Prosecution Insights
Last updated: October 01, 2026
Application No. 18/928,542

ACCESS CONTROL AND GOVERNANCE FOR DISTRIBUTED DATA

Non-Final OA §101§103
Filed
Oct 28, 2024
Priority
Sep 13, 2024 — IN 202411069437
Examiner
ANKRUM, ALEC CHRISTOPHER
Art Unit
2434
Tech Center
2400 — Computer Networks
Assignee
Salesforce Inc.
OA Round
1 (Non-Final)
Grant Probability
Favorable
1-2
OA Rounds

Examiner Intelligence

Grants only 0% of cases
0%
Career Allowance Rate
0 granted / 0 resolved
-58.0% vs TC avg
Minimal +0% lift
Without
With
+0.0%
Interview Lift
resolved cases with interview
Typical timeline
Avg Prosecution
8 currently pending
Career history
17
Total Applications
across all art units
This examiner has no resolved cases yet (career too new); statute-level performance unavailable. The Grant Probability card shows Tech Center averages instead.

Office Action

§101 §103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Status Claims 1-20 are under examination. Priority Receipt is acknowledged of certified copies of papers required by 37 CFR 1.55. Applicant’s claim to foreign priority to the following foreign application has been acknowledged by the examiner: IN-202411069437 (9/13/2024) Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-3, 6-10, 13-17, and 20 are rejected under 35 U.S.C. § 101 under the 2019 PEG framework. The claims recite a judicial exception (an abstract idea falling within the “data analysis” grouping) that is not integrated into a practical application. Step 1: Statutory Category. Claims 1, 8, and 15 satisfy the statutory category requirement because they are directed to a method, system, and product under 35 U.S.C. § 101(a), respectively. The claims recite a series of steps involving receiving a request to access data, identifying tags from the data, determining data policies, and outputting data based on the policies. Claim 8’s steps are performed on computer system based on instructions in memory and claim 15’s by a processor from instructions on a non-transitory computer-readable medium. Step 2A, Prong 1: Identification of Judicial Exception. Claims 1, 8, and 15 recite a judicial exception within the abstract idea category. The claims recite data analysis and information processing: “receiving a request… for access to data” “identifying … tags associated with the data”, “determining … data governance policies”, “deriving filtered data”, and “outputting the filtered data” constitute mental processes and data manipulation that could be performed in the human mind. Step 2A, Prong 2: Integration into a Practical Application. Claims 1, 8, and 15 fail integration analysis. The claims do not recite any specific technological improvement to computer functionality. The claims merely state “deriving filtered data” and “outputting the filtered data” without describing the innovation or technological contribution, which is insufficient under Alice and Mayo. The preambles of claims 8 and 15 recite “one or more processors”, “memory”, and “non-transitory computer-readable medium” but these are generic computer implementation language; there is no claim to specialized hardware, FPGA, ASIC, or particular machine architecture. Per Alice, 573 U.S. at 221, merely implementing an abstract idea on a generic computer does not confer eligibility. The claim does not transform a tangible article into a different state or thing; data manipulation alone—receiving a request, identifying data tags, applying data policies, filtering data, and outputting data—is not transformation. Per Bilski, 561 U.S. at 618, and PEG p. 56, transformation requires a change in physical properties or state of a tangible article. The additional elements (processor, memory, non-transitory computer-readable medium, computer system, and computing device) are routine, conventional steps in data governance and constitute insignificant extra-solution activity. Per PEG p. 56, field-of-use limitations do not suffice. The claim does not recite a specific technological problem solved; the specification describes a business problem (data governance and access rules needing to be properly managed to protect data) but not how the claimed method, system, or product improves upon existing data governance tools in a non-conventional manner. Step 2B: Significantly More / WURC Analysis. The additional elements—processor, memory, non-transitory computer readable medium, computer system, and computing device—are all well-understood, routine, and conventional (WURC) in the field of cybersecurity and data governance as of the priority date of September 13, 2024. Processors, memory, non-transitory computer readable mediums, computer systems, and computing devices are standard, commercially available components. The specification provides no factual evidence demonstrating that these elements, individually or in combination, represent a non-conventional or inventive approach. Under Berkheimer v. HP, Inc., 881 F.3d 1360 (Fed. Cir. 2018), the examiner would need to establish a factual record that these elements are not WURC, and no such record exists. Therefore, the claim fails Step 2B as well. A similar analysis can be applied to dependent claims 2-3, 6-10, 13-17, and 20. These claims further recite and describe data manipulation using classes/taxonomy, attribute analysis, query modification, and data tag generation, therefore they are directed to a judicial exception. The judicial exception is not integrated into a practical application and the claims do not recite additional elements that amount to significantly more than the judicial exception. