DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
The following is a Final Office action in response to communications received on 07/23/2026.
Response to Amendment
Claims 1, 8, 9, 16, and 17 have been amended.
Claims 1-20 have been examined.
Applicant’s arguments with respect to claims 1, 9, and 17 regarding the new limitations: “the determining being based on at least one of an export-authorization indicator stored in association with the first data and specifying that user authorization is required to export the first data, a data type of the first data being designated as unauthorized to be exported, the first data being stored in a storage location designated for restricted data, or a source application that provided the first data being identified as providing data that is unauthorized to be exported”, have been considered but are moot in view of the new ground of rejection presented in the current office action.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13.
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer.
Claims 1-20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-20 of U.S. Patent No. 12216782 in view of US 20200125775 to Nagpal et al (hereinafter Nagpal).
Instant application
U.S. Patent No. 12216782
1. A method, comprising: receiving, by a computing device, a request to execute instructions generated responsive to one or more user inputs to an application at the computing device, the one or more user inputs defining a user compilation of actions that include an internal action and an export action;
responsive to receiving the request, executing the instructions within an execution space for the instructions at the computing device by: determining, within the execution space, that first data stored in local storage at the computing device comprises private data, the determining being based on at least one of an export-authorization indicator stored in association with the first data and specifying that user authorization is required to export the first data, a data type of the first data being designated as unauthorized to be exported, the first data being stored in a storage location designated for restricted data, or a source application that provided the first data being identified as providing data that is unauthorized to be exported;
importing the first data to the execution space from the local storage without outputting a user prompt for authorization;
performing the internal action on the first data within the execution space without outputting a user prompt for authorization;
after performing the internal action on the first data and before performing the export action,
outputting a request for user authorization to export second data associated with the first data from the execution space; and
responsive to receiving the user authorization, performing the export action at least in part by exporting the second data from the execution space.
2. (Original) The method of claim 1, wherein exporting the second data from the execution space comprises exporting the second data from the execution space to local memory at the computing device, the local memory accessible by one or more applications other than the application that generated the instructions.
6. (Original) The method of claim 1, further comprising: executing a subsequent iteration of the instructions, including executing a subsequent iteration of the export action based on the user authorization and without requesting an additional user authorization; receiving a change to the internal action; executing a further subsequent iteration of the instructions including the changed internal action; and prior to completing a further subsequent iteration of the export action, preventing exportation of third data, generated using the changed internal action, without the additional user authorization.
17. (Original) An electronic device, comprising: memory; and one or more processors, wherein the one or more processors are configured to: receive a request to execute additional instructions that have been generated responsive to one or more user inputs to an application at the electronic device, the one or more user inputs defining a user compilation of actions that include an internal action and an export action;
responsive to receiving the request, execute the additional instructions within an execution space for the additional instructions at the electronic device by: determining, within the execution space, that first data stored in local storage at the electronic device comprises private data, , the determining being based on at least one of an export-authorization indicator stored in association with the first data and specifying that user authorization is required to export the first data, a data type of the first data being designated as unauthorized to be exported, the first data being stored in a storage location designated for restricted data, or a source application that provided the first data being identified as providing data that is unauthorized to be exported;
importing the first data to the execution space from the local storage without outputting a user prompt for authorization; performing the internal action on the first data within the execution space without outputting a user prompt for authorization; after performing the internal action on the first data and before performing the export action, outputting a request for user authorization to export second data associated with the first data from the execution space; and
responsive to receiving the user authorization, performing the export action at least in part by exporting the second data from the execution space.
1. A method, comprising: receiving, by a computing device, a request to execute a script by a first application, wherein the script includes: a first instruction to obtain first data, and a second instruction to export second data associated with the first data by generating a communication to another computing device using a second application separate from the first application executing the script;
after receiving the request, initiating execution of the script by the first application;
6. The method of claim 1, further comprising executing the first instruction to obtain the first data without requesting user authorization.
2. The method of claim 1, wherein the script includes a third instruction to perform at least one internal action on the first data prior to executing the second instruction, the method further comprising tracking the first data through the at least one internal action.
Claim 1: accordance with a determination that the first data meets a set of one or more criteria, identifying the first data as unauthorized to be exported; and after executing the first instruction and before completing the second instruction, preventing, based on identifying the first data as unauthorized to be exported, exportation of the second data without user authorization.
