DETAILED ACTION
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This action is response to communication: response to amendments/arguments filed on 06/11/2026
Claims 1-20 are currently pending in this application.
The IDS filed on 06/11/2026 has been accepted.
Double Patenting
The prior double patenting rejections have been withdrawn in response to the terminal disclaimer filed on 06/11/2026.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-3, 8 are rejected under 35 U.S.C. 103 as being unpatentable over Bunter US Patent Application Publication 2012/0278901 (Bunter), in view of Barkley et al. US Patent No. 6,202,066 (Barkley), and further in view of Sheng et al. US Patent Application Publication 2017/0124362 (Sheng).
As per claim 1, Bunter teaches a computer-implemented method of managing access to computer resources, the method comprising: by one or more processors configured to execute computer instructions: receiving from a first user a selection of a first purpose, wherein the first purpose is indicated by first use case object (paragraph 17 with user selection of a role/purpose such as a visitor, controlling data, viewing data, etc; see also paragraph 26); determining a first qualification object that is linked to the first use case object (paragraphs 25-27 wherein a user registers and the system integrates access rights to the user and role); in response to receiving, from the first entity, the selection of the first purpose: determining authorizations of the first entity for the computer resource and providing the first entity with access to the resource in accordance with the determined authorization (paragraphs 17, 26, and throughout with granting user access to a user interface according to the role/access rights).
Although Bunter teaches providing access to a computer resource associated with the first use case object, Harris does not explicitly teach providing a first one or more computer resources of a plurality of computer resources associated with the first use case object. However, this would have been obvious. Bunter already teaches providing access to data based on the selection, and it would have been obvious, if not inherent, that this “data” comprises a plurality of resources, as users generally tend to look at multiple resources in one setting. However, for a further example, see Barkley (Figure 3, col. 4 lines 53 to col. 5 line 5, col. 7 lines 15-20 wherein groups of users/roles have access to a plurality of computer resources based on the role/purpose). The cited sections further teach determining authorizations of the first entity for the first plurality of computer resoruces and providing the first entity with access to the first plurality of computer resources in accordance with the determined authorizations.
The combination thus further teaches receiving, from a second entity, a selection of the first purpose, and in response to receiving, from the second entity, the selection of the first purpose: determining a plurality of computer resources associated with the first use case object; determining authorizations of the second entity for the plurality of computer resources; and providing the second entity with access to a second one or more computer resources of the plurality of computer resources in accordance with the determined authorizations of the second entity (see rejection above with first entity, but applied to a second entity; see references above with users with same roles).
At the time the invention was filed, it would have been obvious to one of ordinary skill in the art to combine the teachings of Bunter with Barkley. One of ordinary skill in the art would have been motivated to perform such an addition to provide access control to objects that is significantly simplified and reliable (col. 7 lines 15-20).
Although the references above teach providing appropriate resources in accordance with the roles, the references do not explicitly teach wherein the authorizations of the second entity are different from the authorizations of the first entity, and wherein the second one or more computer resources is different from at least one of the first one or more computer resources.
However, this would have been obvious. For example, see Sheng (paragarphs 24-26, claim 1, Figure 2, paragraph 31 and throughout with determining access levels based on a variety of factors, including role, location, etc, and providing different resources accordingly, even if the same role/purpose/use case object).
At the time the invention was filed, it would have been obvious to one of ordinary skill in the art to combine the teachings of the Bunter combination with Sheng. One of ordinary skill in the art would have been motivated to perform such an addition to provide a secure access control method that provides high granularity of access control (paragraphs 5 and 6 of Sheng).
As per claim 2, the Bunter combination teaches wherein the authorizations includes at least one of: read authorization, write authorization, or modify authorization (Barkley col. 10 liens 55-60; see also col. 11 lines 1-50)
As per claim 3, the Bunter combination teaches wherein determining the authorizations of the first entity for the plurality of computer resources comprises: determining that the first enetiy has at least one of: a read authorization, a write authorization, or a modify authorization for at least one of the first plurality of computer resources (see throughout Barkley; for example, see col. 11 lines 40 to col. 12 lines 25 with determining different authorizations depending on role of user).
As per claim 8, the Bunter combination teaches wherein the plurality of computer resources include at least one of a file, a folder, a database, a memory, a processor, a drive, a storage device, a computer, a laptop, or a phone (Bunter paragraph 26 with access to data/file; also see Barkley throughout, such as abstract, for resources including files).
Claim 9 is rejected using the same basis of arguments used to reject claim 1 above.
Claim 10 is rejected using the same basis of arguments used to reject claim 2 above.
Claim 11 is rejected using the same basis of arguments used to reject claim 3 above.
Claim 16 is rejected using the same basis of arguments used to reject claim 8 above.
