Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
This action is in response to the Amendment filed on 07/15/2026.
Claims 1-20 are under examination.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP §§ 706.02(l)(1) - 706.02(l)(3) for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/process/file/efs/guidance/eTD-info-I.jsp.
Claims 1-20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-20 of U.S. Patent No. 12,126,623 in view of Bono et al. (US 2010/0192211 A1). The subject matter claimed in the instant application is disclosed in the patent and is covered by the patent except limitations of “revoke, from a token, a first permission that grants access to the first resource of an entity; and modify the token to remove the first permission”. However, Bono et al. teaches this feature (par. 0041). Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of Bono et al. into the teaching of U.S. Patent No. 12,126,623 with the motivation to provide revocable object access such that the user may revoke access to the object by changing the token permission settings in the ACL as taught by Bono et al. (Bono et al.: abs.).
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Dunjic et al. (US 2022/0350907 A1), Bono et al. (US 2010/0192211 A1) and Sinha et al. (US 2023/0289411 A1).
Regarding claim 1, Dunjic et al. discloses A system, comprising: one or more processors; and one or more non-transitory computer-readable mediums comprising computer- executable instructions stored thereon that, as a result of execution by the one or more processors, cause the system to at least: receive an application programming interface (API) call to revoke a first permission of an application provider that grants access to a first resource of an entity [par. 0108, “A programmatic interface established by and maintained at computing system 130, such as application programming interface (API) 414, may receive request 410, and may route request 410 to consent and permissioning engine 142…”, par. 0121, “a secure programmatic interface established and maintained by executed mobile banking application 110, such application programming interface (API) 428, may receive current consent data”, par. 0102, “executed mobile banking application 110 and/or the executed web browser application may perform operations that render the obtained information within one or more display screens of a corresponding digital interface, which may prompt user 101 to provide input that modifies or revokes a level of access granted to third-party application”], receive, in response to a confirmation request, confirmation that the API call is approved by the entity [par. 0124, “display screen 436A may include additional interface elements, such as “SUBMIT” element 442, that, when selected by user 101 through additional provided input, confirm an election by user 101 to revoke, or maintain, the level of access granted to third-party application 112”]; and remove the first permission [par. 0102, “Based on data identifying the modified or revoked access for a particular one of the third-party applications, such as executed third-party application 112 or third-party application 114, computing system 130 may perform any of the exemplary processes described herein to generate a modified consent document and corresponding consent hash value for that particular third-party application”].
Dunjic et al. does not explicitly disclose revoke, from a token, a first permission that grants access to the first resource of an entity; and modify the token to remove the first permission.
However, Bono et al. teaches revoke, from a token, a first permission that grants access to the first resource of an entity; and modify the token to remove the first permission [par. 0041, “ access to the object 116 may be revoked for the token 122 by configuring an entry for the token 122 in the token permissions 126 to indicate that the token 122 is not to be used to grant access the object 116”].
Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of Bono et al. into the teaching of Dunjic et al. with the motivation to provide revocable object access such that the user may revoke access to the object by changing the token permission settings in the ACL as taught by Bono et al. [Bono et al.: abs.].
They do not explicitly disclose the token indicates both: the first permission; and a second permission to access a second resource of the entity.
However, Sinha et al. teaches the token indicates both: the first permission; and a second permission to access a second resource of the entity [par. 0174, example token includes a list of resources that are the object of the permission and a set of permissions granted, for the list of resources. In addition, the token includes the identifier of the principal user].
Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of Sinha et al. into the teaching of Dunjic et al. and Bono et al. with the motivation to use the token to verify the user's right to access the requested resource as taught by Sinha et al. [Sinha et al.: par. 0138].
Regarding claim 2, the rejection of claim 1 is incorporated.