4. The method of claim 1, further comprising: receiving the user authorization for the exportation of the second data; executing the second instruction for the exportation of the second data based on the user authorization;
3. The method of claim 1, wherein the exportation of the second data includes storing information associated with the first data in memory of the computing device that is accessible by a process at the computing device that is separate from the script.
4. The method of claim 1, further comprising: … executing a subsequent iteration of the script, including executing a subsequent iteration of the second instruction to export the second data without requesting an additional user authorization; receiving a change to an internal action of the script; executing a further subsequent iteration of the script including the changed internal action; and prior to completing a further subsequent iteration of the second instruction for the further subsequent iteration of the script, preventing exportation of third data, generated using the changed internal action, without user authorization.
14. An electronic device, comprising: memory; and one or more processors, wherein the one or more processors are configured to: receive a request to execute a script by a first application, wherein the script includes: a first instruction to obtain first data, and a second instruction to export second data associated with the first data by generating a communication to another computing device using a second application separate from the first application executing the script; after receiving the request, initiate execution of the script by the first application; in accordance with a determination that the first data meets a set of one or more criteria, identify the first data as unauthorized to be exported; and
15. The electronic device of claim 14, wherein the one or more processors are further configured to execute the first instruction to obtain the first data without requesting user authorization.
19. The electronic device of claim 14, wherein the one or more processors are further configured to: receive the user authorization for the exportation of the second data; execute the second instruction for the exportation of the second data based on the user authorization;
Claim 1: after executing the first instruction and before completing the second instruction, prevent, based on identifying the first data as unauthorized to be exported, exportation of the second data without user authorization.
U.S. Patent No. 12216782 does not teach: determining, within the execution space, that first data stored in local storage at the computing device comprises private data, the determining being based on at least one of an export-authorization indicator stored in association with the first data and specifying that user authorization is required to export the first data, a data type of the first data being designated as unauthorized to be exported, the first data being stored in a storage location designated for restricted data, or a source application that provided the first data being identified as providing data that is unauthorized to be exported. However, Nagpal teaches:
determining, within the execution space, that first data stored in local storage at the computing device comprises private data, the determining being based on at least one of an export-authorization indicator stored in association with the first data and specifying that user authorization is required to export the first data, a data type of the first data being designated as unauthorized to be exported, the first data being stored in a storage location designated for restricted data, or a source application that provided the first data being identified as providing data that is unauthorized to be exported (Nagpal: [0030] At step 306, the data loss prevention engine 104 determines whether any restricted text is present in the data 103. The data loss prevention engine 104 may access the data 103 and determine that the content of the data 103 contains text. The data loss prevention engine 104 determines a text type for the identified text. Examples of text types may include, but are not limited to, personal information, product information, client information, information technology information, confidential information, financial information, network configuration information, account information, general information, addresses, or any other class of text. The data loss prevention engine 104 compares the determined text type to a set of restricted text types to determine whether the determine whether the text type matches any of the restricted text types. [0036] At step 314, the data loss prevention engine 104 blocks the transmission of the data 103 to the target network device 106. In another embodiment, blocking the transmission of the data 103 comprises rerouting the data 103. As another example, the data loss prevention engine 104 may reroute the data 103 to an administrative group for approval before forwarding the data 103 to the target network device 106).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to employ the teachings of Nagpal in the invention of Friedman to include the above limitations. The motivation to do so would be to detect and block instances of data exfiltration which improves the network bandwidth utilization by preventing unauthorized data from leaving the network that would otherwise consume network resources (Nagpal: [0006]).
Claim Rejections - 35 USC § 112
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112:
The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention.
Claims 1, 9, and 17 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. Claims 1, 9, and 17 recite: “an export-authorization indicator stored in association with the first data and specifying that user authorization is required to export the first data”. The applicant cited paragraph [0032] of the specification of the instant application in support of this limitation. Paragraph [0032] states: “Identifying the data as unauthorized to be exported may include detecting a privacy flag or other privacy indicator stored in associated with the data, identifying the data as having a data type that is unauthorized to be exported, …”. The paragraph supports an export-authorization indicator in the form of a privacy flag or other indicator but does not state that the privacy flag or other indicator specifies that a user authorization is required to export the data. The examiner has found no support for an export-authorization indicator specifying that user authorization is required to export the first data in the specification of the instant application.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The text of those sections of Title 35, U.S. Code not included in this action can be found in a prior Office action.
