DETAILED ACTION
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This office action is response to communication filed on July 20, 2026.
Status of claims within the present application:
Claims 1 – 20 are pending.
Claims 1 – 2, 4 – 5, 7 – 9, 11 – 13, 15 – 16, and 18 are amended.
Response to Amendment
With respect to claims 1 – 20 that were rejected under 35 U.S.C. 101 because the claimed invention is directed to judicial exception (an abstract idea) without significantly more, applicant’s arguments, see page [12 – 16] of applicant’s remark, filed July 20, 2026, have been fully considered and are persuasive. Therefore, the rejection has been withdrawn.
With respect to claims 1 – 20 that were rejected under 35 U.S.C. 103 as being unpatentable over US 20190377832 A1 to McLean et al., (hereinafter, “McLean”) in view of US 20200327175 A1 to Stephenson et al., (hereinafter, “Stephenson”), applicant’s arguments, see page [16 – 22] of applicant’s remark, filed July 20, 2026, have been considered but are not persuasive. Therefore, applicant is directed to the response below:
With respect to claims 1 and 11, applicant argued that the prior art does not teach “receiving a query request associated with a specific person within an organization and a target access object for which access control is to be performed;”. Examiner noted the prior art of McLean does disclose “Search requests (e.g., from an initial or root search) including one or more specific search parameters can be received from or through authorized clients whose security data is part of the one or more searchable data stores. The search parameters may be directed or limited to include one or more indicators of compromise (“IOCs”) or other suitable information, including but not limited to an IP address, an access time, an access date, an external email address, a country of origin, a traffic type, a communication type, and/or combinations thereof. In addition, while various indicators can be selected for a set or subset of clients/organizations, such indicators generally should not be identifiers for any participating organizations at any established or client selected k-value.” [Para. 6]. The search requests have specific search parameters that determine whether it is from authorized clients which is understood as “a query request associated with a specific person within an organization”. The search parameters can be understood as target access object which access is to be performed on since they can contain IP address, an access time, an access date, an external email address, a country of origin, a traffic type, a communication type, and/or combinations thereof. Applicant’s other arguments have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. Therefore, the rejection still stands.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1 – 20 are rejected under 35 U.S.C. 103 as being unpatentable over US 20190377832 A1 to McLean et al., (hereinafter, “McLean”) in view of US 20230297619 A1 to Vlant et al., (hereinafter, “Vlant”).
Regarding claim 1, McLean teaches a method for dynamic access control, comprising: receiving a query request associated with a specific person within an organization and a target access object for which access control is to be performed; [McLean, para. 6 discloses Search requests (e.g., from an initial or root search) including one or more specific search parameters can be received from or through authorized clients whose security data is part of the one or more searchable data stores. The search parameters may be directed or limited to include one or more indicators of compromise (“IOCs”) or other suitable information, including but not limited to an IP address, an access time, an access date, an external email address, a country of origin, a traffic type, a communication type, and/or combinations thereof. In addition, while various indicators can be selected for a set or subset of clients/organizations, such indicators generally should not be identifiers for any participating organizations at any established or client selected k-value.], but McLean does not teach returning a query result according to inferences made via a data structure in a database in response to the query request, wherein the data structure is an access control knowledge graph and the query result indicates an access permission of the specific person for the target access object.
However, Vlant does teach returning a query result according to inferences made via a data structure in a database in response to the query request, [Vlant, para. 37 discloses receiving a query response from the data store, wherein the query response comprises a dataset comprising the determined source object and target object pairs, and a count value associated with each pair; and providing a response to the read request, wherein the response comprises the query response. The data store may be a PostgreSQL data store. The read request may be in the form of a GraphQL query and the transformed query may be in the form of a PostgreSQL query.] wherein the data structure is an access control knowledge graph [Vlant, para. 63 discloses The graph data structure (or “graph”) may represent a network of entities (such as people or things), for example entities associated with an accounting platform, and the information and relationships known about those entities. The graph may be an enriched information interface, which may be capable of providing a coherent and/or enhanced view of knowledge about the network of entities. The graph may be generated or created based on raw data derived from how the accounting platform is used by organizations to manage their accounting needs.] and the query result indicates an access permission of the specific person for the target access object. [Vlant, para. 276 discloses the response may comprise a first dataset. The first dataset may comprise a list of target object(s) (or target object identifier(s)) associated with each source object (or source object identifier), and optionally, second objects associated with each target object(s). In some embodiments, the read interface 206B determines, target object identifiers using the target object keys from a second object type vertex table. In some embodiments, the second object type vertex table may be the first object type vertex table. In that case, the source and target objects are objects of the same type.]
