category associated with the website like gaming, social media, religion, etc. Traffic monitoring can be performed to check traffic flow and determine the risk associated with the traffic flow. The Domain Name System (DNS)/Uniform Resource Locator (URL) associated with the website requested for access may be identified and the risk associated with the DNS/URL may be determined…score of 8.2”).
Therefore, it would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to modify Trenholm to include wherein the short-term Al engine is configured to manage the interaction; analyze, via a guardian Al engine, the interaction, wherein the guardian Al engine is configured to provide guidelines for the interaction based on a user persona that indicates user preferences during the interaction, wherein the user preferences are based on historical user interactions as suggested by Badana. One of ordinary skill in the art would have been motivated to do so because Trenholm is directed to improving data privacy protection and implementing data trusts using distinct AI engines, and Badana provides a known technique for governing interactions with user data through policy-driven, risk-based analysis.
The references as combined above fails to disclose configure the user metadata based on the custodian Al engine and the guardian Al engine wherein configuring the user metadata includes obfuscating at least a portion of the user metadata; and cause an execution of the interaction.
However, Dhillon in the same field of endeavor discloses configure the user metadata based on the custodian Al engine and the guardian Al engine and cause an execution of the interaction. ([Dhillon, [0040]” User 158 may also restrict the account of user 148 by only permitting interactions with users meeting specific graduated trustworthiness levels. For example, a trust score minimum in a green range may only allow interactions with users from the same school and with a high trust score with a respective parent relationship. A trust score minimum in a yellow range may only allow interactions with users from the same school but may permit a less rigorous trust score with the respective parent relationship. A trust score minimum in a red range may allow unfettered interactions with any other user. Thus, an easy to understand sliding scale or color coded scale may be utilized to enable user 158 to specify a comfortable privacy level for user 148.”).
Therefore, it would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to modify the system created by combination of Trenholm’s governance rules 438 such that they are configured based on the custodian AI engine’s analysis of the interaction and the guardian AI engine’s persona-based guidelines suggested by Badana to further include configure the user metadata based on the custodian Al engine and the guardian Al engine and cause an execution of the interaction as taught by Dhillon using trust-score-based configuration mechanism. One of ordinary skill in the art would have been motivated to do so because Dhillon teaches that dynamically configured user trust metadata can be used to control whether and how interactions are permitted, restricted, or executed, thereby improving user privacy control and interaction safety. Incorporating Dhillon’s trust-score evaluation as an input to the AI governance process. In this modified system, the custodian AI engine and guardian AI engine would configure user metadata based on the evaluated trust level before permitting execution of the interaction. Doing so would improve privacy protection by ensuring that interactions are executed only when the applicable trust requirements are satisfied while maintaining automated AI-based governance of user interactions.
The combination of Trenholm, Badana and Dhillon does not disclose wherein configuring the user metadata includes obfuscating at least a portion of the user metadata.
However, Kras in the same field of endeavor discloses wherein configuring the user metadata ([Kras, [0068]” security awareness training system may use artificial intelligence (AI) and/or machine learning (ML) techniques to determine which criteria need to be marked protected and to decide how much user data should be obfuscated while displaying the user data. Thus, the security awareness portion([Kras, [0008]” then all of the users meeting the criteria are to have at least a portion of their information obfuscated for display”) of the user metadata.
Therefore, it would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to modify the system created by combination of Trenholm, Badana and Dhillon to further include wherein configuring the user metadata includes obfuscating at least a portion of the user metadata as suggested by Kras. One of ordinary skill in the art would have been motivated to do so because incorporating automatic obfuscation of at least a portion of user information in order to protect sensitive user information and improve user privacy while allowing the underlying system to continue processing and displaying user data.
The combination of Trenholm, Badana, Dhillon and Kras fails to explicitly disclose wherein the custodian Al engine is a short-term Al engine configured to be activated when the interaction is received;
However, Stoler in the same field of endeavor discloses wherein the custodian Al engine is a short-term ([Stoler, [0153]]” as instances 902a-902f themselves are dynamically spun up and spun down, secure access to them may be provided to particular clients 904”) Al engine configured to be activated when the interaction is received; ([Stoler, [0052]” the identifying of the request to provision the new virtualized execution instance occurs as part of monitoring requests to instantiate new virtual execution instances”).