Claims 1-5, 8-10, 12, 13, and 16-20 are rejected under 35 U.S.C. 103 as being unpatentable over prior art of record US 8181260 to Friedman et al (hereinafter Friedman) and US 20200125775 to Nagpal et al (hereinafter Nagpal).
As per claims 1, 9, and 17, Friedman teaches:
A method, comprising:
receiving, by a computing device, a request to execute instructions generated responsive to one or more user inputs to an application at the computing device, the one or more user inputs defining a user compilation of actions that include an internal action and an export action (Friedman: column 8, lines 16-43: More specifically, for all script operations (user compilation of actions) that have both an input and an output, any origin tags existing in the data structures of the former will be transferred by the tag propagator component 270 of the scripting engine 240 to the corresponding data structures of the latter. For example, the JavaScript String.subString( ) method is an operation that takes a string of text as input and produces a shorter string of text as output. A script would continue to demand a series of operations exactly as it would in a scripting engine that does not implement this invention, but with origin tags being generated 350 and then propagated 360 transparently to the user and script-programmer, i.e., the script is a set of instructions generated based on inputs from the script-programmer);
responsive to receiving the request, executing the instructions within an execution space for the instructions at the computing device by: determining, within the execution space, that first data stored in local storage at the computing device comprises private data (Friedman: column 2, lines 62-65: controlling transmission of sensitive data. Column 8, lines 52-65: In this particular embodiment, the above-described propagation makes use of four increasingly restrictive origin-tag types. LOCAL: The item was entered by the user, or loaded from a local file. Column 8, lines 30-48: The HTTP client then calls its script interpreter 250. Before executing each script instruction, the script interpreter extracts 410 the set of tags associated with input data elements and passes them to the tag propagator 270. The tag propagator then applies a set of rules to determine a suitable tag for the scripting operation's outputs. If new data elements are entered by the user or are loaded from a local file, these inputs will be treated as having tag type LOCAL, in which case the outputs of the scripting engine's processing will also have an associated tag type LOCAL);
importing the first data to the execution space from the local storage without outputting a user prompt for authorization (Friedman: column 8, lines 16-43: For example, the JavaScript String.subString( ) method is an operation that takes a string of text as input. Column 8, lines 30-48: If new data elements are entered by the user or are loaded from a local file, these inputs will be treated as having tag type LOCAL, i.e., data elements from a local file are imported as inputs without user authorization);
performing the internal action on the first data within the execution space without outputting a user prompt for authorization (Friedman: column 8, lines 16-43: For example, the JavaScript String.subString( ) method is an operation that takes a string of text as input and produces a shorter string of text as output, i.e., an internal action is performed without user authorization the string of text to produce a shorter string of text);
after performing the internal action on the first data and before performing the export action, outputting, based on the determining, a request for user authorization to export second data associated with the first data from the execution space (Friedman: Column 8, lines 30-48: If new data elements are entered by the user or are loaded from a local file, these inputs will be treated as having tag type LOCAL, in which case the outputs of the scripting engine's processing will also have an associated tag type LOCAL. Column 10, lines 48-67: Any scripting operation which is identified as capable of transmitting data is made conditional on the tags of its input data. Column 11, lines 43-52: If some of the data in the engine is sensitive, then the browser may be configured to ask the user before transmitting "LOCAL" information); and
responsive to receiving the user authorization, performing the export action at least in part by exporting the second data from the execution space (Friedman: Column 11, lines 43-52: If some of the data in the engine is sensitive, then the browser may be configured to ask the user before transmitting "LOCAL" information. In many cases, data entered by the user will have been combined, through normal processing, with ORIGIN-tagged data before it is transmitted).