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claims 1-5, 8-12, and 15-19 are rejected under 35 U.S.C. 103 as being unpatentable over Reineke et al. (United States Patent Publication No. 2022/0292211), hereinafter Reineke in view of Alfaras et al. (United States Patent Publication No. 2024/0281419), hereinafter Alfaras. Regarding claim 1, a computer-implemented method comprising: receiving a request from a computing device (Reineke ¶93: “any one or more of the entities disclosed, or implied, by FIGS. 1-5 and/or elsewhere herein, may take the form of, or include, or be implemented on, or hosted by, a physical computing device, one example of which is denoted at 600.”) of a user for access to data available through a computer system (Reineke ¶65: “the user may request 502 access to data , such as a file for example.”), at least some of the data being stored locally in the computer system (Reineke ¶51: “the method 300 may begin when content metadata is extracted 302 from different data sources 302, possibly across multiple repositories, and stored locally…”); identifying one or more tags associated with the data, each tag comprising a metadata label characterizing the data (Reineke ¶64: “when a user attempts to access data, the data catalog may send the relevant contextual metadata to the security service provider, which checks for the existence of a tag indicating content sensitivity, such as ‘pii’ or ‘pci’ for example, within the content metadata, and determine, using the user identity metadata and other elements of the context based hierarchy, if the requester has the clearance to access the sensitive data. Ultimately, a final answer may be returned from the security service provider and enforced at the policy enforcement point, allowing or denying the user access to the data”); determining that one or more data governance policies are applicable to the request based on the one or more tags and further based on one or more attributes of the request (Reineke ¶64: “when a user attempts to access data, the data catalog may send the relevant contextual metadata to the security service provider, which checks for the existence of a tag indicating content sensitivity, such as ‘pii’ or ‘pci’ for example, within the content metadata, and determine, using the user identity metadata and other elements of the context based hierarchy, if the requester has the clearance to access the sensitive data. Ultimately, a final answer may be returned from the security service provider and enforced at the policy enforcement point, allowing or denying the user access to the data”); deriving [filtered] data through applying the one or more data governance policies to the data (Reineke ¶65: “A first check 504 may be performed and if the requested file is not tagged with PII, access to the file may be granted 506.”); and outputting the [filtered] data to the computing device of the user in response to the request (Reineke ¶65: “A first check 504 may be performed and if the requested file is not tagged with PII, access to the file may be granted 506.”). Reineke fails to explicitly teach filtered data. However, Alfaras teaches filtered data (Alfaras ¶264: “access control logic 435 can include mechanisms for data encryption, data masking, and data anonymization to protect sensitive data and ensure confidentiality and privacy. This may involve encrypting data at rest and in transit, masking sensitive data fields to prevent unauthorized access, and anonymizing data to remove personally identifiable information (PII) and protect user privacy.”). It would have been obvious for one of ordinary skill in the art before the effective filing date of the invention to modify Reineke in view of Alfaras to filter the data through data governance policies to protect certain data (Alfaras ¶265: “By implementing robust access control logic 435, organizations can ensure that only authorized users have access to data pipeline systems, protect sensitive data from unauthorized access, and maintain compliance with security and privacy regulations.”). Claims 8 and 15 are substantially similar to claim 1 and are rejected under the same rationale. In addition, Reineke teaches claim 8’s a computer system comprising: one or more processors; and memory storing instructions that, when executed by the one or more processors, cause the computer system to (Reineke ¶85: “A computer may include a processor and computer storage media carrying instructions that, when executed by the processor and/or caused to be executed by the processor, perform any one or more of the methods disclosed herein, or any part(s) of any method disclosed.”). In addition, Reineke teaches claim 15’s a non-transitory computer-readable medium storing program code executable by one or more processors of a computer system, the program code including instructions configurable to cause (Reineke ¶86: “embodiments within the scope of the present invention also include computer storage media, which are physical media for carrying or having computer-executable instructions or data structures stored thereon. Such computer storage media may be any available physical media that may be accessed by a general purpose or special purpose computer.”). Regarding claim 2, Reineke and Alfaras teach the method of claim 1, wherein determining that one or more data governance policies are applicable to the request comprises: identifying, from a set of digital policies maintained by the computer system, a digital policy configured with a rule referring to the one or more tags (Reineke ¶59: “more granular and refined policies could be defined, for example, that would permit users in group ‘engineering’ to access documents annotated with the tag ‘engineering_files.’”) and the one or more attributes of the request as logical conditions for allowing or disallowing access to the data (Reineke ¶52: “The data catalog 356 may then append the metadata about the request and/or the requestor, such as source IP address, user, and action type, for example, to the content metadata identified in or implied by the access request 306. The data catalog 356 may then generate a request that includes both the content metadata and the request/requestor metadata, and sends 308 that request to the security service provider 360 to determine whether the user is authorized to perform the requested action(s) on the data set specified in the