DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Status of Claims
Claims 1-8, 21-32 are pending. Claims 9-20 are cancelled.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-8 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. The claim(s) recite(s) “determining a status of an accessibility of a predefined host” (mental process – observation), “determining that a data structure corresponds to controlled-access information” (mental process – observation), and “responsive to the status… and the determination… encrypting the data structure to secure the controlled-access information” (mental process – mathematical calculation). This judicial exception is not integrated into a practical application because claim 1 fails to recite any further language that integrates the above steps into a method that applies, relies on, or uses the abstract idea in a manner that imposes a meaningful limit on the abstract idea. The claim(s) does/do not include additional elements that are sufficient to amount to significantly more than the judicial exception because the claimed method does not incorporate any hardware elements at all, and therefore recites merely the abstract idea itself.
The dependent claims fail to recite any further limitations that would either integrate the above identified abstract idea into a practical application and fail to recite anything which would constitute significantly more than the abstract idea itself. Thus, these claims are also rejected for the same reasons as applied to claim 1, above.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1-2, 8, 21-22, 28-30 is/are rejected under 35 U.S.C. 103 as being unpatentable over Rodriguez Bravo et al (PGPUB 2022/0067139), hereinafter Rodriguez, and further in view of Devol et al (PGPUB 2011/0305337).
Regarding Claims 1, 21, and 29:
Rodriguez teaches a method of digital rights management, a system, and one or more non-transitory computer readable media containing program instructions that, when executed by one or more processors, cause the one or more processors to perform operations, the system comprising ([0025] device management program 110 can also determine whether sensitive data is stored on a computing device and encrypt the sensitive data; [0053] a system, a method, and/or a computer program product; the computer program product may include a computer readable storage medium (or media) having computer readable program instructions thereon for causing a processor to carry out aspects of the present invention):
a computing device configured to ([0011] a computing device):
determine that a data structure corresponds to controlled-access information ([0040] device management program 110 determines whether there is sensitive data on the device; device management program 110 identifies whether there is sensitive data by identifying locations of potentially sensitive data and identifying data types that are typically associated with sensitive data); and
responsive to the determination of the correspondence, encrypt the data structure to secure the controlled-access information ([0041] device management program 110 can then identify the locations of potentially sensitive data by scanning database 112 for files having extensions “.db”, “.mp3”, “.mp4”, or “.avi”, matching a set of files having the aforementioned extensions, and identifying a set of storage location addresses corresponding to the matched set of files; [0042] device management program 110 can then encrypt the sensitive data; device management program 110 encrypts the identified sensitive data using any encryption method known in the art).
Rodriguez does not explicitly teach determin[ing] a status of an accessibility of a predefined host; and
responsive to the status indicating inaccessibility of the predefined host, encrypt[ing] the data structure to secure the controlled-access information.
However, Devol teaches the concept of determin[ing] a status of an accessibility of a predefined host ([0010] a base station can periodically communicate a heartbeat signal with the wireless transceiver; the wireless transceiver can transmit an acknowledgement of the heartbeat signal to the base station; the system can include a data storage device coupled to the processor in the appliance; and computer readable code executed by the processor to render inaccessible data on the data storage device if the wireless transceiver is separated from the processor or if the wireless transceiver fails to receive a heartbeat transmission from a base station; [0039] the system can use a wireless transmitter in the cell phone that communicates with a central processing unit (CPU) located within the electronic device, such as a laptop; when the wearable transmitter in the cell phone is in range of the receiver in the CPU, the encrypted data is decrypted and stored unencrypted onto the hard disk drive; when the user and wearable transmitter leave the location, the CPU encrypts the unencrypted data and saves the encrypted file, and then deletes the unencrypted file); and
responsive to the status indicating inaccessibility of the predefined host, encrypt[ing] a data structure to secure controlled-access information ([0039] the system can use a wireless transmitter in the cell phone that communicates with a central processing unit (CPU) located within the electronic device, such as a laptop; when the wearable transmitter in the cell phone is in range of the receiver in the CPU, the encrypted data is decrypted and stored unencrypted onto the hard disk drive; when the user and wearable transmitter leave the location, the CPU encrypts the unencrypted data and saves the encrypted file, and then deletes the unencrypted file).