Friedman teaches determining sensitive data type but does not teach: the determining being based on at least one of an export-authorization indicator stored in association with the first data and specifying that user authorization is required to export the first data, a data type of the first data being designated as unauthorized to be exported, the first data being stored in a storage location designated for restricted data, or a source application that provided the first data being identified as providing data that is unauthorized to be exported. However, Nagpal teaches:
the determining being based on at least one of an export-authorization indicator stored in association with the first data and specifying that user authorization is required to export the first data, a data type of the first data being designated as unauthorized to be exported, the first data being stored in a storage location designated for restricted data, or a source application that provided the first data being identified as providing data that is unauthorized to be exported (Nagpal: [0030] At step 306, the data loss prevention engine 104 determines whether any restricted text is present in the data 103. The data loss prevention engine 104 may access the data 103 and determine that the content of the data 103 contains text. The data loss prevention engine 104 determines a text type for the identified text. Examples of text types may include, but are not limited to, personal information, product information, client information, information technology information, confidential information, financial information, network configuration information, account information, general information, addresses, or any other class of text. The data loss prevention engine 104 compares the determined text type to a set of restricted text types to determine whether the determine whether the text type matches any of the restricted text types. [0036] At step 314, the data loss prevention engine 104 blocks the transmission of the data 103 to the target network device 106. In another embodiment, blocking the transmission of the data 103 comprises rerouting the data 103. As another example, the data loss prevention engine 104 may reroute the data 103 to an administrative group for approval before forwarding the data 103 to the target network device 106).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to employ the teachings of Nagpal in the invention of Friedman to include the above limitations. The motivation to do so would be to detect and block instances of data exfiltration which improves the network bandwidth utilization by preventing unauthorized data from leaving the network that would otherwise consume network resources (Nagpal: [0006]).
As per claims 2, 10, and 18, Friedman in view of Nagpal teaches:
The method of claim 1, wherein exporting the second data from the execution space comprises exporting the second data from the execution space to local memory at the computing device, the local memory accessible by one or more applications other than the application that generated the instructions (Friedman: column 3, lines 4-15: the first data element and any data elements generated from the first data element are prevented from being transmitted to any origin other than the origin of the first data element. Column 8, lines 30-48: If new data elements are entered by the user or are loaded from a local file, these inputs will be treated as having tag type LOCAL, in which case the outputs of the scripting engine's processing will also have an associated tag type LOCAL, i.e., the data loaded from the local file is only allowed to be transmitted to the local file. It was well known to one of ordinary skill in the art that local files are stored in a local memory of a computing device which is also accessible by other applications of the computing device that includes the local memory).
As per claims 3 and 19, Friedman in view of Nagpal teaches:
The method of claim 2, wherein the local memory is accessible by a clipboard process at the computing device (Friedman: Column 8, lines 30-48: If new data elements are entered by the user or are loaded from a local file, these inputs will be treated as having tag type LOCAL, in which case the outputs of the scripting engine's processing will also have an associated tag type LOCAL. It was well known to one of ordinary skill in the art that local files are stored in a local memory of a computing device and that the local memory is accessible by the clipboard process).
As per claims 4, 12, and 20, Friedman in view of Nagpal teaches:
The method of claim 1, wherein the second data comprises an output of the internal action (Friedman: column 8, lines 16-43: For example, the JavaScript String.subString( ) method is an operation that takes a string of text as input and produces a shorter string of text as output).
As per claims 5 and 13, Friedman in view of Nagpal teaches:
The method of claim 1, wherein the second data comprises the first data (Friedman: column 8, lines 16-43: For example, the JavaScript String.subString( ) method is an operation that takes a string of text as input and produces a shorter string of text as output. If this method were used in the scripting engine 240 according to the present invention to extract some text (second data) from a page (first data) obtained securely from "example.com", the extracted text would also be tagged with an origin of "example.com", i.e., the extracted text (second data) comprises information from the page (first data)).
As per claims 8 and 16, Friedman in view of Nagpal teaches:
The method of claim 1, wherein exporting the second data from the execution space comprises exporting the second data from the execution space to another computing device remote from the computing device (Friedman: column 10, lines 49-50: Certain script operations involve the transmission of data from a Web browser to servers elsewhere on the network).
Claims 6, 7, 14, and 15 are rejected under 35 U.S.C. 103 as being unpatentable over Friedman in view of Nagpal as applied to claims 1 and 9 above, and further in view of prior art of record US 20140025949 to Kay et al (hereinafter Kay).
