DETAILED ACTION
Response to Amendment
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This is in reply to papers filed on 2025-08-10. Claims 1, 5-8, 12-15, 19-21 are pending, following Applicant's cancellation of claims 2-4, 9-11, 16-18, and addition of new claims 21. Claims 1, 8, 15 is/are independent.
The rejection(s) of claims under 35 U.S.C. § 112 are withdrawn in view of Applicant’s amendments.
The rejection(s) of claims on double patenting grounds are withdrawn in view of Applicant’s amendments.
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a).
Response to Arguments
Applicant's arguments have been fully considered but they are not persuasive.
Applicant’s arguments have been fully considered but are moot in view of the new ground(s) of rejection.
With respect to claim(s) 1 (see page(s) 6-7 of Applicant’s Remarks), Applicant argues that the prior art of record (in particular, U.S. Publication 20090300712 to Kaufmann et al. (hereinafter "Kaufmann '712") in view of U.S. Publication 20170103228 to Yavuz (hereinafter "Yavuz '228")) does not disclose a temporal separation between "receiving an indication of an access to a dataset, the access comprising decrypting an encrypted version of the dataset using a dataset key at a first time" and "encrypting the log using the dataset key at a second time; and storing the encrypted log with the encrypted version of the dataset." However, Kaufmann '712 discloses a user attempting, at a first time, an action on data inside a secure data wrapper (SDW), for which the user must acquire the dataset key by decrypting an encrypted dataset key with a user private key [Kaufmann '712 ¶ 0108, 0103, 0036-0037, 0112, 0118-0119]. Access rules in the SDW must then be enforced to determine whether the user will be permitted to perform the action [Kaufmann '712 ¶ 0106, 0087, 0056-0060]. If the user is authorized, the data content in the SDW must then be decrypted and the action performed [Kaufmann '712 ¶ 0097, 0024, 0071, 0102]. Whether permitted or not, the attempted action must then be logged [Kaufmann '712 ¶ 0106, 0114] and the log stored in the SDW with the encrypted data content [Kaufmann '712 ¶ 0036-0037, 0108, 0106, 0103, 0096] (which data content may have been altered by the action). Given the steps in between, encrypting and storing the updated log must happen at a second time after the initial indication of an access [Kaufmann '712 ¶ 0119, 0114]. Accordingly, Applicant's argument is unpersuasive.
Applicant’s arguments with respect to the remaining claim(s) is/are based on Applicant’s arguments with respect to claim(s) 1 and have been considered as detailed above.
Summary of Claim Rejections under 35 U.S.C. § 103
The following table summarizes the rejections set forth in detail below of the claims over the prior art.
Claim No.
Kaufmann '712 in view of Yavuz '228
1
[Wingdings font/0xFC]
5
[Wingdings font/0xFC]
6
[Wingdings font/0xFC]
7
[Wingdings font/0xFC]
8
[Wingdings font/0xFC]
12
[Wingdings font/0xFC]
13
[Wingdings font/0xFC]
14
[Wingdings font/0xFC]
15
[Wingdings font/0xFC]
19
[Wingdings font/0xFC]
20
[Wingdings font/0xFC]
21
[Wingdings font/0xFC]
Claim Rejections - 35 U.S.C. § 103
The following is a quotation of the appropriate paragraphs of AIA 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale or otherwise available to the public before the effective filing date of the claimed invention.
(a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention.
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of AIA 35 U.S.C. 103 that forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. § 103(a) are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention.
Claim(s) 1-2, 4-9, 11-16, 18-21 is/are rejected under 35 U.S.C. § 103 as being unpatentable over U.S. Publication 20090300712 to Kaufmann et al. (hereinafter "Kaufmann '712") in view of U.S. Publication 20170103228 to Yavuz (hereinafter "Yavuz '228"). Kaufmann '712 is prior art to the claims under 35 U.S.C. § 102(a)(1) and 35 U.S.C. § 102(a)(2). Yavuz '228 is prior art to the claims under 35 U.S.C. § 102(a)(2).