Therefore, it would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to modify the system created by combination of Trenholm, Badana Dhillon and Kras to further include wherein the custodian Al engine is a short-term Al engine configured to be activated when the interaction is received as suggested by Stoler. One of ordinary skill in the art would have been motivated to do so because dynamically instantiating the AI engine only upon receipt of an interaction conserves computing resources by avoiding persistent execution, while providing the interaction-specific analysis and policy enforcement only for the duration needed to process the received interaction.
As per claim 10, the substance of the claimed invention is identical or substantially similar to that of claim 2. Accordingly, this claim is rejected under the same rationale.
As per claim 11, the substance of the claimed invention is identical or substantially similar to that of claim 3. Accordingly, this claim is rejected under the same rationale.
As per claim 12, the substance of the claimed invention is identical or substantially similar to that of claim 4. Accordingly, this claim is rejected under the same rationale.
As per claim 13, the substance of the claimed invention is identical or substantially similar to that of claim 5. Accordingly, this claim is rejected under the same rationale.
As per claim 16, the substance of the claimed invention is identical or substantially similar to that of claim 8. Accordingly, this claim is rejected under the same rationale.
As per claim 17, Trenholm discloses a method for data access management using advanced computational models for data analysis and automated processing, the method comprising: receiving an interaction, ([Trenholm, [0069]” The systems and methods disclosed herein may provide automated and cost-effective data management and oversight. Data import, transfer, and access processes are automated and may occur across multiple technologies, including real-time interactions ”)wherein the interaction comprises a transfer of user metadata; ([Trenholm, [0069]” The system may optimize data transfer cycles to process high volumes of data with minimal delay (a low latency computer network). The system may include a maximized data update frequency. The maximized data update frequency may provide higher time-granularity analysis”) and wherein the guardian Al engine([Trenholm, [0173]” The application hooks may be on the AI engine 436. The policy chain maintained within the distributed ledger 454 may be interrogated or interacted with from the application hooks”) is separate from the [custodian Al engine]; ([Trenholm, [0182]” The AI engine 502 may be used by a data consumer”).
Trenholm does not explicitly disclose analyzing, via a custodian artificial intelligence (AI) engine, the interaction; wherein the custodian Al engine is a short-term Al engine configured to be activated when the interaction is received, and wherein the short-term Al engine is configured to manage the interaction; analyzing, via a guardian Al engine, the interaction, wherein the guardian Al engine is configured to provide guidelines for the interaction based on a user persona that indicates user preferences during the interaction, wherein the user preferences are based on historical user interactions,
configuring the user metadata based on the custodian Al engine and the guardian Al engine wherein configuring the user metadata includes obfuscating at least a portion of the user metadata; and causing an execution of the interaction
However, Badana in the same field of endeavor discloses analyzing, ([ Badana, Col.11 ln17-23]” The analyzer 322 performs authorization of the third-party content for permitting or denying access based on the policies from the categorizer 314. The third-party content categorized according to the risks and the policies is used for analysis by the analyzer 322 to either authorize or restrict the third-party content for access. Based on the analysis of the network traffic and the user profile, it is identified in the analyzer 322 whether the third-party content is authorized for installation”) via a custodian artificial intelligence (AI) engine, ([ Badana, Col.11 ln55-60]” The analyzer 322 includes an analysis engine 402, a scoring engine 404, a rule repository 406, a score threshold cache 408, a correlator 410, an advertisement engine 412, a risk calculator 414, an access provider 416, and a recommendation generator 418”) the interaction; ([ Badana, Col.4 ln20-25]” …the client device 102 routes some interaction… Based on the analysis of the network traffic and the user profile, it is identified in the analyzer 322 whether the third-party content is authorized for installation”)and wherein the short-term Al engine is configured to manage the interaction; analyzing, via a guardian Al engine, the interaction, wherein the guardian Al engine is configured to provide guidelines for the interaction([ Badana, Col.4 ln23-27] “Under policy control, the client device 102 routes some interaction to the mid-link server 108 that hosts a controlled software environment for each end-user 106 to securely interact with the web server 104 and the service(s) 112 or enterprise tools in a way limited by specified policies.”, ” The policies control how the third-party content will be accessed on the browser or applications and provide functionalities. For example, some websites may be blocked, some may be permitted, and some may be permitted for a specific time of the day. The policies include time-based policies that restrict the usage of specific websites … end-user ([ Badana, Col.4 ln38-45] ….”