Therefore, it would be obvious to one of ordinary skill within the art before the effective filing date to combine Vlant’s system with McLean’s system, with a motivation for Optimizing the query is to shift the heaviest part of the query out of the query engine in the graph read interface 206B and into the data store or database where the data is stored, such as the data structure 300 of the graph interface module 206, for exions, apps, employees, contacts, business types, partners, interactions such as events or transactions, etc. For example, an interaction may be a financial transaction or an API call to an app. Each vertex 102 may have a plurality of fields, which may be mandatory or optional. Each field may be populated with a property of the vertex 102. [Vlant, para. 256]
As per claim 2, modified McLean teaches the method according to Claim 1, wherein: the access control knowledge graph is constructed based on a plurality of entities and a relationship between two entities of the plurality of entities, [McLean, para. 5 discloses enabling global searching of one or more data stores including aggregated security data of a plurality of clients in a client base can include receiving and recording a series of anonymity values set by participating clients of the client base whose security data is part of the one or more accessible data stores] the plurality of entities comprises a plurality of access object entities and a plurality of organization entities, [McLean, para. 13 discloses memory systems or storage devices configured to receive and store one or more searchable data stores including security data gathered from a plurality of clients of the client base and/or threat community. Such memory or storage can include servers or other suitable information handling system(s) in an MSSP's event/data center, though other memories or storage systems, e.g., cloud based storage, is possible without departing from the scope of the present disclosure. The security data can include security logs, event logs, raw data, etc. gathered from monitoring of, or otherwise received from, one or more networked systems of the plurality of clients.] the plurality of access object entities corresponds to a plurality of access objects for which access control is to be performed, the plurality of access objects comprises the target access object, [McLean, para. 15 discloses the processor(s) further will be operable to record a series of anonymity k-values set or selected by each of one or more clients of the plurality of participating clients who have security data that is part of the one or more searchable data stores. Upon receiving search requests including one or more search parameters, e.g., IOCs or other security parameter information, from one or more clients, the processor(s) will perform the requested search(es) and generate result sets or data clusters based on the one or more search parameters.] and the plurality of organization entities corresponds to a plurality of sub-organizations of the organization divided into different levels, [McLean, para. 6 discloses The search parameters may be directed or limited to include one or more indicators of compromise (“IOCs”) or other suitable information, including but not limited to an IP address, an access time, an access date, an external email address, a country of origin, a traffic type, a communication type, and/or combinations thereof. In addition, while various indicators can be selected for a set or subset of clients/organizations, such indicators generally should not be identifiers for any participating organizations at any established or client selected k-value.] and the relationship comprises: an organization affiliation relationship between two organization entities of the plurality of organization entities, [McLean, para. 37 discloses clients or other authorized entities can access a computer program product, application, etc., e.g., using one of the client managed information handling systems 32, and initiate searching or querying of the security data in the data stores 11, for example, to facilitate the detection/identification of potential malicious actors or security threats, and possibly remediate or take preventative actions thereagainst, to develop applications or programs for threat prevention/identification, etc.] and an access permission relationship between a respective organization entity of the plurality of organization entities and a respective access entity of the plurality of access object entities. [McLean, para. 37 discloses search parameters may be required to be anchored around indicators of compromise (“IOC”) or other similar information, including but not limited to an IP address, an access time, an access date, an email address, such as an email that is external to the participating clients, a country of origin, a traffic type, a communication type, and/or combinations thereof.]
As per claim 3, modified McLean teaches the method according to Claim 2, wherein: the plurality of entities further comprises at least one role entity; and the relationship further comprises at least one of (i) a respective role permission of a respective role entity of the at least one role entity for the access permission relationship, [McLean, para. 37 discloses clients or other authorized entities can access a computer program product, application, etc., e.g., using one of the client managed information handling systems 32, and initiate searching or querying of the security data in the data stores 11, for example, to facilitate the detection/identification of potential malicious actors or security threats, and possibly remediate or take preventative actions thereagainst, to develop applications or programs for threat prevention/identification, etc.] and (ii) an object affiliation relationship between two access object entities of the plurality of access object entities. [McLean, para. 37 discloses search parameters may be required to be anchored around indicators of compromise (“IOC”) or other similar information, including but not limited to an IP address, an access time, an access date, an email address, such as an email that is external to the participating clients, a country of origin, a traffic type, a communication type, and/or combinations thereof.]