Per claim 1 (independent):
Kaufmann '712 discloses a system comprising one or more processors and memory storing instructions that, when executed by at least one processor of the one or more processors, cause the system to perform operations (processor(s), memory, computer readable media, storage, executable instructions [Kaufmann '712 ¶ 0042, 0064 et seq., 0110])
Kaufmann '712 discloses receiving an indication of an access to a dataset, the access comprising decrypting an encrypted version of the dataset using a dataset key at a first time, the access corresponding to a first role (controls access to data and to logs of actions thereon via cryptography [Kaufmann '712 ¶ 0106, 0087, 0056-0060]; user obtains symmetric SDW key encrypted under user public key [Kaufmann '712 ¶ 0108, 0103, 0036-0037, 0112, 0118-0119]; upon request for an action, opens file, decrypts rules for which actions are permitted by which user, decrypts data file, performs permitted action [Kaufmann '712 ¶ 0113-0114])
Kaufmann '712 does not disclose in response to receiving the indication of the access, generating a log, that records the access to the dataset, and the log comprises different portions having different security parameters or different access privileges
However, Kaufmann '712 discloses in response to receiving the indication of the access, generating a log, that records the access to the dataset, and the log comprises different users/groups having different security parameters or different access privileges (logs authorized actions and unauthorized actions [Kaufmann '712 ¶ 0106, 0114]; log of actions on dataset encrypted with symmetric SDW (secure data wrapper) key [Kaufmann '712 ¶ 0113]; user obtains symmetric SDW key encrypted under user public key [Kaufmann '712 ¶ 0108, 0103, 0036-0037, 0112, 0118-0119]; different users/groups use different user keys to decrypt their encrypted symmetric SDW key [Kaufmann '712 ¶ 0036]; access rights of different users/groups can be restricted individually [Kaufmann '712 ¶ 0097, 0024, 0071, 0102]; user must be on access list and not have been deleted [Kaufmann '712 ¶ 0122])
Kaufmann '712 discloses encrypting the log using the dataset key at a second time (upon closing file, encrypts log of actions in SDW [Kaufmann '712 ¶ 0119, 0114]; dataset encrypted with symmetric SDW (secure data wrapper) key [Kaufmann '712 ¶ 0036-0037, 0108, 0106, 0103, 0096]; log of actions on dataset encrypted with symmetric SDW (secure data wrapper) key [Kaufmann '712 ¶ 0113, 0106])
Kaufmann '712 discloses storing the encrypted log the encrypted version of the dataset (stores the log inside the secure data wrapper (SDW), which is encrypted with the symmetric SDW key [Kaufmann '712 Fig. 2 ref num 280, ¶ 0106])
Further:
Yavuz '228 discloses in response to receiving the indication of the access, generating a log, that records the access to the dataset, and the log comprises different portions having different security parameters or different access privileges (users in group "auditors" have privilege to access some log messages but not others [Yavuz '228 ¶ 0049])
It would have been obvious to a person having ordinary skill in the art (1) before the effective filing date of the claimed invention and (2) before the invention was made to have modified Kaufmann '712 with the differently secured log portions of Yavuz '228 to arrive at an apparatus, method, and product including:
in response to receiving the indication of the access, generating a log, that records the access to the dataset, and the log comprises different portions having different security parameters or different access privileges
A person having ordinary skill in the art would have been motivated to combine them at least because differently secured log portions would grant greater flexibility / granularity is assigning access privileges to users / groups. A person having ordinary skill in the art would have been further motivated to combine them at least because Yavuz '228 teaches [Yavuz '228 ¶ 0049] modifying a log security scheme [Kaufmann '712 ¶ 0106, 0087, 0056-0060] such as that of Kaufmann '712 to arrive at the claimed invention; because Kaufmann '712 and Yavuz '228 are in the same field of endeavor; because doing so constitutes use of a known technique (differently secured log portions [Yavuz '228 ¶ 0049]) to improve similar devices and/or methods (log security scheme [Kaufmann '712 ¶ 0106, 0087, 0056-0060]) in the same way; because doing so constitutes applying a known technique (differently secured log portions [Yavuz '228 ¶ 0049]) to known devices and/or methods (log security scheme [Kaufmann '712 ¶ 0106, 0087, 0056-0060]) ready for improvement to yield predictable results; and because the modification amounts to combining prior art elements according to known methods to yield predictable results. Here, (1) the prior art included each element (as detailed above); (2) one of ordinary skill in the art could have combined the elements as claimed by known methods, and in this combination, each element merely performs the same function as it does separately (security scheme [Kaufmann '712 ¶ 0106, 0087, 0056-0060] protects logs from unauthorized access, with access to particular portions being permitted from certain users / groups but not others [Yavuz '228 ¶ 0049]); (3) one of ordinary skill in the art would have recognized that the results of the combination were predictable; and (4) other considerations do not overcome this conclusion.