([ Badana, Col.5 ln48-65, col.6 ln1-16] The risk can be associated with a user's browsing activity, user profile set by an administrator, and a category associated with the website like gaming, social media, religion, etc. Traffic monitoring can be performed to check traffic flow and determine the risk associated with the traffic flow. The Domain Name System (DNS)/Uniform Resource Locator (URL) associated with the website requested for access may be identified and the risk associated with the DNS/URL may be determined…aggregate score of 8.2” )based on a user persona that indicates user preferences during the interaction, ([Badana, Col.5 ln46-65, col.6 ln1-16]” As illustrated in Table 1, the policies are specified with respective third-party content and risk (also termed as an aggregate risk). The risk can be associated with a user's browsing activity, user profile set by an administrator, and a category associated with the website like gaming, social media, religion, etc. Traffic monitoring can be performed to check traffic flow and determine the risk associated with the traffic flow. The Domain Name System (DNS)/Uniform Resource Locator (URL) associated with the website requested for access may be identified and the risk associated with the DNS/URL may be determined…score of 8.2 wherein the user preferences are based on historical user interactions, ([Badana, col.4 ln19-27- col.6 ln1-16]” The client device(s) 102 uses content and processing from the web server 104 including content sites, for example, websites, plugins, streaming content, etc., and the service(s) 112 for example, SaaS tools, databases, cloud service providers, etc. Under policy control, the client device 102 routes some interaction to the mid-link server 108 that hosts a controlled software environment for each end-user 106 to securely interact with the web server 104 and the service(s) 112 or enterprise tools in a way limited by specified policies”…. As illustrated in Table 1, the policies are specified with respective third-party content and risk (also termed as an aggregate risk). The risk can be associated with a user's browsing activity, user profile set by an administrator, and a category associated with the website like gaming, social media, religion, etc. Traffic monitoring can be performed to check traffic flow and determine the risk associated with the traffic flow. The Domain Name System (DNS)/Uniform Resource Locator (URL) associated with the website requested for access may be identified and the risk associated with the DNS/URL may be determined…score of 8.2”).
Therefore, it would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to modify Trenholm to include wherein the short-term Al engine is configured to manage the interaction; analyzing, via a guardian Al engine, the interaction, wherein the guardian Al engine is configured to provide guidelines for the interaction based on a user persona that indicates user preferences during the interaction, wherein the user preferences are based on historical user interactions as suggested by Badana. One of ordinary skill in the art would have been motivated to do so because Trenholm is directed to improving data privacy protection and implementing data trusts using distinct AI engines, and Badana provides a known technique for governing interactions with user data through policy-driven, risk-based analysis.
The references as combined above fails to disclose configuring the user metadata based on the custodian Al engine and the guardian Al engine wherein configuring the user metadata includes obfuscating at least a portion of the user metadata; and cause an execution of the interaction.
However, Dhillon in the same field of endeavor discloses configuring the user metadata based on the custodian Al engine and the guardian Al engine and causing an execution of the interaction. ([Dhillon, [0040]” User 158 may also restrict the account of user 148 by only permitting interactions with users meeting specific graduated trustworthiness levels. For example, a trust score minimum in a green range may only allow interactions with users from the same school and with a high trust score with a respective parent relationship. A trust score minimum in a yellow range may only allow interactions with users from the same school but may permit a less rigorous trust score with the respective parent relationship. A trust score minimum in a red range may allow unfettered interactions with any other user. Thus, an easy to understand sliding scale or color coded scale may be utilized to enable user 158 to specify a comfortable privacy level for user 148.”).
Therefore, it would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to modify the system created by combination of Trenholm’s governance rules 438 such that they are configured based on the custodian AI engine’s analysis of the interaction and the guardian AI engine’s persona-based guidelines suggested by Badana to further include configure the user metadata based on the custodian Al engine and the guardian Al engine and cause an execution of the interaction as taught by Dhillon using trust-score-based configuration mechanism. One of ordinary skill in the art would have been motivated to do so because Dhillon teaches that dynamically configured user trust metadata can be used to control whether and how interactions are permitted, restricted, or executed, thereby improving user privacy control and interaction safety. Incorporating Dhillon’s trust-score evaluation as an input to the AI governance process. In this modified system, the custodian AI engine and guardian AI engine would configure user metadata based on the evaluated trust level before permitting execution of the interaction. Doing so would improve privacy protection by ensuring that interactions are executed only when the applicable trust requirements are satisfied while maintaining automated AI-based governance of user interactions.
