DETAILED ACTION
Response to Amendment
1. The amendment filed on 4/16/2026 has been entered. Claims 1, 6, 8, 13, 15 and 20 have been amended. No new claims have been added or cancelled. Accordingly, claims 1-20 are pending in this office action.
Notice of Pre-AIA or AIA Status
2. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
3. Applicant’s arguments with respect to claim(s) 1-20 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. However based on the amendments the double patenting rejection has been withdrawn.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
4. Claim(s) 1, 4, 5, 7 8, 11, 12, 14, 15, 18 and 19 is/are rejected under 35 U.S.C. 103 as being unpatentable over US 2012/0311674 (Hockings) in view of Zero Trust Architecture (hereinafter Rose) (Art of record).
As for claim 1 Hockings discloses: A system that comprises: a processor; and a memory that stores program instructions executable to cause the processor to: (See paragraphs 0029-0035) receive at a database server, an external access policy from a central policy storage (See paragraphs 0041-0045, note the users access the external systems or applications through the portal which authenticates users and prevents unauthorized use of resources based on the security policy further See paragraphs 0006, and 0049-0053 note the authorization server includes a cache that stores authorization policies and the decision engine determines which policy to apply, if the policy is successful the new directive is stored at the authorization server for reuse); responsive to receiving, from a user device, a resource access request to access to a resource of the database server, determine an access condition by evaluating at least on the external access policy received from the central policy storage and an internal access policy stored locally at the database server (See paragraphs 0053-0057 note step 1 is to receive a request, all other actions are conducted in response to the received request including further note step 3 does an internal cache check for an access decision and if one does exist if not external authorization occurs this is an evaluation at least on the external and the stored internal); and provide, to the user device, access to the resource based at least on the access condition being met. (See paragraphs 0055-0060 note data can be returned to the user directly based on the internal caching and external authorization which directs the internal decision).
While Hockings discloses using access policies (See above) Hockings does not explicitly disclose: determine that the access condition is met based on evaluation of the external access policy and the internal access policy wherein the external access policy and the internal access policy permit access. Rose, however discloses: determine that the access condition is met based on evaluation of the external access policy and the internal access policy wherein the external access policy and the internal access policy permit access (See page 19 note the threat evaluation can be based on an external service of an internal scan, both of which determine access and threats). It would have been obvious to an artisan of ordinary skill in the pertinent at the time the instantly claimed invention was filed to have incorporated the teaching of Rose into the system of Hockings. The modification would have been obvious because the two references are concerned with the solution to problem of data security management, therefore there is an implicit motivation to combine these references (i.e. motivation from the references themselves). In other words, the ordinary skilled artisan, during his/her quest for a solution to the cited problem, would look to the cited references at the time the invention was made. Consequently, the ordinary skilled artisan would have been motivated to combine the cited references since Rose’s teaching would enable users of the Hocking system to have more efficient processing.
As for claim 4 the rejection of claim 1 is incorporated and further Hockings discloses: wherein the external access policy comprise a granular access policy for at least one of: the database server; a database; a database schema; a database table; a column of data; a database object; or a database-related operation. (See paragraphs 0044 and 0082 note the system uses granular access at the database object level).
As for claim 5 the rejection of claim 1 is incorporated and further Hockings discloses: wherein the program instructions are executed to further cause the processor to: store the external access policy and the internal access policy in a hierarchical data structure of the database server, the hierarchical data structure comprising a plurality of nodes, each node comprising a Boolean expression (See paragraph 0066 note the system combines the policies using a Boolean expression to determine authorization).
As for claim 7 the rejection of claim 1 is incorporated and further Hockings discloses: wherein the program instructions, wherein, to store the external access policy and the internal access policy, the program instructions are executed to cause the processor to: store the external access policy and the internal access policy in a cache of the database server. (See paragraphs 0049-0057 note the policies are cached and made available for reuse from storage, first the system checks the internal cache for stored policies and then the decision engine makes the decision).
Claims 8, 11, 12 and 14 are method claims substantially corresponding to the system of claims 1, 4, 5, and 7 and are thus rejected for the same reasons as set forth in the rejection of claims 1, 4, 5, and 7.
Claims 15, 18 and 19 are computer readable medium claims substantially corresponding to the system of claims 1, 4 and 5 and are thus rejected for the same reasons as set forth in the rejection of claims 1, 4 and 5.