Dunjic et al. further disclose the first permission is to be revoked via an additional API call [par. 0108, “A programmatic interface established by and maintained at computing system 130, such as application programming interface (API) 414, may receive request 410, and may route request 410 to consent and permissioning engine 142…”, par. 0121, “a secure programmatic interface established and maintained by executed mobile banking application 110, such application programming interface (API) 428, may receive current consent data”, par. 0102].
Regarding claim 3, the rejection of claim 1 is incorporated.
Dunjic et al. further disclose the computer-executable instructions that cause the system to modify the [[access data object]] include executable instructions that further cause the system to cause the [[access data object]] to be stored in a data storage system [par. 0053, “executed consent and permissioning engine 142 may perform operations that store the OAuth token, consent document, and consent hash value within an accessible data repository, such as consent data store 138”].
Bono et al. teaches modify the token [par. 0041, “ access to the object 116 may be revoked for the token 122 by configuring an entry for the token 122 in the token permissions 126 to indicate that the token 122 is not to be used to grant access the object 116”] and store the token [see fig. 1, The token 122 is registered in an access control list (ACL) 124 that is part of the authorization module 118. The ACL 124 includes token permissions 126].
Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of Bono et al. into the teaching of Dunjic et al. with the motivation to provide revocable object access such that the user may revoke access to the object by changing the token permission settings in the ACL as taught by Bono et al. [Bono et al.: abs.].
Regarding claim 4, the rejection of claim 1 is incorporated.
Dunjic et al. further disclose receive another API call to provide the application provider with access to the first resource of the entity [par. 0075, “A secure, programmatic interface established and maintained by computing system 130, such as application programming interface (API) 318, may receive request 304, and may route request 304, applied digital signature 314, and a public key certificate 316 to consent and permissioning engine 142, e.g., as executed by computing system 130”]; determine, from the access data object, that the application provider is not authorized to access the first resource; and block the application provider from accessing the first resource [par. 0089, “If, for example, executed consent detection module 324 were to detect an inconsistency between the previously granted level of access (e.g., as specified within consent document 268) and the requested elements of confidential data, executed consent detection module 324 may determine that the request 304 is inconsistent with the previously granted level of access. In some instances (not illustrated in FIG. 3A), executed consent detection module 324 may discard request 304, and may perform operations that generate and transmit an error message to executed third-party application 112, e.g., via API 208”].
Regarding claim 5, the rejection of claim 1 is incorporated.
Dunjic et al. further disclose determine, by at least using the [[access data object]], that the application provider is authorized to access the second resource; and grant the application provider access to the second resource of the entity [par. 0090, “ if executed consent detection module 324 were to establish a consistency between the previously granted level of access and each of the requested elements of confidential data, executed consent detection module 324 may perform operations that package each of data identifiers 306 into corresponding portions of accessible data identifiers 326. By way of example, and as described herein, data identifiers 306 may identify requested elements of confidential data that include, but are not limited to, a current account balance of a credit card account held by user 101 and transaction dates and values characterizing a specified number of recent purchase transactions involving that credit card account, e.g., the thirty most-recent purchase transactions involving the credit card account”].
Sinha et al. teaches using the token, that the application provider is authorized to access the second resource [par. 0174, example token includes a list of resources that are the object of the permission and a set of permissions granted, for the list of resources. In addition, the token includes the identifier of the principal user].
Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of Sinha et al. into the teaching of Dunjic et al. and Bono et al. with the motivation to use the token to verify the user's right to access the requested resource as taught by Sinha et al. [Sinha et al.: par. 0138].
Regarding claim 6, the rejection of claim 1 is incorporated.
Dunjic et al. further disclose executable instructions that further cause the system to grant an aggregator system access to the second resource by using the [[access data object]] in an API call [par. 0091, “the information within consent document 268 may also indicate that user 101 granted third-party application 112 access to elements of confidential transaction data characterizing a transaction type, value, and time for one or more transactions involving user 101”].
Sinha et al. teaches grant an aggregator system access to the second resource by using the token [par. 0174, example token includes a list of resources that are the object of the permission and a set of permissions granted, for the list of resources. In addition, the token includes the identifier of the principal user].
Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of Sinha et al. into the teaching of Dunjic et al. and Bono et al. with the motivation to use the token to verify the user's right to access the requested resource as taught by Sinha et al. [Sinha et al.: par. 0138].
Regarding claim 7, the rejection of claim 1 is incorporated.
Dunjic et al. further disclose one or more permissions are authorized by the entity via a user interface to a computing resource management system [par. 0040, “The one or more display screens of digital consent interface 214 may prompt user 101 to provide input to client device 102 that specifies whether user 101 grants third-party application 112 permission to access certain types, classes, or discrete elements of the confidential data maintained by computing system”].
Regarding claim 8, Dunjic et al. discloses A computer-implemented method, comprising: receiving an application programming interface (API) call to obtain [[an access data object]] that indicates a permission of an application provider to access a first resource of an entity [par. 0121, “a secure programmatic interface established and maintained by executed mobile banking application 110, such application programming interface (API) 428, may receive current consent data”, par. 0091, “the information within consent document 268 may also indicate that user 101 granted third-party application 112 access to elements of confidential transaction data characterizing a transaction type, value, and time for one or more transactions involving user 101”]; generating the [[access data object]] to indicate the permission; and modifying [[the access data object]], to produce a modified [[access data object]], to remove the permission or the previous permission [par. 0102, “Based on data identifying the modified or revoked access for a particular one of the third-party applications, such as executed third-party application 112 or third-party application 114, computing system 130 may perform any of the exemplary processes described herein to generate a modified consent document and corresponding consent hash value for that particular third-party application”].
Bono et al. teaches obtain a token that indicates a permission of an application provider to access a first resource of an entity; generating the token to indicate the permission [abs, “The token is registered in an access control list (ACL), and token permission settings in the ACL are utilized to control access to the object”]; and modifying the token, to produce a modified token, to remove the permission or the previous permission [par. 0041, “ access to the object 116 may be revoked for the token 122 by configuring an entry for the token 122 in the token permissions 126 to indicate that the token 122 is not to be used to grant access the object 116”].
Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of Bono et al. into the teaching of Dunjic et al. with the motivation to provide revocable object access such that the user may revoke access to the object by changing the token permission settings in the ACL as taught by Bono et al. [Bono et al.: abs.].
Sinha et al. teaches identifying a previous permission to access a second resource of the entity; generating the token to indicate the permission and the previous permission [par. 0174, example token includes a list of resources that are the object of the permission and a set of permissions granted, for the list of resources. In addition, the token includes the identifier of the principal user].
Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of Sinha et al. into the teaching of Dunjic et al. and Bono et al. with the motivation to use the token to verify the user's right to access the requested resource as taught by Sinha et al. [Sinha et al.: par. 0138].
Regarding claim 9, the rejection of claim 8 is incorporated.
Dunjic et al. further disclose the API call is received from an aggregator system; and the computer-implemented method further comprises causing the aggregator system to grant the application provider access to the first resource of the entity [par. 0091, “the information within consent document 268 may also indicate that user 101 granted third-party application 112 access to elements of confidential transaction data characterizing a transaction type, value, and time for one or more transactions involving user 101”].
Regarding claim 10, the rejection of claim 8 is incorporated.
Dunjic et al. further disclose causing an aggregator system to record the modified access data object [par. 0053, “executed consent and permissioning engine 142 may perform operations that store the OAuth token, consent document, and consent hash value within an accessible data repository, such as consent data store 138”].
Bono et al. teaches modify the token [par. 0041, “ access to the object 116 may be revoked for the token 122 by configuring an entry for the token 122 in the token permissions 126 to indicate that the token 122 is not to be used to grant access the object 116”] and record the token [see fig. 1, The token 122 is registered in an access control list (ACL) 124 that is part of the authorization module 118. The ACL 124 includes token permissions 126].
Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of Bono et al. into the teaching of Dunjic et al. with the motivation to provide revocable object access such that the user may revoke access to the object by changing the token permission settings in the ACL as taught by Bono et al. [Bono et al.: abs.].
Regarding claim 11, the rejection of claim 8 is incorporated.
Dunjic et al. further disclose receiving an additional API call to access the first resource, the additional API call identifying the application provider [par. 0075, “A secure, programmatic interface established and maintained by computing system 130, such as application programming interface (API) 318, may receive request 304, and may route request 304, applied digital signature 314, and a public key certificate 316 to consent and permissioning engine 142, e.g., as executed by computing system 130”]; determining, from the modified access data object, that the application provider is not authorized to access the first resource; and blocking the application provider from accessing the first resource [par. 0089, “If, for example, executed consent detection module 324 were to detect an inconsistency between the previously granted level of access (e.g., as specified within consent document 268) and the requested elements of confidential data, executed consent detection module 324 may determine that the request 304 is inconsistent with the previously granted level of access. In some instances (not illustrated in FIG. 3A), executed consent detection module 324 may discard request 304, and may perform operations that generate and transmit an error message to executed third-party application 112, e.g., via API 208”].
Bono et al. teaches modify the token [par. 0041, “ access to the object 116 may be revoked for the token 122 by configuring an entry for the token 122 in the token permissions 126 to indicate that the token 122 is not to be used to grant access the object 116”] and store the object in a data storage system [see fig. 1, The token 122 is registered in an access control list (ACL) 124 that is part of the authorization module 118. The ACL 124 includes token permissions 126].
Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of Bono et al. into the teaching of Dunjic et al. with the motivation to provide revocable object access such that the user may revoke access to the object by changing the token permission settings in the ACL as taught by Bono et al. [Bono et al.: abs.].
Regarding claim 12, the rejection of claim 8 is incorporated.
Dunjic et al. further disclose receiving an additional API call to access a third resource of the entity [par. 0075, “A secure, programmatic interface established and maintained by computing system 130, such as application programming interface (API) 318, may receive request 304, and may route request 304, applied digital signature 314, and a public key certificate 316 to consent and permissioning engine 142, e.g., as executed by computing system 130”]; and as a result of identifying that the access data object does not indicate a permission to access the third resource, blocking access to the third resource [par. 0089, “If, for example, executed consent detection module 324 were to detect an inconsistency between the previously granted level of access (e.g., as specified within consent document 268) and the requested elements of confidential data, executed consent detection module 324 may determine that the request 304 is inconsistent with the previously granted level of access. In some instances (not illustrated in FIG. 3A), executed consent detection module 324 may discard request 304, and may perform operations that generate and transmit an error message to executed third-party application 112, e.g., via API 208”].
Bono et al. teaches identifying that the token does not indicate a permission to access the third resource [par. 0041, “The ACL is configured to indicate that the token does not have permission to access the object”].
Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of Bono et al. into the teaching of Dunjic et al. with the motivation to provide revocable object access such that the user may revoke access to the object by changing the token permission settings in the ACL as taught by Bono et al. [Bono et al.: abs.].
Regarding claim 13, the rejection of claim 8 is incorporated.
Sinha et al. further teaches the token indicates permissions for multiple applications to access one or more resources authorized by the entity [par. 0174, example token includes a list of resources that are the object of the permission and a set of permissions granted, for the list of resources. In addition, the token includes the identifier of the principal user].
Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of Sinha et al. into the teaching of Dunjic et al. and Bono et al. with the motivation to use the token to verify the user's right to access the requested resource as taught by Sinha et al. [Sinha et al.: par. 0138].
Regarding claim 14, the rejection of claim 8 is incorporated.