Claims 4-6, 12-14, and 17 are rejected under 35 U.S.C. 103 as being unpatentable over the Bunter combination as applied above, and further in view Bohrer et al. US Patent Application Publication 2003/0088520 (Bohrer)
As per claim 4, the Bunter combination teaches determining that qualifications of the first entity satisfy a first qualification of a first qualification object that is linked to the first use case object, and wherein the first entity is provided access to the first plurality of computer resources based at least in part on determining that the qualifications of the first entity satisfy the first qualification (paragraphs 25-27 wherein resources/access is presented to user based on the selectin of the role and the data that the user is authorized for; paragraphs 17, 26, and throughout with granting user access to a user interface according to the role/access rights; paragraph 26 wherein user is presented with a user interface and data according to his access rights; see paragraph 25 with registration including access rights based on user)
Although the Bunter combination teaches determining a qualification object that is linked to the first use case object, the Bunter combination does not explicitly teach doing this in response to receiving the selection of the first purpose from the user. This would have been obvious. For example, see Bohrer (abstract, Figure 5, paragraph 82, wherein after a user is authenticated, the system compares privacy declarations included in the request for the data in the request; see privacy preference in paragraphs 49-50 with privacy preferences including purpose; in response to the privacy declarations in the request, the system cross-references and matches privacy preference rules for each data item; again, see flow chart of Figure 5, with a request first, and in response to the request including a declaration, the system determines the qualification objects linked to the user).
At the time the invention was filed, it would have been obvious to one of ordinary skill in the art to combine the teachings of the Bunter combination with Bohrer. One of ordinary skill in the art would have been motivated to perform such an addition to provide security and flexibility by providing policies with different granularities (paragraphs 14-15 of Bohrer).
As per claim 5, it would have been obvious over the Bunter combination wherein the first qualification is one of a plurality of qualifications of a plurality of qualification objects linked to the first use case object, any of which may be satisfied by the qualifications of the first entity to provide the first entity with access to the plurality of computer resources (throughout all the references, with different levels of access; for example, see Barkley Figure 3, col. 4 lines 53 to col. 5 line 5, col. 7 lines 15-20 wherein groups of users/roles have access to a plurality of computer resources based on the role/purpose).
As per claim 6, it would have been obvious over the Bunter combination further comprising: by the one or more processors configured to execute the computer instructions: updating the first qualification of the first qualification object, wherein for subsequent access attempts involving the first qualification object, users’ qualifications must satisfy the updated first qualification (see Barkley col. 5 lines 15-27 with updating object permissions by either changing roles of user or by changing the permissions themselves or the object; once permissions are changed, it will be applied to subsequent accesses; also see Sheng paragraph 29 wherein access control updates and changes).
Claim 12 is rejected using the same basis of arguments used to reject claim 4 above.
Claim 13 is rejected using the same basis of arguments used to reject claim 5 above.
Claim 14 is rejected using the same basis of arguments used to reject claim 6 above.
Claim 17 is rejected using the same basis of arguments used to reject claim 1 and 4 above.
Claims 7, 15 are rejected under 35 U.S.C. 103 as being unpatentable over the Bunter combination as applied above, and further in view Joshi et al. US Patent Application Publication 2002/0116642 (Joshi)
As per claim 7, the Bunter combination does not explicitly teach further comprising, by the one or more processors configured to execute the computer instructions: logging, in an audit log on the one or more computer readable storage devices, an entry for an access to a first computer resource, of the first plurality of computer resources, by the first user, wherein the entry includes at least two of: a time stamp for the access, an identity of the first user, an identity of the first computer resource, a first purpose indicated by a first use case object, the qualifictions of the first user, or qualifications required for accessing the first computer resource, the qualifications including the first qualification. However, this would have been obvious. For example, see Joshi (abstract with logging events associated with resources; see paragraph 248 with information such as identity of user and identity of resource).
At the time the invention was filed, it would have been obvious to one of ordinary skill in the art to combine the teachings of the Bunter combination with Joshi. One of ordinary skill in the art would have been motivated to perform such an addition to effectively manage and protect systems (paragraph 22 of Joshi).
Claim 15 is rejected using the same basis of arguments used to reject claim 7 above.
Allowable Subject Matter
Claims 18-20 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims, and further to overcome the double patenting rejections set forth above (or receiving an approved terminal disclaimer)
The following is a statement of reasons for the indication of allowable subject matter: Although the references above teach many aspects of the claimed limitations, the limitations, as a whole, would not have been obvious over the prior art of record. For example, claims 18-20 describe instances of receiving a selection of a second purpose from a first user. Such scenarios are not taught in the cited references above. Further, see the prosecution history of parent patent applications 16/023,397 and 16/288,528.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to JASON KAI YIN GEE whose telephone number is (571)272-6431. The examiner can normally be reached on Monday-Friday 8:30-5:00 PST Pacific.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Farid Homayounmehr can be reached on (571) 272-3739. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free).
/JASON K GEE/Primary Examiner, Art Unit 2495