DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1-9 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claim 1 recites the limitation "the computing service requesting the data". There is insufficient antecedent basis for this limitation in the claim. The claim later recites the limitation, “the encryption key is not shared by the data management service with other computing services requesting the data”. Prior to these computer services being included in the claim, the only mention of a compute service is, “a data management service of the service provider that handles requests for the data from computing services. This limitation outlines the role of the data management service in handling requests, but does not specifically claim that any specific requests have been received from a first computing service or that there are other computing services requesting the data. This seems to all be passively claimed, and renders the claims unclear and indefinite. Further, when the claim states that, “the encryption key is not shared by the data management service with other computing services requesting the data”, it is unclear if this is meant to teach that it is sharing the key with the first computing service.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-20, as best understood, are rejected under 35 U.S.C. 103 as being unpatentable over Ciampaglia et al., USPN 2023/0090611, in view of Baum et al., USPN 2015/0149362.
With regard to claim 1, Ciampaglia discloses a system including a non-transitory memory, and one or more hardware processors coupled to the non-transitory memory and configured to execute instructions to cause the system to (0023) receive a request to remove data associated with an account of a service provider (0034), wherein the request includes at least an account identifier (ID) for the account (0034, 0026), authenticate the request (0081-0082) determine that the data is managed in an encrypted form by a data management service of the service provider that handles requests for the data from computing services (0047, 0075, 0079-0082), wherein the data management service encrypts and decrypts the data at the data management service for the computing service requesting the data (0047), determine the encryption key used for the encrypted form of the data (0043, 0027), wherein the encryption key is required to decrypt the encrypted form of the data (0165), and wherein the encryption key is stored by a data management service associated with a data removal platform handling the request without replication outside of the data management service (0165, 0140, Fig. 9C), and execute a process to erase the encryption key from the data removal platform, wherein the process renders the encrypted form of the data unreadable after the encryption key is erased (0165). Ciampaglia does not disclose that the encryption key is not shared by the data management service with other computing services requesting the data. Baum discloses a system for handling PII requests (0068) and deleting PII keys to effectively render the PII unretrievable (0082-0083), similar to that of Ciampaglia, and further discloses the encryption key is not shared by the data management service with other computing services requesting the data (0064-0068, 0083). It would have been obvious for one of ordinary skill in the art, prior to the instant effective filing date, to not share the encryption keys of Ciampaglia with requesting computing services, as taught by Baum, for the motivation of maintaining security and ensuring that deleting of the keys would effectively render the PII unretrievable, a stated motivation of Ciampaglia (0165, 0140, 0084) and Baum (0082-0083).
With regard to claims 2, 10, 11, and 16, Ciampaglia in view of Baum discloses the system of claim 1, as outlined above, and Ciampaglia further discloses prior to receiving the request, executing the instructions further causes the system to receive a request for a generation of the encryption key for the account at the data management service (0026-0027), wherein the request for the generation is based on at least one of an account enrollment of the account or a data collection of the data including at least one of personally identifiable information (PII) data or sensitive data (0026-0027, 0047), and generate and store the encryption key at the data management service (Fig. 2, 0074, 0081-0083).
With regard to claim 3, Ciampaglia in view of Baum discloses the system of claim 1, as outlined above, and Ciampaglia further discloses the at least one of the PII data or the sensitive data is encrypted using the encryption key (0047), and wherein the account ID is linked to the encryption key across a plurality of computing services that utilize the at least one of the PII data or the sensitive data (0026-0027).
With regard to claim 4, Ciampaglia in view of Baum discloses the system of claim 1, as outlined above, and Ciampaglia further discloses executing the instructions further causes the system to receive the at least one of the PII data or the sensitive data during an activity performed using the account (0026-0027, 0037-0040), and encrypt, at the data management service, the at least one of the PII data or the sensitive data using the encryption key without sharing the encryption key outside of the data management service (0047, 0074, 0081-0083).
With regard to claim 5, Ciampaglia in view of Baum discloses the system of claim 1, as outlined above, and further Ciampaglia discloses the encrypted form of the data is encrypted using the encryption key based on at least one of a data security requirement, a privacy data retention regulation, or a data erasure policy, and wherein the data erasure policy causes the process to be executed in compliance with the data security requirement and the privacy data retention regulation (0041-0043, 0064-0066).
With regard to claims 6, 13, and 17-20, Ciampaglia in view of Baum discloses the system of claim 5, as outlined above, and Ciampaglia further discloses executing the process includes deleting the encryption key from a storage accessible by the data management service (0165, 0140, Fig. 9C), and providing a pseudonymized text for the data identifying that the data has been rendered unreadable, wherein the pseudonymized text includes placeholder values in place of PII data (0066).
With regard to claims 7 and 14, Ciampaglia in view of Baum discloses the system of claim 1, as outlined above, and Ciampaglia further discloses executing the instructions further causes the system to provide a proof of the data being rendered unreadable based on the deleting the encryption key, wherein the proof is provided for at least one of a data retention record or a regulatory compliance (0048, 0071, 0082, 0041-0043, 0064-0066).
With regard to claims 8 and 15, Ciampaglia in view of Baum discloses the system of claim 1, as outlined above, and Ciampaglia further discloses prior to receiving the request, executing the instructions further causes the system to receive a request to access the data from the encrypted form of the data (0081), authorize the request to access the data (0081-0082), decrypt, at the data management service, the encrypted form of the data using the encryption key (0083, 0047, 0070), and provide the data in an unencrypted form in response to the request (0083).
With regard to claim 9, Ciampaglia in view of Baum discloses the system of claim 1, as outlined above, and Ciampaglia further discloses decrypting the data is performed without sharing the encryption key outside of the data management service including without providing the encryption key to a requestor of the request to access the data (0081-0083), and wherein the request is received from a computing service corresponding to the requestor using an integration between the computing service and the data management service that authorized the computing service for access to the unencrypted form of the data (0081-0083).
With regard to claim 12, Ciampaglia in view of Baum discloses the system of claim 1, as outlined above, and Ciampaglia further discloses the encrypted data is stored by a plurality of databases of the service provider, and wherein the data management service manages decryptions of the encrypted data from the plurality of databases (Fig. 2, 0096, 0053).
Response to Arguments
Applicant’s arguments, filed 26 May 2026, have been fully considered and are persuasive. Therefore, the prior rejection has been withdrawn. However, upon further consideration, a new grounds of rejection is made, as outlined above.
References Cited
Norcross et al., USPN 2023/0359759, discloses a system where PII keys are locally stored and no accessible to requesting devices (0044, 0061).
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to JACOB LIPMAN whose telephone number is (571)272-3837. The examiner can normally be reached 5:30AM-6:00PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Ali Shayanfar can be reached at 571-270-1050. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/JACOB LIPMAN/Primary Examiner, Art Unit 2434