Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Priority
This is a continuation of International Patent Application No. PCT/CN2023/104524 filed on Jun. 30, 2023, which claims priority to Chinese Patent Application No. 202210972620.6 filed on Aug. 15, 2022 and Chinese Patent Application No. 202310076418. X filed on Feb. 7, 2023, all of which are hereby incorporated by reference in their entireties.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 03/31/2025, 09/29/2025, and 04/14/2025 were filed after the mailing date of the Non-Provisional Patent Application on 02/14/2025. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
DETAILED ACTION
This Office Action is in response to a Non-Provisional Patent Application received on 02/14/2025. Applicant submitted preliminary amendments on 03/25/2025 in which claims 1-20 have been amended. In this application, claims 1-20 have been received for consideration and have been examined.
Specification
Applicant’s submitted specification has been reviewed and found to be in compliance.
Drawings
Applicant’s submitted drawings have been reviewed and found to be in compliance.
Claim Rejections - 35 USC § 101 (Abstract Idea)
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more analyzed according to MPEP 2106.
Step 1: The independent claims 1, 9, and 17 do fall into one of the four statutory categories of “a method”, “a computing device” and “a non-transitory computer-readable storage medium” claims. Nevertheless, the claims still considered as abstract idea (i.e., Mental process - concepts performed in the human mind (including an observation, evaluation, judgment, opinion) for the following prongs and reasons.
Step 2A: Prong 1: The limitations of the independent claims 1, 9, and 17 recite the abstract idea of:
obtaining a first resource control policy that is from an administrator of a target organization and that is for a target [[cloud]] resource in the target organization (Mental process: a human obtains a resource control policy from an administrator of a target organization for a target resource in the target organization),
wherein the first resource control policy indicates a first access permission that is of a first user outside the target organization and that is for the target [[cloud]] resource (Mental process: the resource control policy indicates an access permission being outside the target organization and that is for target resource);
recording the first resource control policy (Mental process: the human notes down/records the resource control policy);
obtaining a first resource access request that is from the first user and that is for accessing the target [[cloud]] resource (Mental process: the human obtains a resource access request from a user for accessing the target resource); and
denying, based on the first resource control policy, the first resource access request (Mental process: the human denies the resource access request from the user based on above determination that access permission being outside the target organization and that is for target resource).
Step 2A: Prong 2: The judicial exception (i.e., target cloud resource) is not integrated into a practical application. In particular, the claims do not recite any additional element to perform beyond routine steps. To show that the involvement of a computer assists in improving the technology, the claims must recite the details regarding how a computer aids the method, the extent to which the computer aids the method, or the significance of a computer to the performance of the method. Merely adding generic computer components to perform the method is not sufficient. Thus, the claim must include more than mere instructions to perform the method on a generic component or machinery to qualify as an improvement to an existing technology (MPEP 2106.5(a) II).
In this particular case, the additional elements of the claim are:
“A method” (claim 1),
“A computing device” (claim 9) and
“A non-transitory computer-readable storage medium” (claim 17).
According to the established Alice v. CLS Bank framework by courts, the claim limitations have been analyzed as follows:
The following claim method steps can be broken down into steps that a human could theoretically do with a pen, a piece of paper, and their own brain.
Obtaining and Recording Policies:
Involves receiving and storing a rule or policy.
Considered a basic mental process or organizational activity of record-keeping.
Obtaining Requests and Denying Access:
Involves evaluating a request against a stored rule and making a binary decision (allow/deny).
Considered a fundamental human concept of applying rules or conditional logic.
Technical Context
Lacks specific technical improvements to computer functioning itself.
Uses generic computer components ("target cloud resource") merely as a tool to perform a conventional business or administrative process.
Because these steps are essentially mere mental processes, analyzing data, and evaluating outcomes, they are viewed as abstract ideas standing alone.
If a claim is abstract, it can still be patented if it adds an "inventive concept"—such as a specific, unconventional way to improve computer technology.