It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to combine the detection of a remote host teachings of Devol with the detecting and securing sensitive information teachings of Rodriguez, for the reasons identified in Devol, e.g. [0013]: “Advantages of the preferred embodiments may include one or more of the following. The system secures valuable items such as laptops, handheld computers, PDAs, and other items. In addition, the system secures invaluable data from falling into the wrong hands. The system mitigates problems arising from the forgetfulness of individuals, in addition to thievery.”
Regarding Claim 2, 22, and 30:
Rodriguez in view of Davol teaches the method of claim 1, the system of claim 21, and the one or more non-transitory computer readable media of claim 29. In addition, Rodriguez teaches wherein, to determine the data structure corresponds to the controlled-access information, the computing system is configured to:
compare a file extension of the data structure to a predefined set of file extensions ([0041] database 112 contains a list of one or more sets of data types (e.g., file extensions such as .mp4, .tff, .jpeg, .pdf, etc.) that can potentially contain sensitive information regarding an individual or a set of individuals, which can include, but is not limited to, contact information (e.g., name of the individual, email address, phone number, social media identification, messaging service alias, etc.), images, audio (i.e., audio that captures the voice of the individual(s) speaking), and video recordings; among database 112 are a set of files stored in a SQLite3 file format (i.e., “.db”) that lists contact information of a set of individuals, a set of audio files with extension “.mp3” and “.mp4”, and a set of video files with extension “.avi”; device management program 110 can identify from database 112 that the device has extensions “.db”, “.mp3”, “.mp4”, and “.avi” and that those file extensions are potentially sensitive data types; device management program 110 can then identify the locations of potentially sensitive data by scanning database 112 for files having extensions “.db”, “.mp3”, “.mp4”, or “.avi”, matching a set of files having the aforementioned extensions, and identifying a set of storage location addresses corresponding to the matched set of files).
Regarding Claims 8 and 28:
Rodriguez in view of Davol teaches the method of claim 1 and the system of claim 21. In addition, Davol teaches wherein to determine the status of the accessibility of the predefined host, the computing device is configured to:
send a request for an indication of a presence of the predefined host ([0012] system includes checking if the user is nearby, sending challenge message to the mobile phone and receiving validation message from the user key; the system can lock the computer or log out from an operating system if the user key is not nearby; the system can generate an alarm on the mobile device or the user key when the user key signal is not received within a predetermined period); and
determine that a predefined time has elapsed from the request without receiving a response ([0012] system includes checking if the user is nearby, sending challenge message to the mobile phone and receiving validation message from the user key; the system can lock the computer or log out from an operating system if the user key is not nearby; the system can generate an alarm on the mobile device or the user key when the user key signal is not received within a predetermined period).
The rationale to combine Rodriguez and Davol is the same as provided for claims 1 and 21 due to the overlapping subject matter between claims 1 and 8, 21 and 28.
Claim(s) 3, 23, 31 is/are rejected under 35 U.S.C. 103 as being unpatentable over Rodriguez in view of Devol, and further in view of Wang et al (PGPUB 2025/0181758).
Regarding Claim 3, 23, and 31:
Rodriguez in view of Davol teaches the method of claim 1, the system of claim 21, and the one or more non-transitory computer readable media of claim 29.
Neither Rodriguez nor Davol explicitly teaches wherein to determine the data structure corresponds to the controlled-access information, the system is configured to:
determine the data structure corresponds to the controlled-access information based on a location of the data structure within a file structure.