Per claim 5 (dependent on claim 2):
Kaufmann '712 in view of Yavuz '228 discloses the elements detailed in the rejection of claim 2 above, incorporated herein by reference
Kaufmann '712 discloses the first access privilege corresponds to a privilege to generate the log and full access privilege to the log, and wherein the second access privilege corresponds to at least a partially restricted access privilege to the log (different users/groups use different user keys to decrypt their encrypted symmetric SDW key [Kaufmann '712 ¶ 0036]; access rights of different users/groups can be restricted individually [Kaufmann '712 ¶ 0097, 0024, 0071, 0102]; user must be on access list and not have been deleted [Kaufmann '712 ¶ 0122])
Per claim 6 (dependent on claim 1):
Kaufmann '712 in view of Yavuz '228 discloses the elements detailed in the rejection of claim 1 above, incorporated herein by reference
Kaufmann '712 does not disclose deactivating the dataset key upon the log being encrypted
Further:
Yavuz '228 discloses deactivating the dataset key upon the log being encrypted (deletes log key from memory after "expiration of a predetermined time period" to prevent misuse by attacker [Yavuz '228 ¶ 0045])
For the reasons detailed above with respect to claim 1, it would have been obvious to a person having ordinary skill in the art (1) before the effective filing date of the claimed invention and (2) before the invention was made to have modified Kaufmann '712 with the differently secured log portions of Yavuz '228 to arrive at an apparatus, method, and product including:
deactivating the dataset key upon the log being encrypted
Per claim 7 (dependent on claim 1):
Kaufmann '712 in view of Yavuz '228 discloses the elements detailed in the rejection of claim 1 above, incorporated herein by reference
Kaufmann '712 does not disclose deactivating the dataset key within a threshold time duration of the log being encrypted
Further:
Yavuz '228 discloses deactivating the dataset key within a threshold time duration of the log being encrypted (deletes log key from memory after "expiration of a predetermined time period" to prevent misuse by attacker [Yavuz '228 ¶ 0045])
For the reasons detailed above with respect to claim 1, it would have been obvious to a person having ordinary skill in the art (1) before the effective filing date of the claimed invention and (2) before the invention was made to have modified Kaufmann '712 with the differently secured log portions of Yavuz '228 to arrive at an apparatus, method, and product including:
deactivating the dataset key within a threshold time duration of the log being encrypted
Per claim 8 (independent):
The remaining limitations of the claim(s) correspond(s) to features of claim(s) 1 and the claim(s) is/are rejected for the reasons detailed with respect to those claims.
Per claim 12 (dependent on claim 9):
Kaufmann '712 in view of Yavuz '228 discloses the elements detailed in the rejection of claim 9 above, incorporated herein by reference
The remaining limitations of the claim(s) correspond(s) to features of claim(s) 5 and the claim(s) is/are rejected for the reasons detailed with respect to those claims.
Per claim 13 (dependent on claim 8):
Kaufmann '712 in view of Yavuz '228 discloses the elements detailed in the rejection of claim 8 above, incorporated herein by reference
The remaining limitations of the claim(s) correspond(s) to features of claim(s) 6 and the claim(s) is/are rejected for the reasons detailed with respect to those claims.
Per claim 14 (dependent on claim 8):
Kaufmann '712 in view of Yavuz '228 discloses the elements detailed in the rejection of claim 8 above, incorporated herein by reference
The remaining limitations of the claim(s) correspond(s) to features of claim(s) 7 and the claim(s) is/are rejected for the reasons detailed with respect to those claims.