Dunjic et al. further disclose providing, via an access API call, an aggregator system with access to the second resource using the modified access data object [par. 0075, “A secure, programmatic interface established and maintained by computing system 130, such as application programming interface (API) 318, may receive request 304”, par. 0179, “the modified consent data may associate the unique application identifier of each of the one or more executable third-party applications (e.g., third-party applications 112 or 114) with either: (i) elements of modification information that identify a requested modification to the level of access to confidential data previously granted by user 101 to an executable third-party application associated with the unique application identifier; or (ii) elements of status information indicative of an intention to maintain the level of access to confidential data previously granted by user 101 to the that executable third-party application”].
Bono et al. teaches modify the token [par. 0041, “ access to the object 116 may be revoked for the token 122 by configuring an entry for the token 122 in the token permissions 126 to indicate that the token 122 is not to be used to grant access the object 116”].
Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of Bono et al. into the teaching of Dunjic et al. with the motivation to provide revocable object access such that the user may revoke access to the object by changing the token permission settings in the ACL as taught by Bono et al. [Bono et al.: abs.].
Regarding claim 15, it recites limitations like claim 1. The reason for the rejection of claim 1 is incorporated herein.
Regarding claim 16, the rejection of claim 15 is incorporated.
Bono et al. further teaches the computer-executable instructions include executable instructions that further cause the computer system to refresh the token to generate a refreshed token [abs, “The user may revoke access to the object by changing the token permission settings in the ACL”, par. 0039, “token permission settings may be changed multiple times, thus allowing access to an object to be allowed, revoked, re-allowed, and so on. Thus, by managing object access via token permission settings in the ACL, associating a token with an object enables conditional access to the object. For example, to allow access to an object using a URL/token combination, a condition may require that the token permission settings for the token allow the object to be accessed”].
Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of Bono et al. into the teaching of Dunjic et al. with the motivation such that associating a token with an object enables conditional access to the object as taught by Bono et al. [Bono et al.: abs.].
Regarding claim 17, the rejection of claim 15 is incorporated.
Dunjic et al. further disclose the API call is received from an aggregator system at least in part as a result of the entity being redirected to a computing resource management system in response to a login operation at one or more application providers [see Fig. 4A, par. 0104, “ Executed mobile banking application 110 may receive the one or more authentication credentials… executed mobile banking application 110 may perform operations that… implements a token-based consent and authorization processes (e.g., an OAuth protocol) to authenticate an identity of user 101 and generate an OAuth token indicative of the successful authentication of the identity of user 101 and a permission of executed mobile banking application 110 to access programmatic interfaces established and maintained by computing system 130 ”, par. 0075, “A secure, programmatic interface established and maintained by computing system 130, such as application programming interface (API) 318, may receive request 304”].
Regarding claim 18, the rejection of claim 15 is incorporated.
Dunjic et al. further disclose the API call is received from an aggregator system acting on behalf of the application [par. 0075, “A secure, programmatic interface established and maintained by computing system 130, such as application programming interface (API) 318, may receive request 304”].
Regarding claim 19, the rejection of claim 5 is incorporated.
Dunjic et al. further disclose receive, from an aggregator system, an additional API call to access the second resource of the entity [par. 0075, “A secure, programmatic interface established and maintained by computing system 130, such as application programming interface (API) 318, may receive request 304, and may route request 304, applied digital signature 314, and a public key certificate 316 to consent and permissioning engine 142, e.g., as executed by computing system 130”]; identify, from the set of permissions indicated by the [[access data object]], the second permission that allows access to the second resource of the entity; and provide the aggregator system access to the second resource on behalf of the application [par. 0090, “if executed consent detection module 324 were to establish a consistency between the previously granted level of access and each of the requested elements of confidential data, executed consent detection module 324 may perform operations that package each of data identifiers 306 into corresponding portions of accessible data identifiers 326. By way of example, and as described herein, data identifiers 306 may identify requested elements of confidential data that include, but are not limited to, a current account balance of a credit card account held by user 101 and transaction dates and values characterizing a specified number of recent purchase transactions involving that credit card account, e.g., the thirty most-recent purchase transactions involving the credit card account”].