However, Wang teaches the concept wherein to determine a data structure corresponds to controlled-access information, a system is configured to:
determine the data structure corresponds to the controlled-access information based on a location of the data structure within a file structure ([0079] sub-operation 350 of FIG. 3B includes identifying the sensitive data that has been requested to be migrated; in preferred approaches, the sensitive data is identified by determining the location in a volume that the sensitive data resides; as noted above, the location of the sensitive data may be quantified using one or more key-value character strings that describe where the sensitive data is positioned in a volume; the volume is further correlated with a container that may be determined as a part of sub-operation 350 to identify the sensitive data; in some approaches, identifying information may be received in the initial migration request; for instance, the migration request may include key-value character strings that define the boundaries of the sensitive data (e.g., the extents of a file) being migrated).
It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to combine the determining sensitive data using location in a data structure teachings of Wang with the detecting and securing sensitive information teachings of Rodriguez in view of Devol, in order to improve the accuracy of sensitive information identification using direct input of the data location, thereby avoiding any accidental data leaks resulting from poor judgement calls in systems where the attempting to identify the sensitive data is done heuristically or algorithmically.
Claim(s) 4, 24, 32 is/are rejected under 35 U.S.C. 103 as being unpatentable over Rodriguez in view of Devol, and further in view of Jain et al (PGPUB 2021/0312077).
Regarding Claims 4, 24, and 32:
Rodriguez in view of Davol teaches the method of claim 1, the system of claim 21, and the one or more non-transitory computer readable media of claim 29.
Neither Rodriguez nor Davol explicitly teaches wherein to determine the data structure corresponds to the controlled-access information, the system is configured to:
determine the data structure corresponds to the controlled-access information based on a comparison of a unique identifier of the data structure to a predefined list of unique identifiers.
However, Jain teaches the concept wherein to determine a data structure corresponds to controlled-access information, a system is configured to:
determine the data structure corresponds to the controlled-access information based on a comparison of a unique identifier of the data structure to a predefined list of unique identifiers ([0033] for example, the locally stored data includes sensitive user data when the data includes login credentials (e.g., user ID and password), financial information, unique personal identifiers, medical information, or other similar information; if the locally stored data does not include sensitive user data, the process completes; if the locally stored data does include sensitive user data, then the process proceeds, and a list of data files that include the sensitive user data may be filtered out and identified as containing sensitive user data).
It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to combine the securing sensitive data through determining identifiers teachings of Jain with the detecting and securing sensitive information teachings of Rodriguez in view of Devol, in order to improve the accuracy of sensitive information identification using direct identifiers in the data, thereby avoiding any accidental data leaks resulting from poor judgement calls in systems where the attempting to identify the sensitive data is done heuristically or algorithmically.
Claim(s) 5-6, 25-26 is/are rejected under 35 U.S.C. 103 as being unpatentable over Rodriguez in view of Devol, and further in view of Orloff (US 12,587,534).
Regarding Claims 5 and 25:
Rodriguez in view of Davol teaches the method of claim 1 and the system of claim 21.
Neither Rodriguez nor Davol explicitly teaches wherein the computing device is further configured to:
send an indication of the status indicating inaccessibility of the predefined host to a predefined address, comprising a source of the indication.
However, Orloff teaches the concept wherein a computing device is configured to:
send an indication of a status indicating inaccessibility of a predefined host to a predefined address, comprising a source of the indication ([col 10 line 14-43] user behaviors may be weighted similarly, for example with higher weight assigned to behaviors associated more closely with fraud or other scrupulous activities (e.g., multiple failed attempts to access highly sensitive data), and lower weight assigned to behaviors that may not necessarily be related as such (e.g., multiple failed attempts to access less sensitive data); [col 12 line 5-31] further aspect of the system is timely notification by the system when a seed is triggered; a notification, or response, might be, for example, an email, a phone call, an SMS text message, system alert from a cloud service, or the like; [col 10 line 58-col 11 line 11] alerts, notifications, warnings in-app and/or through other modalities, associated devices, and such can be provided, for example to indicate activity associated with high risk).