This method uses broad terms like "resource control policy" and "a target cloud resource".
These are generic terms. They simply instruct a computer to perform abstract tasks faster, rather than actually solving a specific technological problem.
Courts have repeatedly ruled that merely applying a mental or business process to a generic computer does not make it eligible for a patent.
The additional elements are recited at a high-level of generality (i.e., as generic terms performing generic computer functions (see instant spec. [0040-0044]) such that it amounts no more than mere instructions to apply the exception using generic computer components. Accordingly, the additional elements do not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. Therefore, the claims are directed to an abstract idea.
Step 2B: The claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the claims do not reflect improvement in the technology. Further, mere automated instructions to apply an exception using a generic computer component cannot provide an inventive concept. Thus, the claims are not patent eligible.
As discussed above with respect to integration of the abstract idea into a practical application, the additional elements identified above amount to no more than mere instructions to apply the exception using general purpose computer.
To support this factual conclusion, the examiner takes Official Notice that one of the ordinary skill in the art, before the effective filing date of the claimed invention, would have found processors and/or software well-known and routine in technology that involves computers (instant spec. [0040-0044] discloses that the functions of the disclosed claims can be implemented using generic computer(s)) such that it amounts no more than mere instructions to apply the exception using generic computer components. Accordingly, the additional elements do not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. Thus, the examiner asserts that the above noted elements, when considered individually or in combination, do not constitute as “significantly more” than the abstract idea.
The dependent claims 2-8, 10-16, and 18-20 of respective independent claims 1, 9, and 17 have been analyzed and fall into one of the statutory categories and therefore passes step 1 analysis. However, under step 2, 2A & 2B analysis, the dependent claims recite mental processes which can be implemented by one or more human users using pen and paper. Thus, dependent claims also recite abstract idea and considered ineligible.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1-5, 7-13, and 15-20 are rejected under 35 U.S.C. 103 as being unpatentable over Cook et al., (US20200366707A1) in view of Aziz et al., (US20210141930A1) and further in view of Lander et al., (US20170331832A1).
Regarding claim 1, Cook discloses:
A method comprising ([0021–0024], [0034] and [0145–0146] discloses methods and systems for administering and evaluating security policies applicable to resources of a cloud computing-resource service provider):
obtaining, a first resource control policy that is from an administrator of a target organization ([0021–0023] discloses that users of a computing-resource service provider may create, change and delete security policies and submit policies through service APIs) and
that is for a target cloud resource in the target organization ([0021], [0023–0024] and [0034] discloses security policies associated with computing resources supplied by a computing-resource service provider; [0146] The resources include VM instances, database-storage systems, block-storage services, content-management services and other cloud resources),
recording, the first resource control policy ([0021-0024], [0034] & [0145] discloses creating and maintaining security policies for subsequent analysis and use in deciding resource requests; [0168] discloses storing access-rights information in a data store. The policy must remain available to the authorization service so it can be applied to later resource requests); and
denying, based on the first resource control policy, the first resource access request ([0024] & [0034] discloses evaluating a resource-access request using the security policy applicable to the request and granting or denying the request. It also discloses a deny-by-default model in which access is denied absent an applicable grant).
Cook fails to discloses:
wherein the first resource control policy indicates an access a first access permission that is of a first user outside the target organization and that is for the target cloud resource; obtaining, a first resource access request that is from the first user and that is for accessing the target cloud resource.
However, Aziz discloses:
wherein the first resource control policy indicates an access a first access permission that is of a first user outside the target organization and that is for the target cloud resource ([0022], [0027], [0034], [0041], & [0047-0049] discloses expressly defines an external user as a user who is not a member of the tenant and discloses assigning such an external user a permission level for tenant content);
obtaining, a first resource access request that is from the first user and that is for accessing the target cloud resource ([0034], & [0047-0051] discloses requests made by internal or external users to access content of an organizational tenant).