Regarding claim 4, modified McLean teaches the method according to Claim 3, wherein: the access control knowledge graph comprises a plurality of access object nodes corresponding to the plurality of access object entities, [McLean, para. 5 discloses enabling global searching of one or more data stores including aggregated security data of a plurality of clients in a client base can include receiving and recording a series of anonymity values set by participating clients of the client base whose security data is part of the one or more accessible data stores] a plurality of organization nodes corresponding to the plurality of organization entities, [McLean, para. 6 discloses The search parameters may be directed or limited to include one or more indicators of compromise (“IOCs”) or other suitable information, including but not limited to an IP address, an access time, an access date, an external email address, a country of origin, a traffic type, a communication type, and/or combinations thereof. In addition, while various indicators can be selected for a set or subset of clients/organizations, such indicators generally should not be identifiers for any participating organizations at any established or client selected k-value.] and at least one role node corresponding to the at least one role entity; [McLean, para. 37 discloses clients or other authorized entities can access a computer program product, application, etc., e.g., using one of the client managed information handling systems 32, and initiate searching or querying of the security data in the data stores 11, for example, to facilitate the detection/identification of potential malicious actors or security threats, and possibly remediate or take preventative actions thereagainst, to develop applications or programs for threat prevention/identification, etc.], but McLean does not teach in the access control knowledge graph (i) the organization affiliation relationship is represented as an edge connected between two organization nodes corresponding to the two organization entities; the access permission relationship is represented as a rule node connected between an organization node corresponding to the respective organization entity and an access object node corresponding to a respective access object entity, (ii) the object affiliation relationship is represented as an edge connected between two access object nodes corresponding to the two access object entities, and (iii) the respective role permission is represented as an edge connected between a role node corresponding to the respective role entity and a rule node corresponding to the access permission relationship.
However, Vlant does teach in the access control knowledge graph (i) the organization affiliation relationship is represented as an edge connected between two organization nodes corresponding to the two organization entities; [Vlant, para. 68 discloses the graph 100 may comprise multiple edges 104, for example, of different edge types, between the same two vertices 102. In some embodiments, each edge 104 may be representative of an individual interaction between the entities (objects or inferred objects) of the two vertices 102 interconnected by the edge 104. For example, each edge 104 may be representative of an edge type and a specific interaction. Each edge 104 may have a plurality of fields, which may be mandatory or optional.] the access permission relationship is represented as a rule node connected between an organization node corresponding to the respective organization entity and an access object node corresponding to a respective access object entity, [Vlant, para. 73 discloses The builder module 204 may be configured to determine edge(s) 104 and/or vertices 102 based on corresponding objects and/or object relationships as defined in the raw data, and/or may be configured to infer edges and/or vertice(s) based on information defined in the raw data or the graph 100, or derived or deduced from the raw data 202 and/or graph 100. In some embodiments, the builder module(s) 204 may be configured to determine edge(s) 104 and/or vertices 102 continuously, in an event-driven manner (for example, in response to receiving event streams comprising relevant raw data from a streaming source or streaming platform), on a periodic or scheduled basis, or on an aperiodic or ad hoc basis.] (ii) the object affiliation relationship is represented as an edge connected between two access object nodes corresponding to the two access object entities, [Vlant, para. 67 discloses Each edge 104 defines a relationship between two vertices 102, for example, that is representative of a fact or state that holds between the two vertices 102. The relationship may be determined from the raw data, or maybe inferred from the raw data based on interactions or transitivity between objects of the raw data, and/or edges 104 and/or vertices 102 in the graph 100. For example, the inferred relationship (or inferred edge) may not be captured in the raw data. The inference may be based, for example, on properties of the two vertices 102 joined or connected by the inferred edge 104 (for example, similarity in name and potentially similarity in other metadata), interactions that have been recorded (in the raw data and/or the graph 100) between the items of information (objects or inferred objects) represented by the specific vertice(s), or logical implications. An example of a logical implication may be knowledge that Org Z and Org Y are related, and that Org Z and Org X are related, and the deduction that based on these relationships it follows that Org Y and Org X are related.] and (iii) the respective role permission is represented as an edge connected between a role node corresponding to the respective role entity and a rule node corresponding to the access permission relationship. [Vlant, para. 73 discloses multiple builder modules 204 may create the same types of vertices and/or edges. Additional builder module(s) 204 may be added on an ad hoc basis as required to facilitate growth of the graph 100. In some embodiments, builder modules 204 may be configured to determine or assemble data for adding or contributing or storing in data storage or data structures, such as a relational databases or non-relational databases or tabular data structure.]