Per claim 15 (independent):
The remaining limitations of the claim(s) correspond(s) to features of claim(s) 1 and the claim(s) is/are rejected for the reasons detailed with respect to those claims.
Per claim 19 (dependent on claim 16):
Kaufmann '712 in view of Yavuz '228 discloses the elements detailed in the rejection of claim 16 above, incorporated herein by reference
The remaining limitations of the claim(s) correspond(s) to features of claim(s) 5 and the claim(s) is/are rejected for the reasons detailed with respect to those claims.
Per claim 20 (dependent on claim 15):
Kaufmann '712 in view of Yavuz '228 discloses the elements detailed in the rejection of claim 15 above, incorporated herein by reference
The remaining limitations of the claim(s) correspond(s) to features of claim(s) 6 and the claim(s) is/are rejected for the reasons detailed with respect to those claims.
Per claim 21 (dependent on claim 1):
Kaufmann '712 in view of Yavuz '228 discloses the elements detailed in the rejection of claim 1 above, incorporated herein by reference
Kaufmann '712 discloses receiving a key request for an encrypted dataset key to access the encrypted log, wherein the key request corresponds to a second role, the key request including a second role identifier and a dataset identifier that identifies the dataset corresponding to the encrypted log (user obtains symmetric SDW key encrypted under user public key [Kaufmann '712 ¶ 0108, 0103, 0036-0037, 0112, 0118-0119]; different users/groups use different user keys to decrypt their encrypted symmetric SDW key [Kaufmann '712 ¶ 0036]; access rights of different users/groups can be restricted individually [Kaufmann '712 ¶ 0097, 0024, 0071, 0102])
Kaufmann '712 discloses in response to approving the key request, providing the encrypted dataset key (user obtains symmetric SDW key encrypted under user public key [Kaufmann '712 ¶ 0108, 0103, 0036-0037, 0112, 0118-0119]; user must be on access list and not have been deleted [Kaufmann '712 ¶ 0122])
Kaufmann '712 does not disclose receiving a log request for the encrypted log, the log request comprising the second role identifier and the dataset identifier (logs authorized actions and unauthorized actions [Kaufmann '712 ¶ 0106, 0114]; different users/groups use different user keys to decrypt their encrypted symmetric SDW key [Kaufmann '712 ¶ 0036]; access rights of different users/groups can be restricted individually [Kaufmann '712 ¶ 0097, 0024, 0071, 0102]; user must be on access list and not have been deleted [Kaufmann '712 ¶ 0122])
Kaufmann '712 does not disclose in response to approving the log request, providing the encrypted log
However, Kaufmann '712 discloses in response to approving the access request, adding to the encrypted log (different users/groups use different user keys to decrypt their encrypted symmetric SDW key [Kaufmann '712 ¶ 0036]; access rights of different users/groups can be restricted individually [Kaufmann '712 ¶ 0097, 0024, 0071, 0102]; user must be on access list and not have been deleted [Kaufmann '712 ¶ 0122])
Further:
Yavuz '228 discloses in response to approving the log request, providing the encrypted log (users in group "auditors" have privilege to access some log messages but not others [Yavuz '228 ¶ 0049])
For the reasons detailed above with respect to claim 1, it would have been obvious to a person having ordinary skill in the art (1) before the effective filing date of the claimed invention and (2) before the invention was made to have modified Kaufmann '712 with the differently secured log portions of Yavuz '228 to arrive at an apparatus, method, and product including:
in response to approving the log request, providing the encrypted log
Conclusion
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to THEODORE C PARSONS whose telephone number is (571)270-1475. The examiner can normally be reached on MTWRF 7:30-4:30.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jung Kim can be reached on (571) 272-3804. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from Patent Center. Status information for published applications may be obtained from Patent Center. Status information for unpublished applications is available through Patent Center for authorized users only. Should you have questions about access to Patent Center, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) Form at https://www.uspto.gov/patents/apply/forms.
/THEODORE C PARSONS/Primary Examiner, Art Unit 2494