It would have been obvious to an ordinary skill in the art before the effective filing date of the claimed invention to modify the system of security policies to grant or deny permissions related to the access of computing resources and a multitenant architecture by which software and its supporting architecture serves multiple customers of a service, as disclosed by Aziz.
The motivation to include the multitenant architecture is to provide mechanisms by which a tenant can delegate administrator rights to an external user such that the external user can grant other users access to the tenant's content while the tenant controls the level of access that is provided to the external users.
The combination of Cook and Aziz fail to disclose:
customer-administrator and tenant-administrator functions.
However, Lander discloses:
customer-administrator and tenant-administrator functions ([0218] One embodiment provides fine-grained authorization policies for protecting the IDCS service resources described herein that are based on role-based access control (“RBAC”) and attribute-based access control (“ABAC”). These fine-grained authorization policies provide not only the authorization constructs for controlling access to IDCS resources for administrative operations through IDCS REST APIs, but also provide the constructs for achieving delegated administration, such as by creating different classes of administrators with varying degree of privileges to manage resources; [0243] In conjunction with the allowed scopes, custom claims/statements can also be returned at 1304. Custom claims provide different information that can be used by the server for authorization. For example the custom claim “user_isAdm in” is used to identify the user administrator for an application).
It would have been obvious to an ordinary skill in the art before the effective filing date of the claimed invention to modify Cook in view of Aziz and include system and method of role-based access control with different classes of administrators, as disclosed by Lander.
The motivation to combine the teachings of role-based access control with different classes of administrator is to maintain varying degree of privileges to manage resources.
Regarding claim 9, it is a computing device claim and recites similar subject matter as claim 1 and therefore rejected under similar ground of rejection.
Regarding claim 17, it is a non-transitory computer-readable medium claim and recites similar subject matter as claim 1 and therefore rejected under similar ground of rejection.
Regarding claim 2, the combination of Cook, Aziz, and Lander discloses:
The method of claim 1, further comprising:
obtaining a second resource access request that is from a second user outside the target organization and that is for accessing the target cloud resource (Cook: [0021], [0024], and [0069-0070]); and
allowing, based on the first resource control policy, the second resource access request (Cook: [0023-0024], [0029], and [0034]).
Regarding claim 10, it is a computing device claim and recites similar subject matter as claim 2 and therefore rejected under similar ground of rejection.
Regarding claim 18, it is a non-transitory computer-readable medium claim and recites similar subject matter as claim 2 and therefore rejected under similar ground of rejection.
Regarding claim 3, the combination of Cook, Aziz, and Lander discloses:
The method of claim 1, further comprising:
obtaining a second resource control policy that is from the administrator and that is for the target cloud resource (Cook: [0021-0024], & [0029]),
wherein the second resource control policy indicates a second access permission that is of a second user in the target organization and that is for the target cloud resource (Aziz: [0027-0028], [0034], and [0041]);
recording the second resource control policy (Cook: [0168]);
obtaining a second resource access request that is from the second user and that is for accessing the target cloud resource (Cook: [0069-0070]); and
allowing, based on the second resource control policy, the second resource access request (Cook: [0024], & [0034]).
Regarding claim 11, it is a computing device claim and recites similar subject matter as claim 3 and therefore rejected under similar ground of rejection.
Regarding claim 19, it is a non-transitory computer-readable medium claim and recites similar subject matter as claim 3 and therefore rejected under similar ground of rejection.
Regarding claim 4, the combination of Cook, Aziz, and Lander discloses:
The method of claim 1, wherein before obtaining and recording the first resource control policy, the method further comprises:
obtaining registration requests that carry user accounts (Lander: [0120-0121]);
respectively registering and recording the user accounts based on the registration requests (Lander: [0115-0121]),
wherein each of the user accounts comprises an account of the administrator (Lander: [0133], & [0255-0256]);
classifyingLander: [0120-0121]) and
setting the account as an administrator account of the target organization (Lander: [0033-0034], & [0121]).