The combination of Trenholm, Badana and Dhillon does not disclose wherein configuring the user metadata includes obfuscating at least a portion of the user metadata.
However, Kras in the same field of endeavor discloses wherein configuring the user metadata ([Kras, [0068]” security awareness training system may use artificial intelligence (AI) and/or machine learning (ML) techniques to determine which criteria need to be marked protected and to decide how much user data should be obfuscated while displaying the user data. Thus, the security awareness portion([Kras, [0008]” then all of the users meeting the criteria are to have at least a portion of their information obfuscated for display”) of the user metadata.
Therefore, it would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to modify the system created by combination of Trenholm, Badana and Dhillon to further include wherein configuring the user metadata includes obfuscating at least a portion of the user metadata as suggested by Kras. One of ordinary skill in the art would have been motivated to do so because incorporating automatic obfuscation of at least a portion of user information in order to protect sensitive user information and improve user privacy while allowing the underlying system to continue processing and displaying user data.
The combination of Trenholm, Badana, Dhillon and Kras fails to explicitly disclose wherein the custodian Al engine is a short-term Al engine configured to be activated when the interaction is received;
However, Stoler in the same field of endeavor discloses wherein the custodian Al engine is a short-term ([Stoler, [0153]]” as instances 902a-902f themselves are dynamically spun up and spun down, secure access to them may be provided to particular clients 904”) Al engine configured to be activated when the interaction is received; ([Stoler, [0052]” the identifying of the request to provision the new virtualized execution instance occurs as part of monitoring requests to instantiate new virtual execution instances”).
Therefore, it would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to modify the system created by combination of Trenholm, Badana Dhillon and Kras to further include wherein the custodian Al engine is a short-term Al engine configured to be activated when the interaction is received as suggested by Stoler. One of ordinary skill in the art would have been motivated to do so because dynamically instantiating the AI engine only upon receipt of an interaction conserves computing resources by avoiding persistent execution, while providing the interaction-specific analysis and policy enforcement only for the duration needed to process the received interaction.
As per claim 18, the substance of the claimed invention is identical or substantially similar to that of claim 2. Accordingly, this claim is rejected under the same rationale.
As per claim 19, the substance of the claimed invention is identical or substantially similar to that of claim 3. Accordingly, this claim is rejected under the same rationale.
As per claim 20, the substance of the claimed invention is identical or substantially similar to that of claim 4. Accordingly, this claim is rejected under the same rationale.
Claims 6, 7, 14, and 15 are rejected under 35 U.S.C. §103 as being unpatentable over Trenholm et al.(US 20220058285 A1) [hereinafter "Trenholm"] in view of Badana et al. (US12126655B2) [hereinafter "Badana"] and in view of Dhillon et al. (US20130227700 A1) [hereinafter “Dhillon”] and in view of Kras et al.(US 20220210182 A1) [hereinafter “Kras”] and in view of Stoler et al.(US 20200334371 A1) [hereinafter “Stoler”] as applied to claims 5 and 13 and further in view of Yan et al. (US 20150222606 A1) [hereinafter “Yan”].
As per claim 6, the combination of references as applied above discloses the system of claim 5. The combination fails to explicitly disclose wherein executing the instructions further causes the processing device to: determine an interaction score threshold, wherein the interaction score threshold indicates an allowable interaction score of the interaction; determine the interaction score is within the interaction score threshold; and configure the user metadata prior to transfer during the interaction. However, Yan in the same field of endeavor discloses wherein executing the instructions further causes the processing device to: determine an interaction score threshold, wherein the interaction score threshold indicates an allowable interaction score of the interaction; determine the interaction score is within the interaction score threshold; and configure the user metadata prior to transfer during the interaction.([Yan, [0011]]” In an exemplary embodiment, the secret attribute key associated with the at least one trust level attribute can be generated based on an identity of the user of the second device and the at least one trust level related attribute. In an exemplary embodiment, the trust level related attribute can indicate a pre-determined threshold of trust level, and the checking comprises checking whether the trust level of the user of the second device meets the pre-determined threshold of trust level)”.