As per claims 6 and 14, Friedman in view of Nagpal does not teach the limitations of claim 6. However, Kay teaches:
further comprising: executing a subsequent iteration of the instructions, including executing a subsequent iteration of the export action based on the user authorization and without requesting an additional user authorization (Kay: [0028] The permissions may be a declaration of the access that is desired by the web application or extension application to user-specific identity information. While the above example illustrates a single permission, multiple permissions may be declared, and granted by the user as part of the installation process for the application. This informs the user about the access that is potentially being requested to specific information during the lifetime of the application while in use in the browser application of a client device controlled by the user. [0044]: For example, a web application may include an "identity" permission in a manifest file, as described in FIG. 3, and may make JAVASCRIPT API calls to access a user's identity information. In some implementations, HTTP response headers may be able to send these user identity details from a remote server, so long as the user has granted the web application appropriate permissions);
receiving a change to the internal action (Kay: [0046] In some instances, a developer of a web application may desire to add additional permissions in order to access other device-side information that was not originally declared at the time the application was installed. This may occur as part of an update to the web application or extension, and may be made available through the store in which the web application or extension was downloaded from through the browser application. [0048]: If more than one version exists of the web application or extension application, a developer can make use of a feature in one version and not in other versions. Optional permissions may be used to include features in one version that are not included in other versions, i.e., an updated version includes a change to an internal action (in the form of extra features) of the web application or extension);
executing a further subsequent iteration of the instructions including the changed internal action; and prior to completing a further subsequent iteration of the export action, preventing exportation of third data, generated using the changed internal action, without the additional user authorization (Kay: [0048]: The optional permissions may only request access on demand following installation of the application at the time when access is requested. The user is given the option to grant or deny the optional permission at the time that it is requested. If the user denies permission, then the permission may not access the desired device-related information. If permission is granted by the user, then the extension or application may access the desired information).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to employ the teachings of Kay in the invention of Friedman in view of Nagpal to include the above limitations. The motivation to do so would be to allow the developer to experiment with the new feature while not causing problems or breaking existing users (Kay: [0048]).
As per claims 7 and 15, Friedman in view of Nagpal and Kay teaches:
The method of claim 6, wherein the third data is generated by the changed internal action based on the first data (Kay: [0044]: Client-side APIs, in conjunction with a secure mechanism such as signature validation, as described in FIG. 5B, may be used by web applications to get user identity details like a name, email, avatar, etc. For example, a web application may include an "identity" permission in a manifest file, as described in FIG. 3, and may make JAVASCRIPT API calls to access a user's identity information. In some implementations, HTTP response headers may be able to send these user identity details from a remote server, so long as the user has granted the web application appropriate permissions. Converting the user identity details (first data) into a suitable format (third data) to transfer to a remote server was well known to one of ordinary skill in the art before the effective filing date of the claimed invention).
The examiner presents the same rationale combine prior arts Friedman in view of Nagpal and Kay as in claim 6 above.
Claim 11 is rejected under 35 U.S.C. 103 as being unpatentable over Friedman in view of Nagpal as applied to claim 10 above, and further in view of prior art of record JP2011022856A to Otake et al (hereinafter Otake).
Examiner’s Note: The examiner used an English translation of Otake which was provided in the previous office action.
As per claims 11, Friedman in view of Nagpal does not teach the limitations of claim 11. However, Otake teaches:
wherein exporting the second data from the execution space to the local memory at the computing device comprises copying the second data to a clipboard at the computing device (Otake: [0004]: One way to transfer data between web applications using a web browser is, for example, by having JavaScript in a web page monitor changes in the clipboard caused by a copy operation performed on another web application. [0050]: Furthermore, on the browser side, the copy process is executed after the call to the copyPasteMashup_onKeyDown function is completed, and the data within the range specified by the user is stored in the clipboard).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to employ the teachings of Otake in the invention of Friedman in view of Nagpal to include the above limitations. The motivation to do so would be to facilitate the exchange of data between web applications (Otake: [0007]).
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to MADHURI R HERZOG whose telephone number is (571)270-3359. The examiner can normally be reached 8:30AM-4:30PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Taghi Arani can be reached at (571)272-3787. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
MADHURI R. HERZOG
Primary Examiner
Art Unit 2438
/MADHURI R HERZOG/Primary Examiner, Art Unit 2438