Regarding claim 12, it is a computing device claim and recites similar subject matter as claim 4 and therefore rejected under similar ground of rejection.
Regarding claim 20, it is a non-transitory computer-readable medium claim and recites similar subject matter as claim 4 and therefore rejected under similar ground of rejection.
Regarding claim 5, the combination of Cook, Aziz, and Lander discloses:
The method of claim 4, wherein the first resource access request carries information of a user account of the first user and wherein obtaining the first resource access request comprises:
determining that the user account does not belong to the target organization (Cook: [0034]); and
determining that the first resource access request is from the first user (Dawson: [0034] & [0041]).
Regarding claim 13, it is a computing device claim and recites similar subject matter as claim 5 and therefore rejected under similar ground of rejection.
Regarding claim 7, the combination of Cook, Aziz, and Lander discloses:
The method of claim 1, wherein the first resource control policy comprises:
a cloud resource identifier field identifying the target cloud resource (Cook: [0023]);
an effect field identifying that access to the target cloud resource is denied or allowed (Cook: [0023]);
a request type field identifying a request type of the first resource access request (Cook: [0023-0024]); and
a condition field indicating the first user outside the target organization (Cook: [0023-0024]).
Regarding claim 15, it is a computing device claim and recites similar subject matter as claim 7 and therefore rejected under similar ground of rejection.
Regarding claim 8, the combination of Cook, Aziz, and Lander discloses:
The method of claim 1, wherein a type of the target cloud resource comprises a virtual machine and a container for a computing service, a bucket for an object storage service, an Elastic Volume Service (EVS) disk, or a cloud database (Cook: [0062] & [0084]).
Regarding claim 16, it is a computing device claim and recites similar subject matter as claim 8 and therefore rejected under similar ground of rejection.
Claim(s) 6, and 14 are rejected under 35 U.S.C. 103 as being unpatentable over Cook et al., (US20200366707A1) in view of Aziz et al., (US20210141930A1) in view of Lander et al., (US20170331832A1) and further in view of Belinkiy et al., (US20120159577A1).
Regarding claim 6, the combination of Cook, Aziz, and Lander fails to disclose:
The method of claim 4, wherein the first resource access request does not carry information of a user account registered on a cloud management platform, and wherein obtaining the first resource access request comprises:
determining that the first resource access request does not carry the information; and
determining that the first resource access request is from the first user.
However, Belinkiy discloses:
determining that the first resource access request does not carry the information ([0023-0024] & [0031] discloses an anonymous principal represented by an anonymous credential or placeholder that does not reveal the principal’s identity. An authorization request from the anonymous principal is received and evaluated without identifying the requesting person as a conventional registered user); and
determining that the first resource access request is from the first user ([0025-0026] & [0031] discloses during parsing that the request carries an anonymous credential rather than a normal identified principal. It further discloses testing whether a principal is anonymous and restricting resources to non-anonymous principals).
It would have been obvious to an ordinary skill in the art before the effective filing date of the claimed invention to modify Cook in view of Aziz and further in view of Lander and include a system that process resource-access requests that do not identify a user account registered with a cloud-management platform, as disclosed by Belinkiy.
The motivation to combine the teachings of Belinkiy is to classify and evaluate requests lacking registered account information. This would have prevented unidentified users from bypassing access controls and predictably allow such requests to be treated as originating outside the organization and evaluated under the applicable external-user policy.
Regarding claim 14, it is a computing device claim and recites similar subject matter as claim 6 and therefore rejected under similar ground of rejection.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SYED M AHSAN whose telephone number is (571)272-5018. The examiner can normally be reached 8:30 AM - 6:00 PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, William Korzuch can be reached at 571-272-7589. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/SYED M AHSAN/Primary Examiner, Art Unit 2491