Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
Applicant’s arguments with respect to claim(s) 1-2, 4-14, 16-18, 20 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1-2, 4-8, 10-14, 16-18, 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Chintalapati (US 2024/0330678) in view of Szentes (US 11,200,339) in further view of Morris (US 2010/0228624)
Regarding Claim 1,
Chintalapati (US 2024/0330678) teaches a system for generating dynamic data security layers for disparate electronic environments, the system comprising:
a memory device with computer-readable program code stored thereon; at least one processing device operatively coupled to the at least one memory device and the at least one communication device, wherein executing the computer-readable code is configured to cause the at least one processing device to:
identify a potential recipient identifier (Paragraph [0180] teaches identity of third-party entity which may access user account data); identify user account data associated with the potential recipient identifier (Fig. 12, user ID)(Also see Fig. 9, 15 and associated text, teaches identifying sharing preferences of user account data associated with third-party entities);
apply the user account data and the potential recipient identifier to an artificial intelligence (AI) engine (Fig. 5 and associated text teaches an artificial intelligence program, 502)(Fig. 7, 1004 teaches using model to predict data privacy measures for user data);
determine, by the AI engine, a data security layer for the potential recipient identifier and the user account data (Paragraph [0179] teaches “the data privacy preferences may be dependent and associated with a specific user and the third-party entities); and automatically generate, by the AI engine, a data security layer dataset from the user account data (Paragraph [0179] and Fig. 15, 2304, teaches third-party entities use artificial intelligence in all decisions relating to sharing of user account data)(Paragraph [0179] teaches different data privacy preferences)
Chintalapati teaches the system of claim 1, but does not explicitly teach wherein executing the computer-readable code is further configured to cause the at least one processing device to: generate a digital user persona based on the data security layer dataset for the user account; and transmit the digital user persona to the potential recipient identifier.
Szentes (US 11,200,339) teaches generate a digital user persona based on the data security layer dataset for the user account (Fig. 1B, teaches first profile, second profile, third profile, wherein second and third profiles have persona data including different last names)); and transmit the digital user persona to the potential recipient identifier (Fig. 4, 420, select PII profile).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify Chintalapati to generate a digital user persona and transmit the persona to the potential recipient
The motivation is to help secure personal data (Abstract of Szentes)
Chintalapati and Szentes do not explicitly teach wherein the digital user persona comprises a digital wallet of the user split into multiple levels that control which data is published regarding the user based on a level of security needed
Morris (US 2010/0228624) teaches wherein the digital user persona comprises a digital wallet of the user split into multiple levels that control which data is published regarding the user based on a level of security needed (Paragraph [0063] teaches a configurable security level for the information card is configured by the user through the digital wallet)(Paragraph [0041] teaches the security level controls what data is shared with third parties (i.e. published))
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify Chintalapati and Szentes to include the digital user persona comprising a digital wallet split into multiple security levels as taught by Morris and the results would be predictable (i.e. the user could select which security level to determine what elements could be shared with a third party website)
Regarding Claim 4,
Chintalapati, Szentes and Morris teaches the system of claim 1. Chintalapati wherein executing the computer-readable code is further configured to cause the at least one processing device to:
determine a plurality of data security layers based on one or more potential recipient identifiers, wherein each data security layer may be specific to each potential recipient identifier (Paragraph [0179] teaches “the data privacy preferences may be dependent and associated with a specific user and the third-party entities)(Fig. 1 shows multiple users); and generate a plurality of data security layer datasets with pieces of data from the user account data based on the plurality of data security layers (Paragraph [0179] and Fig. 15, 2304, teaches third-party entities use artificial intelligence in all decisions relating to sharing of user account data)(Paragraph [0179] teaches different data privacy preferences).
Regarding Claim 5,
Chintalapati, Szentes and Morris teaches the system of claim 1. Chintalapati wherein the potential recipient identifier is received from a user device associated with a user account of the user account data (Fig. 15, 2312, also see paragraph [0179])).
Regarding Claim 6,
Chintalapati, Szentes and Morris teaches the system of claim 1. Chintalapati teaches wherein executing the computer-readable code is further configured to cause the at least one processing device to:
generate a training dataset comprising historical data security layers, historical data security layer datasets, and historical recipient identifiers (Fig. 7, “collect training data”)(Paragraph [0126] teaches personal data of each user is utilized in training the machine learning program…interactions the specific user has engaged with the enterprise system)(Also see Paragraph [0164]);
apply the training dataset to the AI engine; and train the AI engine at least at a first instance by applying the training dataset to the AI engine (Fig. 7, train predictive model).
Regarding Claim 7,
Chintalapati, Szentes and Morris teaches the system of claim 6. Chintalapati teaches wherein the training dataset comprises historical data security levels associated with a user account, historical data security layer datasets associated with the user account, and historical recipient identifiers associated with the user account (Fig. 7, “collect training data”)(Paragraph [0126] teaches personal data of each user is utilized in training the machine learning program…interactions the specific user has engaged with the enterprise system)(Also see Paragraph [0164]).