Therefore, it would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to modify Trenholm to include a usage score, wherein the usage score comprises the party’s proposed use of the user metadata and a downstream score, wherein the downstream score comprises analyzing third parties associated with the party to determine how the user metadata will be used by the third parties as suggested by Badana, add a trust score, wherein the trust score comprises the ability to trust a party associated with the interaction as taught by Dhillon and further include wherein executing the instructions further causes the processing device to: determine an interaction score threshold, wherein the interaction score threshold indicates an allowable interaction score of the interaction; determine the interaction score is within the interaction score threshold; and configure the user metadata prior to transfer during the interaction as suggested by Yan . One of ordinary skill in the art would have been motivated to do so because employing a predetermined interaction score threshold is a known and predictable technique for determining whether an interaction is allowable, thereby enabling consistent enforcement of interaction policies based on computed scores.
As per claim 7, the references as combine above disclose the system of claim 5. Kras further discloses wherein executing the instructions further causes the processing device to obfuscate at least a portion of the user metadata([Kras, [0008]” then all of the users meeting the criteria are to have at least a portion of their information obfuscated for display”)Kras fails to disclose prior to transfer during the interaction.
However, Badana discloses prior to transfer during the interaction([Badana, col.24 ln 13-25]” receiving a request for data from the end-user…. determining a category associated with the request for the data; identifying a plurality of policies… determining a machine-learning based Uniform Resource Locator (URL) score associated”).
Therefore, it would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to modify the interaction evaluation performed by the combined system to include prior to transfer during the interaction as suggested by Badana. One of ordinary skill in the art would have been motivated to do so because evaluating the interaction before transferring information allows the system to apply the appropriate policies and determine whether the requested information should be modified, restricted, or otherwise processed before disclosure.
The combination fails to disclose determine an interaction score threshold, wherein the interaction score threshold indicates an allowable interaction score of the interaction; determine the interaction score is outside the interaction score threshold.
However, Yan in the same field of endeavor discloses determine an interaction score threshold, wherein the interaction score threshold indicates an allowable interaction score of the interaction; determine the interaction score is outside the interaction score threshold([Yan, [0011]]” In an exemplary embodiment, the secret attribute key associated with the at least one trust level attribute can be generated based on an identity of the user of the second device and the at least one trust level related attribute. In an exemplary embodiment, the trust level related attribute can indicate a pre-determined threshold of trust level, and the checking comprises checking whether the trust level of the user of the second device meets the pre-determined threshold of trust level)”.The examiner interprets the phrase “meets the pre-determined threshold of trust level” as requiring a comparison of the trust level to the threshold and, by logical converse encompassing a condition in which the trust level does not meet the threshold, is outside the threshold.
Therefore, it would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to modify the system created by combination of Trenholm, Badana, Dhillon, Kras to further include wherein executing the instructions further causes the processing device to determine an interaction score threshold, wherein the interaction score threshold indicates an allowable interaction score of the interaction; determine the interaction score is outside the interaction score threshold as suggested by Yan . One of ordinary skill in the art would have been motivated to do so because incorporating an explicit threshold comparison, as taught by Yan, provides a predictable and well-understood mechanism for determining whether an interaction score satisfies or fails an allowable condition, thereby enabling the processing device to distinguish interactions that fall outside interaction score threshold.
As per claim 14, the substance of the claimed invention is identical or substantially similar to that of claim 6. Accordingly, this claim is rejected under the same rationale.
As per claim 15, the substance of the claimed invention is identical or substantially similar to that of claim 7. Accordingly, this claim is rejected under the same rationale.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Kravitz et al. (US 20190333031 A1) discloses System, method, and computer program product for validating blockchain or distributed ledger transactions in a service payment.
Fontaine et al. (US 12483397 B1) discloses Use of Cryptographic Twins for Secure Storage and Access of Entity Data.
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Komi N. AMEVIGBE whose telephone number is (571)272-3381. The examiner can normally be reached Monday-Friday 2pm-10pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Carl Colin can be reached at (571) 272-3862. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/K.N.A./Examiner, Art Unit 2493
/Michael Simitoski/Primary Examiner, Art Unit 2493