Therefore, it would be obvious to one of ordinary skill within the art before the effective filing date to combine Vlant’s system with McLean’s system, with a motivation for Optimizing the query is to shift the heaviest part of the query out of the query engine in the graph read interface 206B and into the data store or database where the data is stored, such as the data structure 300 of the graph interface module 206, for exions, apps, employees, contacts, business types, partners, interactions such as events or transactions, etc. For example, an interaction may be a financial transaction or an API call to an app. Each vertex 102 may have a plurality of fields, which may be mandatory or optional. Each field may be populated with a property of the vertex 102. [Vlant, para. 256]
As per claim 5, modified McLean teaches the method according to Claim 4, wherein: the rule node in the access control knowledge graph further specifies a type of the access permission relationship; and the type of the access permission relationship comprises at least one of a management permission, a read permission, and a write permission. [McLean, para. 31 discloses the client/customer systems 12 can be in networked/linked communication with a security event management center 13, or other security collection and processing center, including one or more data management centers 14, e.g., as managed by an MSSP. The client/customer networked systems 12 can communicate with the data center 14 through a network 16, such as a public or private network, e.g., a local area network, though client/customer information handling systems 12 also can be in communication with the data center 14 through other suitable lines of communication 18, such as peer to peer file sharing systems, and/or other, suitable wireless, virtual, and/or wired connections. The data center 14 further can include one or more internal networks 20 with a plurality of information handling systems 22, connected thereto. In one embodiment, the information handling systems 22 can comprise several computer(s) and can include a processor 26, and a memory or other suitable storage medium 28. The memory 28 can include a random access memory (RAM), read only memory (ROM), and/or other non-transitory computer readable mediums.]
As per claim 6, modified McLean teaches the method according to Claim 4, wherein: the query result is derived based on an inheritance mode of a connection relationship between a first organization node of the plurality of organization nodes and a first rule node of a plurality of rule nodes; [McLean, para. 6 discloses The search parameters may be directed or limited to include one or more indicators of compromise (“IOCs”) or other suitable information, including but not limited to an IP address, an access time, an access date, an external email address, a country of origin, a traffic type, a communication type, and/or combinations thereof. In addition, while various indicators can be selected for a set or subset of clients/organizations, such indicators generally should not be identifiers for any participating organizations at any established or client selected k-value.] the inheritance mode comprises one of (i) a two-way inheritance mode, which indicates that a connection relationship between the first organization node and the first rule node is inherited by a parent node and a child node of the first organization node, [McLean, para. 48 discloses All other clients have set their anonymity values to 1. As an initial step, a root search request/inquiry is received, including selected search parameters, e.g., as shown in FIG. 4, the search is requesting clients in the data store that have established or tried to establish a connection with a specific IP address, e.g., IP X (at 202). This query generates 2 result sets, “yes” or “no,” and, as the result sets for both answers, each have an aggregated score of 50 (which is greater than the participating client's selected anonymity values 1, 5, and 10), no client data points will be removed or filtered from the result set or cluster of data for this inquiry/search (at 204).] (ii) an upward inheritance mode, which indicates that the connection relationship between the first organization node and the first rule node is inherited solely by the parent node of the first organization node, [McLean, para. 52 discloses the client search request is received and includes search parameters, here asking whether the clients in the client base have established or tried to establish a connection to a specific IP, e.g., IP X. As shown at 304, this resulted in 50 yes and 50 no results; and since the result sets do not have aggregated anonymity score/value below any of the clients' anonymity values, all 100 participating clients' data points or information will be returned in the search results.] (iii) a downward inheritance mode, which indicates that the connection relationship between the first organization node and the first rule node is inherited solely by the child node of the first organization node, [McLean, para. 54 discloses An additional compound or “drill down search” further can be received, for example, to narrow, revise, or filter the overall results to specific geographical regions, e.g., U.S.A. or Europe, tied to the IP address (and/or use thereof) at 310; and, as shown in FIG. 5, since the results from the search include an aggregate anonymity score that is less than the set anonymity values of both client A and client B, e.g., a score of “4” outgoing connections to/from address “IPX” was found, which is less than B's anonymity value of “10” and A's anonymity value of “5,” the security data or information from both client A and client B will be removed from the result set (at 312).] and (iv) a no-inheritance mode, which indicates that the connection relationship between the first organization node and the first rule node is not inherited by the parent node or the child node of the first organization node. [McLean, para. 53 discloses a compound, filtering or “drill down” search request containing parameters on the directionality of connection, e.g., outgoing or incoming, was received. However, in this example, since the aggregate score of the resultant data points was not below either of client A's or client B's selected anonymity values, or any of the other client anonymity values, all client security data points will remain, i.e., no data points will be removed, as shown at 308.]