request 306.”). Claims 9 and 16 are substantially similar to claim 2 and are rejected under the same rationale. Regarding claim 3, Reineke and Alfaras teach the method of claim 2, wherein the rule includes a tag class as an indirect reference to the one or more tags (Reineke ¶68: “within a hospital environment, data could be of type ‘confidential’ with subtypes ‘medical’ or ‘financial.’”), the tag class representing a group of tags that are related according to a tag taxonomy (Reineke ¶63: “By using a context-based hierarchy where metadata attributes are defined for underlying data, embodiments of the invention may enable businesses to better position themselves to handle future regulatory requests.”). Claims 10 and 17 are substantially similar to claim 3 and are rejected under the same rationale. Regarding claim 4, Reineke and Alfaras teach the method of claim 1, but Reineke fails to teach wherein the one or more data governance policies include a masking policy, and wherein deriving the filtered data comprises masking a portion of the data in accordance with the masking policy. However, Alfaras teaches wherein the one or more data governance policies include a masking policy (Alfaras ¶252: “data connector logic 433 may include capabilities for data security, compliance, and governance to ensure the confidentiality, integrity, and regulatory compliance of data throughout the pipeline. This may involve implementing encryption, access controls, data masking, and auditing mechanisms to protect sensitive data, enforce data privacy regulations, and maintain compliance with industry standards and regulations.”), and wherein deriving the filtered data comprises masking a portion of the data in accordance with the masking policy (Alfaras ¶264: “access control logic 435 can include mechanisms for data encryption, data masking, and data anonymization to protect sensitive data and ensure confidentiality and privacy. This may involve encrypting data at rest and in transit, masking sensitive data fields to prevent unauthorized access, and anonymizing data to remove personally identifiable information (PII) and protect user privacy.”). It would have been obvious for one of ordinary skill in the art before the effective filing date of the invention to modify Reineke in view of Alfaras to mask a portion of data to protect certain data (Alfaras ¶265: “By implementing robust access control logic 435, organizations can ensure that only authorized users have access to data pipeline systems, protect sensitive data from unauthorized access, and maintain compliance with security and privacy regulations.”). Claims 11 and 18 are substantially similar to claim 4 and are rejected under the same rationale. Regarding claim 5, Reineke and Alfaras teach the method of claim 1, but Reineke fails to teach wherein the one or more data governance policies include an authorization policy, and wherein deriving the filtered data comprises omitting a portion of the data in accordance with the authorization policy. However, Alfaras teaches wherein the one or more data governance policies include an authorization policy (Alfaras ¶252: “data connector logic 433 may include capabilities for data security, compliance, and governance to ensure the confidentiality, integrity, and regulatory compliance of data throughout the pipeline. This may involve implementing encryption, access controls, data masking, and auditing mechanisms to protect sensitive data, enforce data privacy regulations, and maintain compliance with industry standards and regulations.”), and wherein deriving the filtered data comprises omitting a portion of the data in accordance with the authorization policy (Alfaras ¶264: “access control logic 435 can include mechanisms for data encryption, data masking, and data anonymization to protect sensitive data and ensure confidentiality and privacy. This may involve encrypting data at rest and in transit, masking sensitive data fields to prevent unauthorized access, and anonymizing data to remove personally identifiable information (PII) and protect user privacy.”). It would have been obvious for one of ordinary skill in the art before the effective filing date of the invention to modify Reineke in view of Alfaras to omit a portion of data to protect certain data (Alfaras ¶265: “By implementing robust access control logic 435, organizations can ensure that only authorized users have access to data pipeline systems, protect sensitive data from unauthorized access, and maintain compliance with security and privacy regulations.”). Claims 12 and 19 are substantially similar to claim 5 and are rejected under the same rationale. Claims 6 and 13 are rejected under 35 U.S.C. 103 as being unpatentable over Reineke in view of Alfaras in view of Dettinger et al. (United States Patent Publication No. 2007/0156668), hereinafter Dettinger. Regarding claim 6, Reineke and Alfaras teach the method of claim 1, but fail to teach wherein deriving the filtered data comprises rewriting an initial query corresponding to the request to form a modified query for obtaining the filtered data from a datastore of the computer system. However, Dettinger teaches wherein deriving the filtered data comprises rewriting an initial query corresponding to the request to form a modified query for obtaining the filtered data from a datastore of the computer system (Dettinger ¶13: “applying the selected authorization filter to identify one or more conditions added to the database query, and modifying the database query to include the one or more conditions.”). It would have been obvious for one of ordinary skill in the art before the effective filing date of the invention to modify Reineke and Alfaras to rewrite an initial query to only retrieve filtered data that is appropriate for the request (Dettinger ¶21: “the focus of the query refers to the perspective of a user regarding the data being queried. For example, a physician may wish to query a database to identify certain patients, while a researcher may wish to compose a query to identify interesting or unusual patterns of medical tests results, independent of any particular patient. Accordingly, the focus of a query composed by the physician could be termed ‘patients,’ and the focus of a query composed by the researcher could be termed ‘medical tests’ or ‘research.’ At the same time, however, the data underlying queries from both the physician and the researcher may be the same. In one embodiment, different authorization routines may be applied to the queries of the physician and the researcher to manage the data accessed by these users.”). Claim 13 is substantially similar to claim 6 and is rejected under the same rationale. Claims 7, 14, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Reineke in view of Alfaras in view of Neystadt et al. (United States Patent Publication No. 2025/0307301), hereinafter Neystadt Regarding claim 7, Reineke and Alfaras teach the the method of claim 1, but fail to teach further comprising: determining the one or more tags using the data as an input to a machine learning model, a generative artificial intelligence model, or a pattern recognition algorithm; storing the one or more tags in association with the data prior to receiving the request; determining an initial set of tags for the data using the machine learning model, the pattern recognition algorithm, or both, wherein the initial set of tags comprises a subset of tags from a tag taxonomy; and determining the one or more tags through inputting the initial set of tags to the generative artificial intelligence model. However, Neystadt teaches further comprising: determining the one or more tags using the data as an input to a machine learning model, a generative artificial intelligence model, or a pattern recognition algorithm (Neystadt ¶33: “the step of obtaining a plurality of classification labels to be used when labelling data items may comprise: inputting the plurality of sample data items into a large language model, LLM; outputting, from the large language model, a list of topics describing what the sample data items relate to; and obtaining the plurality of classification labels from the list of topics.”); storing the one or more tags in association with the data (Neystadt ¶78: “The generated at least one embedding vector for each sample data item is associated with one of the plurality of classification labels from the classification policy CP. The generated at least one embedding vector and associated classification label for each sample data item is then stored in database 106.”) prior to receiving the request (Neystadt ¶45: “retrieving at least one data management policy corresponding to at least one classification label of the labelled data item; and using the at least one data management policy to control an action performed with respect to the labelled data item.”); determining an initial set of tags for the data using the machine learning model (Neystadt ¶59: “the present techniques use an embedding machine learning, ML, model to automatically determine the relevant classification label(s) for an unlabelled data item, which is then used to select and apply the relevant data management policy(ies).”), the pattern recognition algorithm, or both, wherein the initial set of tags comprises a subset of tags from a tag taxonomy (Neystadt ¶08: “the labels may be ‘personal’, ‘finance’, ‘human resources’, ‘confidential business information’, etc. By comparing (in embedding space) the embedding vectors generated for non-labelled data items with the stored labels, it is possible to quickly classify non-labelled data items. Furthermore, as each label is associated with at least one data management policy that is appropriate for that class, once the non-labelled data items have been determined, the appropriate security policy or policies can be quickly retrieved and used.”); and determining the one or more tags through inputting the initial set of tags to the generative artificial intelligence model (Neystadt ¶74: “An initial set of topics generated by the LLM may be input back into the LLM with a prompt to generate a refined list of mutually exclusive topics that cover the initially derived topics. The prompt may include a maximum number of mutually exclusive topics to be generated. The LLM then outputs a list of n mutually exclusive topics.”). It would have been obvious for one of ordinary skill in the art before the effective filing date of the invention to modify Reineke and Alfaras in view of Neystadt to determine tags for the data automatically using a machine learning model to be able to classify large amounts of data (Neystadt ¶02: “With huge volumes of digital data items being generated within organisations on a yearly and even daily basis, it is desirable to automate the application of such policies to the data items. However, this may require understanding the data items in some way, so that the appropriate policy/policies can be applied. For example, it may be useful to classify the data items. Currently, classification rules that help to determine how data items are classified may be manually generated, which is difficult and time consuming.”). Claims 14 and 20 and are substantially similar to claim 7 and are rejected under the same rationale. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to ALEC ANKRUM whose telephone number is (571)272-9209. The examiner can normally be reached M-F 7:15am-3:15pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Ali Shayanfar can be reached at 571-270-1050. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /A.C.A./Examiner, Art Unit 2434 /NOURA ZOUBAIR/Primary Examiner, Art Unit 2434
Read full office action

Prosecution Timeline

Oct 28, 2024
Application Filed
Jul 06, 2026
Non-Final Rejection mailed — §101, §103 (current)

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
Grant Probability
Low
PTA Risk
Based on 0 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month