DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claims 1-20 have been examined.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 11/10/25 is being considered by the examiner.
Claim Interpretation
The following is a quotation of 35 U.S.C. 112(f):
(f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof.
The following is a quotation of pre-AIA 35 U.S.C. 112, sixth paragraph:
An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof.
The claims in this application are given their broadest reasonable interpretation using the plain meaning of the claim language in light of the specification as it would be understood by one of ordinary skill in the art. The broadest reasonable interpretation of a claim element (also commonly referred to as a claim limitation) is limited by the description in the specification when 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is invoked.
As explained in MPEP § 2181, subsection I, claim limitations that meet the following three-prong test will be interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph:
(A) the claim limitation uses the term “means” or “step” or a term used as a substitute for “means” that is a generic placeholder (also called a nonce term or a non-structural term having no specific structural meaning) for performing the claimed function;
(B) the term “means” or “step” or the generic placeholder is modified by functional language, typically, but not always linked by the transition word “for” (e.g., “means for”) or another linking word or phrase, such as “configured to” or “so that”; and
(C) the term “means” or “step” or the generic placeholder is not modified by sufficient structure, material, or acts for performing the claimed function.
Use of the word “means” (or “step”) in a claim with functional language creates a rebuttable presumption that the claim limitation is to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites sufficient structure, material, or acts to entirely perform the recited function.
Absence of the word “means” (or “step”) in a claim creates a rebuttable presumption that the claim limitation is not to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is not interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites function without reciting sufficient structure, material or acts to entirely perform the recited function.
Claim limitations in this application that use the word “means” (or “step”) are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. Conversely, claim limitations in this application that do not use the word “means” (or “step”) are not being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action.
Regarding claim 19, it uses the phrases (i) means to access, (ii) means to generate, and (iii) means to configure each invoke 112(f) claim interpretation [prong 1 and prong 2: “mean to”]. Each of these phrases do not recite structure that can perform those functions [prong 3]. The specification defines a processor of a computing device and machine readable instructions as the equivalent structure and algorithm that performs these functions as represented in Fig. 4.
See also [0052] Fig. 4 depicts process 400 in accordance with embodiments of the present disclosure. In one embodiment, process 400 is embodied as machine-readable instructions that, when read by a machine, such as at least one processor of a computing device (e.g., rule generator 112 and/or security analysis component 116) causes the machine to perform the steps of process 400.
Thus, in the light of the specification, the means to access, generate, and configure are supported by the generic processor of computing device as embodied in paragraph 0052 and perform the algorithm depicted in Fig. 4. Therefore the limitations of claim 19 are fully supported by Applicant’s specification.
Claim Rejections - 35 USC § 112
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112:
The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention.
Claims 1-20 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. Claims 1, 10 and 19 recite “in response to receiving a request for a requested datum of the set of data, the security analysis component selectively returns or declines the requested datum in accordance with evaluating the requested datum with the set of rules.” However, the Specification provides support for evaluating application to determine if application complies with requirement, and output result of the evaluation (Specification: [0050]-[0052]). The Specification does not describe selectively returns or declines the requested datum in accordance with evaluating the requested datum with the set of rules. Therefore, the claims will be examined based on providing result of evaluation based on the set of rules.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13.
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer.
Claims 1-20 rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-19 of U.S. Patent No. 12,259,983. Although the claims at issue are not identical, they are not patentably distinct from each other because present application and related patent both disclose system/method for automatically training a security analysis component to evaluate an application under test (AUT) for compliance with a security context. See comparison of exemplary claims below.
Instant Application
U.S. 12,259,983
1. A system for automatically training a security analysis component to evaluate an application under test (AUT) for compliance with a security context, comprising:
at least one processor of a number of processors that accesses instructions maintained in a non-transitory memory, that, when executed by the at least one processor of the number of processors, cause the at least one processor of the number of processors to:
access the security context defining protected data, the protected data comprising one or more datum of a set of data;
generate a set of rules defining risks to the protected data, wherein the risks comprise usages of the protected data;
configure the security analysis component with the set of rules for testing the AUT for compliance with the security context; and
in response to receiving a request for a requested datum of the set of data, the security analysis component selectively returns or declines the requested datum in accordance with evaluating the requested datum with the set of rules.
1. A system for automatically training a security analysis component to evaluate an application under test (AUT) for compliance with a security context, comprising:
at least one processor of a number of processors that accesses instructions maintained in a non-transitory memory, that, when executed by the at least one processor of the number of processors, cause the at least one processor of the number of processors to:
access the security context defining protected data, the protected data comprising one or more datum of a set of data;
generate a set of rules defining risks to the protected data, wherein the risks comprise usages of the protected data;
configure the security analysis component with the set of rules for testing the AUT for compliance with the security context; and
in response to receiving a request for a requested datum of the set of data, the security analysis component selectively returns or declines the requested datum in accordance with evaluating the requested datum with the set of rules; and
wherein the security analysis component performs tests on the AUT comprising identifying a call path utilizing the protected data, in accordance with the set of rules, and wherein the call path defines steps in the AUT and the AUT comprises source code; and
wherein the call path that accesses the protected data is marked with a taint flag and wherein the taint flag is assigned to all subsequent manipulations originating from the protected data.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-20 rejected under 35 U.S.C. 103 as being unpatentable over Ranjan et al. US 2021/0334384 (hereinafter Ranjan) in view of Farkash et al. U.S. 2020/0320202 (hereinafter Farkash).