Regarding Claim 10,
Chintalapati, Szentes and Morris teaches the system of claim 1. Chintalapati teaches wherein executing the computer-readable code is further configured to cause the at least one processing device to:
transmit, in response to the generated data security layer dataset by the AI engine, a data security layer approval interface component to a user device associated with the user account data; receive, from the user device, a user account response to the generated data security layer dataset, wherein the user account response comprises an approval or denial (Paragraph [0183] teaches once the data privacy preferences have been determined by the machine learning program, a review of the profile data may be requested using a GUI as seen in Fig. 16);
and transmit the data security layer dataset to the potential recipient identifier based on the approval of the user account response (Fig. 17, teaches transmitting the sharing preference based on approval of the user account response).
Regarding Claim 11,
Chintalapati, Szentes and Morris teaches the system of claim 10. Chintalapati teaches wherein executing the computer-readable code is further configured to cause the at least one processing device to:
receive, based on the denial of user account response, an updated data security layer dataset from the user device, wherein the updated data security layer dataset comprises at least one addition or at least one deletion of user account data from the generated data security layer dataset; and transmit the updated data security layer dataset to the potential recipient identifier (Paragraph [0183] teaches review screen may include an update/edit feature to modify the profile data when not confirmed).
Regarding Claim 14, 16
Claim 14, 16 is similar to Claims 1, 4 and is rejected for a similar rationale.
Regarding Claim 18,
Claim 18 is similar in scope to Claim 1 and is rejected for a similar rationale.
Regarding Claim 2,
Chintalapati, Szentes and Morris teaches the system of claim 1. While Chintalapati teaches the recipient identifier Chintalapati does not explicitly teach wherein the potential recipient identifier comprises at least one of an internet protocol (IP) address, a hypertext transfer protocol secure (HTTPS) address, an electronic communication address, or a use-case identifier.
The Examiner takes Official Notice that IP address or HTTPS address are well known identifiers
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the identifier of Chintalapati to include an IP address or HTTPS address and the results would be predictable (i.e. the third-party entity would also include IP address or HTTPS address)
Regarding Claim 13,
Chintalapati, Szentes and Morris teaches the system of claim 1, but does not explicitly teach wherein the data security layer dataset is an encrypted container or an encrypted distributed ledger entry.
The Examiner takes Official Notice that encrypted distributed ledgers and containers are well known
It would have been obvious to one of ordinary skill in the art before he effective filing date of the invention to modify the data security layer dataset of Chintalapati with an encrypted distributed ledger or container and the results would be predictable (i.e. Chintalapati would use an encrypted distributed ledger or container)
Regarding Claim 8,
Chintalapati, Szentes and Morris teaches the system of claim 1, but does not explicitly teach wherein executing the computer-readable code is further configured to cause the at least one processing device to:
identify a use-case for the user account data at the potential recipient identifier; update the data security layer based on the use-case; and generate the data security layer dataset from the user account data based on the updated data security layer.
Szentes (US 11,200,339) teaches identify a use-case for the user account data at the potential recipient identifier (Col. 6, lines 55-67, teaches information for a banking website describing how accurate personal identifying information is largely required); update the data security layer based on the use-case; and generate the data security layer dataset from the user account data based on the updated data security layer (Fig. 4, 420, select PII profile).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify Chintalapati to generate a digital user persona and transmit the persona to the potential recipient
The motivation is to help secure personal data (Abstract of Szentes)
Regarding Claim 12,
Chintalapati, Szentes and Morris teaches the system of claim 1, but does not explicitly teach wherein the data security layer dataset is an imitation of the user account data.
Szentes (US 11,200,339) teaches wherein the data security layer dataset is an imitation of the user account data (Fig. 1B, teaches first profile, second profile, third profile, wherein the mixed and placeholder profiles are imitation of user account data);
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify Chintalapati so the data security layer dataset is an imitation of the user account data
The motivation is to help secure personal data (Abstract of Szentes)
Regarding Claim 17, 20
Claim 17, 20 is similar in scope to Claim 4, 8 and is rejected for a similar rationale.
Claim(s) 9 is/are rejected under 35 U.S.C. 103 as being unpatentable over Chintalapati, Szentes and Morris in view of Springer (US 2022/0245283)
Regarding Claim 9,
Chintalapati, Szentes and Morris teaches the system of claim 1, but does not explicitly teach wherein the data security layer dataset is limited by a viability threshold time, and wherein, in an instance where the viability threshold time is met, the data security layer dataset is destroyed or denied access for the potential recipient identifier.
Springer (US 2022/0245283) teaches wherein the data security layer dataset is limited by a viability threshold time, and wherein, in an instance where the viability threshold time is met, the data security layer dataset is destroyed or denied access for the potential recipient identifier (Paragraph [0007] teaches sensitive information is configured to be auto-deleted after an expiration time window)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify Chintalapati with the threshold time of Springer
The motivation is to maintain data control (Paragraph [0007] of Springer)
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to HARRIS C WANG whose telephone number is (571)270-1462. The examiner can normally be reached M-F 9:00-5:30.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, LUU PHAM can be reached at 571-270-5002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/HARRIS C WANG/Primary Examiner, Art Unit 2439