As per claim 7, modified McLean teaches the method according to Claim 1, wherein the returning a query result based on the query request comprises: generating, based on the query request, one or more graph query statements applicable to the access control knowledge graph; [McLean, para. 8 discloses Upon receipt of a participant search request, a result set or cluster of data will be generated together with an aggregated anonymity score for the result set or cluster of data. Para. 9 discloses If the result set or data cluster includes data points and/or other information from clients whose set anonymity value is greater than the aggregated anonymity value determined for the result set or data cluster, the data and/or other information of such clients will be removed or otherwise filtered out from the result set to generate one or more filtered result sets or data clusters. A new aggregated anonymity score further can be determined for the filtered result sets or data clusters.] and inferring, based on the one or more graph query statements, the access permission of the specific person to the target access object. [McLean, para. 10 discloses When it is determined that the initial or filtered result set or data cluster does not include data or other information from clients with a selected anonymity value greater than the aggregated anonymity score, the result set or data cluster can be displayed or otherwise presented to the client or clients performing the search query or request.]
As per claim 8, modified McLean teaches the method according to Claim 7, wherein: a plurality of entities and relationships for constructing the access control knowledge graph are extracted from external source data; [McLean, para. 8 discloses Upon receipt of a participant search request, a result set or cluster of data will be generated together with an aggregated anonymity score for the result set or cluster of data. Para. 9 discloses If the result set or data cluster includes data points and/or other information from clients whose set anonymity value is greater than the aggregated anonymity value determined for the result set or data cluster, the data and/or other information of such clients will be removed or otherwise filtered out from the result set to generate one or more filtered result sets or data clusters. A new aggregated anonymity score further can be determined for the filtered result sets or data clusters.] and the access control knowledge graph comprises virtual nodes and edges, and the virtual nodes and edges describe a mapping relationship between the plurality of entities and relationship and the external source data. [McLean, para. 13 discloses enables clients of an MSSP, or other data controllers or owners, security analysts, security researchers, security application developers, security incident responders, and/or other authorized entities to perform global aggregated searching of security data aggregated, for example, across a particular client base, such as a client base of an MSSP and/or a threat community, while substantially protecting the anonymity of the individual clients or owners of the data of the aggregated security data store. This system can include memory systems or storage devices configured to receive and store one or more searchable data stores including security data gathered from a plurality of clients of the client base and/or threat community. Such memory or storage can include servers or other suitable information handling system(s) in an MSSP's event/data center, though other memories or storage systems, e.g., cloud based storage, is possible without departing from the scope of the present disclosure. The security data can include security logs, event logs, raw data, etc. gathered from monitoring of, or otherwise received from, one or more networked systems of the plurality of clients.]
Regarding claim 9, modified McLean teaches the method according to Claim 8, but McLean does not teach wherein the returning a query result based on the query request further comprises converting the one or more graph query statements into converted table query statements applicable to a data structure of the external source data; and retrieving, based on the converted table query statements, corresponding table data in the external source data.