As per claim 1, 10 and 19, Ranjan discloses a system/method for automatically training a security analysis component to evaluate an application under test (AUT) for compliance with a security context, comprising:
at least one processor of a number of processors that accesses instructions maintained in a non-transitory memory, that, when executed by the at least one processor of the number of processors, cause the at least one processor of the number of processors to (Ranjan: [0096]):
access the security context defining protected data, the protected data comprising one or more datum of a set of data (Ranjan: [0022]: analyze various pre-defined data sets/protected data to scan them for pre-defined security leak patterns, the predefined data sets can be service logs, call stack traces, or API responses based on different security contexts);
generate a set of rules defining risks to the protected data, wherein the risks comprise usages of the protected data (Ranjan: [0023]-[0029]: pre-defined rules to detect data leaks for different protected data; [0036]: risk associated with usage of data including data leakage);
configure the security analysis component with the set of rules for testing the AUT for compliance with the security context (Ranjan: [0023]-[0029]: determine compliance with security context); and
output result of the testing (Ranjan: [0072]).
Ranjan does not explicitly disclose in response to receiving a request for a requested datum of the set of data, the security analysis component selectively returns or declines the requested datum in accordance with evaluating the requested datum with the set of rules. However, Farkash discloses testing privacy policy rules prior to deploying applications, wherein the application enforces rules to ensure compliance (Farkash: [0032]-[0033]: security leak detection system is deployed in the form of microservices to analyze data sets). It would have been obvious to one having ordinary skill in the art that applications that are subject to testing/evaluation based on pre-defined security rules will output compliant data when deployed as well known in the art.
As per claim 2, 11 and 20, Ranjan as modified discloses the limitations of claims 1, 10 and 19 respectively. Ranjan further discloses wherein at least one rule of the set of rules defines a risk comprising one or more of reading, writing, or manipulating the protected data (Ranjan: [0023]-[0029]).
As per claim 3 and 12, Ranjan as modified discloses the limitations of claims 1 and 10 respectively. Ranjan further discloses wherein the set of rules define risks to the protected data comprising less than all of the set of rules applicable to the protected data (Ranjan: [0022]-[0029]: pre-defined security rules are applied based on different datasets).
As per claim 4 and 13, Ranjan as modified discloses the limitations of claims 1 and 10 respectively. Ranjan further discloses wherein the set of rules define risks to the protected data comprising less than all of the set of data (Ranjan: [0023]-[0028]: protected data could be associated with API, service logs or call stack traces).
As per claim 5 and 14, Ranjan as modified discloses the limitations of claims 1 and 10 respectively. Ranjan further discloses wherein the set of rules defining risks to the protected data defines risks to the protected data comprising a first set of protected data, determined upon the security context having a first security context value, and the set of rules defining risks to the protected data defines risks to the protected data comprising a second set of protected data, determined upon the security context having a second security context value (Ranjan: [0043]-[0045]: apply different test cases using different input parameters based on context).
As per claim 6 and 15, Ranjan as modified discloses the limitations of claims 1 and 10 respectively. Ranjan further discloses wherein the set of rules defining risks to the protected data is generated to comprise a first set of rules, determined upon the security context having a first security context value, and the set of rules defining risks to the protected data is generated to comprise a second set of rules, determined upon the security context having a second security context value (Ranjan: [0043]-[0045]: apply different test cases using different input parameters based on context).
As per claim 7 and 16, Ranjan as modified discloses the system of claim 1. Ranjan as modified further discloses wherein the security context comprises one or more requirements of the Health Information Portability Act (HIPAA) (Farkash: [0032]-[0033]). It would have been obvious to one having ordinary skill in the art to prevent sensitive/personal leakage to ensure compliance with privacy rules, such as HIPAA, as well known in the art.
As per claim 8 and 17, Ranjan discloses the limitations of claims 1 and 10 respectively. Ranjan further discloses wherein the security context comprises one or more requirements associated with data records comprising both sensitive data and non-sensitive data (Ranjan: [0022]-[0029]; Farkash: [0032]-[0033]).
As per claim 9, Ranjan discloses the system of claim 1. Ranjan further discloses wherein the security analysis component performs tests on the AUT comprising testing the AUT, and wherein the AUT is embodied as executable machine code, for at least one of inputs or outputs of the protected data in accordance with the set of rules (Ranjan: [0022]-[0029]: microservices).
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Sun et al. U.S. 11,354,433 discloses dynamic taint tracking on mobile devices.
Vantrease et al. U.S. 11,275,661 discloses test generation of a distributed system.
Glowa et al. U.S. 2022/0075710 discloses method for improved unit test creation.
Bae et al. U.S. 2021/0232377 discloses encoding dependencies in call graphs.
Xiang et al. U.S. 2021/0034754 discloses security testing based on user request.
McFall et al. U.S. 2020/0327252 discloses method privacy engineering method.
Zheng et al. U.S. 10,565,377 discloses context-based analysis of application.
Slivkins et al. U.S. 2018/0101473 discloses application testing to ensure data privacy.
Muthurajan et al. U.S. 20170220804 discloses method for determining protective measure for data that meets criteria.
Finger et al. U.S. 2017/0220458 discloses orchestrating and providing a regression test.
Chestna U.S. 2015/0143524 discloses method for implementing application policies among development environments.
Scholte U.S. 2014/0020093 discloses preserving web document integrity ghrough web template learning.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SHIN HON (ERIC) CHEN whose telephone number is (571)272-3789. The examiner can normally be reached Monday to Thursday 9am- 7pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn Feild can be reached at 571-272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/SHIN-HON (ERIC) CHEN/ Primary Examiner, Art Unit 2431