5. Claim(s) 2, 3, 6, 9, 10, 13 16, 17 and 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Hockings and Rose as applied to claims 1, 8 and 15 above, and further in view of US 10,719,373 (hereinafter Koponen).
Per claims 2, 9, and 16 the rejection of claims 1, 8, and 15 are incorporated respectively and further Koponen discloses: provide, by the database server, a policy pull request to the central policy storage based on at least one of: a starting or restarting of the database server; a periodicity condition; or a failover condition, wherein the policy pull request specifies provisioning of the external access policy to the database server (See column 9 line 64 – column 10 line 10 note Koponen discloses that a pull request can be sent based on parameters or periodically via the local agent over a network). It would have been obvious to an artisan of ordinary skill in the pertinent at the time the instantly claimed invention was filed to have incorporated the teaching of Koponen into the system of Hockings and Rose. The modification would have been obvious because the three references are concerned with the solution to problem of data management via policies (See Koponen abstract and Hockings abstract), therefore there is an implicit motivation to combine these references (i.e. motivation from the references themselves). In other words, the ordinary skilled artisan, during his/her quest for a solution to the cited problem, would look to the cited references at the time the invention was made. Consequently, the ordinary skilled artisan would have been motivated to combine the cited references since Koponen’s teaching would enable users of the Hockings and Rose system to have more efficient processing of policy information.
Per claims 3, 10, and 17 the rejection of claims 2, 9 and 16 are incorporated respectively and further Koponen discloses: wherein the periodicity condition is based on an amount of time that has elapsed since a policy pull request was provided by the database server (See column 9 line 64 – column 10 line 10 note Koponen discloses that a pull request can be sent based periodically via the local agent over a network). It would have been obvious to an artisan of ordinary skill in the pertinent at the time the instantly claimed invention was filed to have incorporated the teaching of Koponen into the system of Hockings and Rose. The modification would have been obvious because the three references are concerned with the solution to problem of data management via policies (See Koponen abstract and Hockings abstract), therefore there is an implicit motivation to combine these references (i.e. motivation from the references themselves). In other words, the ordinary skilled artisan, during his/her quest for a solution to the cited problem, would look to the cited references at the time the invention was made. Consequently, the ordinary skilled artisan would have been motivated to combine the cited references since Koponen’s teaching would enable users of the Hockings and Rose system to have more efficient processing of policy information.
Per claims 6, 13, and 20 the rejection of claims 5, 12 and 19 are incorporated respectively, and further Koponen discloses: wherein, to determine that the access condition is met based on the external access policy and the internal access policy indicating the grant of access, the program instructions are executed to cause the processor to: recursively iterate over the hierarchical data structure to determine a Boolean value of a root node of the hierarchical data structure (See column 3 line 65-column 4 line 10 and column 30 lines 45-60 note the system will recursively work through the tree to determine which policies should be implemented based on the hash and any flags); and determine that the access condition is met based on the Boolean value of the root node of the hierarchical data structure (See column 22 lines 23-37 note the Boolean flag is used to determine the policy). It would have been obvious to an artisan of ordinary skill in the pertinent at the time the instantly claimed invention was filed to have incorporated the teaching of Koponen into the system of Hockings and Rose. The modification would have been obvious because the three references are concerned with the solution to problem of data management via policies (See Koponen abstract and Hockings abstract), therefore there is an implicit motivation to combine these references (i.e. motivation from the references themselves). In other words, the ordinary skilled artisan, during his/her quest for a solution to the cited problem, would look to the cited references at the time the invention was made. Consequently, the ordinary skilled artisan would have been motivated to combine the cited references since Koponen’s teaching would enable users of the Hockings and Rose system to have more efficient processing of policy information.
Conclusion
Applicant's submission of an information disclosure statement under 37 CFR 1.97(c) with the timing fee set forth in 37 CFR 1.17(p) on 3/30/2026 prompted the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 609.04(b). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to ELIYAH STONE HARPER whose telephone number is (571)272-0759. The examiner can normally be reached on Monday-Friday 10:00 am - 6:00 pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Sanjiv Shah can be reached on (571)270-375098. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/Eliyah S. Harper/Primary Examiner, Art Unit 2166 May 30, 2026