Sinha et al. further teachers identify, from the set of permissions indicated by the token, the second permission that allows access to the second resource of the entity [par. 0174, example token includes a list of resources that are the object of the permission and a set of permissions granted, for the list of resources. In addition, the token includes the identifier of the principal user].
Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of Sinha et al. into the teaching of Dunjic et al. and Bono et al. with the motivation to use the token to verify the user's right to access the requested resource as taught by Sinha et al. [Sinha et al.: par. 0138].
Regarding claim 20, the rejection of claim 15 is incorporated.
Dunjic et al. further disclose receive an additional API call to include a third permission of the application to access a third resource of the entity [par. 0108, “A programmatic interface established by and maintained at computing system 130, such as application programming interface (API) 414, may receive request 410, and may route request 410 to consent and permissioning engine 142…”, par. 0040, “The one or more display screens of digital consent interface 214 may prompt user 101 to provide input to client device 102 that specifies whether user 101 grants third-party application 112 permission to access certain types, classes, or discrete elements of the confidential data maintained by computing system”]; and in response to receipt of the API call, modify the [[access data object]] or the modified [[access data object]] to indicate at least the third permission and the second permission [par. 0102, “Based on data identifying the modified or revoked access for a particular one of the third-party applications, such as executed third-party application 112 or third-party application 114, computing system 130 may perform any of the exemplary processes described herein to generate a modified consent document and corresponding consent hash value for that particular third-party application”].
Bono et al. teaches modify the token [par. 0041, “access to the object 116 may be revoked for the token 122 by configuring an entry for the token 122 in the token permissions 126 to indicate that the token 122 is not to be used to grant access the object 116”].
Before the effective filing date of the claimed invention, it would have been obvious to a person having ordinary skill in the art to incorporate the teaching of Bono et al. into the teaching of Dunjic et al. with the motivation to provide revocable object access such that the user may revoke access to the object by changing the token permission settings in the ACL as taught by Bono et al. [Bono et al.: abs.].
Response to Arguments
Applicants’ arguments, filed on 07/15/2026, with respect to rejection under 35 USC § 103 have been considered but are moot in view of the new ground(s) of rejection.
Conclusion
The prior art made of record and not relied upon is considered pertinent to Applicant’s disclosure:
US 20230128813 A1 SYSTEMS AND METHODS FOR MANAGING TOKENS AND FILTERING DATA TO CONTROL DATA ACCESS
US 20230222137 A1 DATA MANAGEMENT PLATFORM
US 20210075782 A1 SYSTEMS AND METHODS FOR CONTROLLING THIRD-PARTY ACCESS OF A PROTECTED DATA RESOURCE
US 20200104519 A1 MANAGING CONTENT AUTHORIZATION IN A FEDERATED APPLICATION SYSTEM
US 9699170 B2 Bundled Authorization Requests
US 20150200948 A1 Controlling Access By Web Applications To Resources On Servers
US 20130067568 A1 Resource Access Authorization
US 20090089803 A1 Notifying A User Of Access To Information By An Application
US 20150089617 A1 SINGLE SIGN-ON (SSO) FOR MOBILE APPLICATIONS
US 20220350907 A1 ENFORCING DATA PRIVACY POLICIES FOR FEDERATED APPLICATIONS
US 20230308429 A1 METHOD AND APPARATUS RELATED TO AUTHORISATION TOKENS FOR SERVICE REQUESTS
US 20250150826 A1 SYSTEMS AND METHODS FOR TIERED AUTHENTICATION
US 20210019763 A1 A METHOD FOR MANAGING A VERIFIED DIGITAL IDENTITY
US 20190370487 A1 CONSENT-DRIVEN PRIVACY DISCLOSURE CONTROL PROCESSING
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to JASON CHIANG whose telephone number is (571)270-3393. The examiner can normally be reached on 9 AM TO 6 PM.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn Feild can be reached on (571) 272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/JASON CHIANG/Primary Examiner, Art Unit 2431