However, Vlant does teach wherein the returning a query result based on the query request further comprises converting the one or more graph query statements into converted table query statements applicable to a data structure of the external source data; [Vlant, para. 266 discloses the builder module may be configured to send a query to the read interface 206B of the graph structure 300, and in response to the query, to receive the first dataset. For example, the query may take the form of the modified query “Node A, Node A”, as set out above. Para. 276 discloses read interface 206B provides a response to the read request. The response may comprise a first dataset. The first dataset may comprise a list of target object(s) (or target object identifier(s)) associated with each source object (or source object identifier), and optionally, second objects associated with each target object(s). In some embodiments, the read interface 206B determines, target object identifiers using the target object keys from a second object type vertex table. In some embodiments, the second object type vertex table may be the first object type vertex table. In that case, the source and target objects are objects of the same type.] and retrieving, based on the converted table query statements, corresponding table data in the external source data. [Vlant, para. 278 discloses the read interface 206B provides a response to the read request. The response may comprise the first database. The first dataset may comprise a list of objects of the source object type, and for each object, a set of objects of the target object type associated with each object of the source object type, and optionally, an object of the second object type associated with each object of the set. An example of the output provided by the read interface 206B in response to the modified query is shown above in Table V. In some embodiments, the read interface 206B may provide the response to the one or more service modules 208, such as the app recommendation module 420, the business register module 422, and/or the correlation module 426. In some embodiments, the response is in the form of a nested list, such as a triple nested list. For example, the triple nested list may comprise a first set of objects of a source object type (e.g. a set of apps), and for each object of the source object type, a set of objects of a second object type ((e.g. a set of orgs), and for each of the set of objects of the second object type, a second set of objects of the target object type (e.g. a set of apps).]
Therefore, it would be obvious to one of ordinary skill within the art before the effective filing date to combine Vlant’s system with McLean’s system, with a motivation for Optimizing the query is to shift the heaviest part of the query out of the query engine in the graph read interface 206B and into the data store or database where the data is stored, such as the data structure 300 of the graph interface module 206, for exions, apps, employees, contacts, business types, partners, interactions such as events or transactions, etc. For example, an interaction may be a financial transaction or an API call to an app. Each vertex 102 may have a plurality of fields, which may be mandatory or optional. Each field may be populated with a property of the vertex 102. [Vlant, para. 256]
As per claim 10, modified McLean teaches the method according to Claim 1, further comprising: controlling, based on the query result, access of the specific person to the target access object. [McLean, para. 3 discloses clients or customers of a client group, can be provided or enabled with searchable access to one or more databases or data stores including specific security related data or information gathered from a larger group of clients of the client base, for example, security data compiled or aggregated by an MSSP serving the client base. Other suitable, authorized entities also may be permitted to have searchable access to such collected data stores, e.g., authorized third party technology partners or other data controllers or owners, security analysts, security researchers, security application developers, security incident responders, and/or various other suitable entities, without departing from the scope of the present disclosure]
Regarding claim 11, it recites features similar to features within claim 1, therefore, it is rejected in similar manner.
As per claim 12, modified McLean teaches the method according to Claim 11, wherein the method is for an access control side, and the query result is obtained at a query side by the inferences using the access control knowledge graph based on the query request. [McLean, para. 10 discloses When it is determined that the initial or filtered result set or data cluster does not include data or other information from clients with a selected anonymity value greater than the aggregated anonymity score, the result set or data cluster can be displayed or otherwise presented to the client or clients performing the search query or request.]
Regarding claims 13 – 17, they recite features similar to features within claims 2 – 6, therefore, they are rejected in similar manner.
Regarding claim 18, it recites features similar to features within claim 8, therefore, it is rejected in similar manner.
Regarding claims 19 – 20, they recite features similar to features within claim 1, therefore, they are rejected in similar manner.
Conclusion
Pertinent prior art made of record, however, not relied upon:
US 20220239662 A1 to Conkle et al.
“A computing support system is configured to programmatically manage support access to a computing system via a support technician console across multiple levels of support access. The system receives a request to authenticate a user requesting support for the computing system, issues one or more authentication challenges to the user to authenticate the identity of the user, receives one or more corresponding authentication challenge responses from the user based on the authentication challenge, and verifies a level of authentication based on the authentication challenge response, the level of authentication being selected from multiple levels of authentication. The system also determines a level of support access to the computing system based on the verified level of authentication and the identity of the user and programmatically enforces limits on the support access to the computing system via the support technician console based on the determined level of support access.”
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Phuc Pham whose telephone number is (571)272-8893. The examiner can normally be reached Monday - Thursday 7:30 AM - 4:30 PM; Friday 8:00 AM - 12:00 PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Linglan Edwards can be reached at (571) 270-5440. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/P.P./Patent Examiner, Art Unit 2408
/LINGLAN EDWARDS/Supervisory Patent Examiner, Art Unit 2408