It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to combine notification of access failure teachings of Orloff with the detecting and securing sensitive information teachings of Rodriguez in view of Devol, in order to alert administrators or authorities in the event of adverse system events, allowing prompt remediation to possible system compromises or thefts, swift issue resolution, and active security response to protect sensitive data.
Regarding Claims 6 and 26:
Rodriguez in view of Davol and Orloff teaches the method of claim 5 and the system of claim 25. In addition, Orloff teaches wherein the indication of the status indicating the inaccessibility of the predefined host comprises an email message ([col 12 line 5-31] email); and
the predefined address corresponds to a law enforcement agency ([col 12 line 44-col 13 line 19] the point of contact is alerted through electronic delivery; in various embodiments, the point of contact is a law enforcement and/or intelligence gathering agency).
The rationale to combine Rodriguez in view of Davol and Orloff is the same as provided for claims 5 and 25, due to the overlapping subject matter between claims 5 and 6, 25 and 26.
Claim(s) 7, 27 is/are rejected under 35 U.S.C. 103 as being unpatentable over Rodriguez in view of Devol, and further in view of Bahari (US 12,341,773).
Regarding Claims 7 and 27:
Rodriguez in view of Davol teaches the method of claim 1 and the system of claim 21.
Neither Rodriguez nor Davol explicitly teaches the computing device further configured to:
determining, responsive to the status indicating the inaccessibility of the predefined host, a status of an accessibility of a second predefined host, wherein the encryption of the data structure is responsive to a determination of the inaccessibility of the second predefined host.
However, Bahari teaches the concept of determining, responsive to a status indicating inaccessibility of a predefined host, a status of an accessibility of a second predefined host, wherein [protection] of a data structure is responsive to a determination of the inaccessibility of the second predefined host ([col 9 line 65-col 10 line 30] node of the network 102 that is operating and able to successfully communicate with other devices, including other nodes of the network 102, is referred to herein as “online,” whereas a node of the network 102 that is unable to successfully communicate due to an error or anomaly, such as a loss of power, is referred to herein as “offline”; the online/offline status of a node is generally discoverable by other nodes of the network; for example, if a first node attempts communication with a second node that fails to respond after a predefined amount of time or number of attempts, then the first node may determine that the second node is offline; each node may maintain a list of all of the nodes of the network 102 and, for each node, indicate whether the node is currently online or offline; when a first node detects a change in the online/offline status of a second node (i.e., that the online/offline status of the second node has changed relative to its status indicated by the node list), the first node may update its node list and then inform the other nodes of the network of the change; [col 6 line 48-64] the authentication nodes 104a-c (after receiving separate access requests from the client device 100) communicate with one another to determine the total number of authentication nodes 104a-d that have successfully authenticated the client device 100; if the total number does not exceed the threshold TH, then the authentication nodes 104a-c may determine that a valid consensus for authenticating the client has not been reached; [col 7 line 44-59] the other authentication nodes should prevent a valid consensus from being reached, thereby preventing the hacker from gaining access to sensitive information within the network 102); and
Rodriguez teaches wherein protection is encryption ([0042] device management program 110 can then encrypt the sensitive data; device management program 110 encrypts the identified sensitive data using any encryption method known in the art).
It would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to combine the detection of offline hosts teachings of Bahari with the detecting and securing sensitive information teachings of Rodriguez in view of Devol, in order to provide a system which dynamically adjusts authentication security to accommodate any unforeseen server failures, while protecting sensitive data by preventing access in the event that the number of security servers reaches a threshold where confident authentication becomes impossible.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to FORREST L CAREY whose telephone number is (571)270-7814. The examiner can normally be reached 9:00AM-5:30PM M-F.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, William Korzuch can be reached at (571) 272-7589. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/FORREST L CAREY/Examiner, Art Unit 2491
/WILLIAM R KORZUCH/Supervisory Patent Examiner, Art Unit 2491