Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
This Office Action is in response to the U.S. patent application 19054969 filed on February 17, 2025.
Of original claims 1-20: no claims have been amended, cancelled or added; claims 1 and 19-20 are independent claims. Accordingly, claims 1-20 remain pending, and have been examined in this application.
Information Disclosure Statement
The information disclosure statements (IDSs) submitted on June 2, 2025, March 3, 2026, and April 21, 2026, comply with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statements have been considered by the examiner.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
(a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention.
Claims 1-7, 10 and 12-20 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by O’Byrne et al. (“O’Byrne”; US20210329037A1).
Per claim 1: O’Byrne discloses a computer-implemented method (O’Byrne Abstract, “Methods and systems to manage permissions in a structured user-environment which provide a User Interface (UI) that provides a simple, intuitive administration to apply permissions at the user and group level to data in the structured user-environment”) comprising:
at a processor of a device (O’Byrne para. [0016], “the apparatus comprising: a processor”):
obtaining membership data for a list of objects associated with a plurality of administrative units (O’Byrne para. [0041], “the user interface 100 is for permissions accorded to user “Jane Doe”; O’Byrne para. [0004], “Administrators responsible for configuring permissions”);
identifying, at a management service and based on the membership data, a list of associated qualities for each object of the list of objects for a first administrative unit of the plurality of administrative units (O’Byrne FIG. 1: see “”User Permissions” as claimed management service; see vertical “Start Page” column for claimed “list of associated qualities” for “Jane Doe” as claimed object; see “interface 100” which can be accessed by any of the “administrators”);
accessing a list of object qualifications for each object of the list of objects associated with the first administrative unit (O’Byrne FIG 1: see vertical “menu controls 106” column for claimed “object qualifications“);
comparing the object qualities (O’Byrne’s FIG. 1 vertical “Start Page” column for claimed “list of associated qualities”) to object qualifications (O’Byrne’s FIG 1 vertical “menu controls 106” column for claimed “object qualifications”) for each object of the list of objects associated with the first administrative unit; and
based on the comparing step, adjusting the first administrative unit to at least one of add or remove an object, or adjust an authorization of an object (O’Byrne para. [0048], “User interface 100 lists a number of permissions “Jane Doe”. For the permission “Start Page”, setting control 108 is set at its default value, namely, “Blank”. At the outset of the UI, the default effective value is set as “Denied”. However, the present UI indicates that the effective value is now “Allowed”. Since the effective value was not changed from “Denied” to “Allowed” due to the presence of an “Allow” value in setting control 108, this implies that the change has occurred elsewhere. This is indicated by an indicator, or “Infotip” 110, that provides information about the source of the change.”).
Per claim 2: O’Byrne disclosed the method of claim 1. O’Byrne further discloses an arrangement wherein adjusting the first administrative unit to at least one of add or remove an object or adjust an authorization of an object comprises determining to delegate administrative rights to a particular object for the first administrative unit (O’Byrne para. [0048], “Since the effective value was not changed from “Denied” to “Allowed” due to the presence of an “Allow” value in setting control 108, this implies that the change has occurred elsewhere. This is indicated by an indicator, or “Infotip” 110, that provides information about the source of the change. Rather than having the administrator search manually through various user groups and/or security/controls (along with their respective privilege settings) to find where the source of the change is, dialog box 112 associated with “Infotip” 110, immediately provides the answer. By opening or clicking “infotip” 110, dialog box 112 opens, immediately providing an explanation of the source of the effective value. of permission inheritance. The administrator can immediately see that the effective privilege for “Jane Doe” for the “Start Page” is allowed, by virtue of the fact that “Jane Doe” belongs to two groups, “Business Users” and “Regular Work Group”, each of which allows members of the group to have access to the “Start Page”. The default value of “Denied” of the effective privilege has been changed to “Allowed”—not directly, due to the presence of an “Allow” value in setting control 108, but by membership of “Jane Doe” in each of the two groups.”).
Per claim 3: O’Byrne disclosed the method of claim 1. O’Byrne further discloses an arrangement wherein adjusting the first administrative unit to at least one of add or remove an object or adjust an authorization of an object is based on permission roles and assigning permission delegation to a user (O’Byrne para. [0055], “The next permission, “User Administrator” in the heading “Administrator” has its setting control 132 rendered inaccessible. That is, the setting control cannot be edited. This inaccessibility is indicated by setting control 132 fully shaded in grey, and implies there are no means to alter setting control 132. This implies that the administrator cannot make any changes to the effective value for the permission “User Administrator”. In addition, the effective value is “Allowed” and has associated “infotip” 134 that, once opened, provides dialog box 136 that explains the resolution between the setting value (set as inaccessible) and the effective value (set as “Allowed”). Dialog box 136 indicates that the effective value is “Allowed” due to the fact that the permission for “User Administrator” is automatically included with the permission for “System Administrator”. Since the effect value for “System Administrator” is “Allowed”, the effective value for “User Administrator” is also “Allowed”. Due to the link between “User Administrator” and “System Administrator”, setting control 132 cannot be used to change the effective value of “User Administrate”. Therefore, setting control 132 is rendered inaccessible.”).
Per claim 4: O’Byrne disclosed the method of claim 1. O’Byrne further discloses an arrangement wherein adjusting the first administrative unit to at least one of add or remove an object or adjust an authorization of an object comprises determining to remove access to the first administrative unit for a particular object (O’Byrne para. [0041], “The skeleton user interface 100 is accessed by an individual who controls permissions (or privileges) of users in the structured user-environment. As an example, this may be an administrator. In some embodiments, this can be a user administrator or a system administrator. In FIG. 1, the user interface 100 is for permissions accorded to user “Jane Doe”. In general, “Jane Doe” does not have access to user interface 100. However, if “Jane Doe” is designated as an administrator, then she will have access to user interface 100.”).
Per claim 5: O’Byrne disclosed the method of claim 1. O’Byrne further discloses an arrangement wherein adjusting the first administrative unit to at least one of add or remove an object or adjust an authorization of an object comprises determining to provide access to another administrative unit for a particular object (O’Byrne para. [0041], “The skeleton user interface 100 is accessed by an individual who controls permissions (or privileges) of users in the structured user-environment. As an example, this may be an administrator. In some embodiments, this can be a user administrator or a system administrator. In FIG. 1, the user interface 100 is for permissions accorded to user “Jane Doe”. In general, “Jane Doe” does not have access to user interface 100. However, if “Jane Doe” is designated as an administrator, then she will have access to user interface 100.”).
Per claim 6: O’Byrne disclosed the method of claim 1. O’Byrne further discloses an arrangement wherein adjusting the first administrative unit to at least one of add or remove an object or adjust an authorization of an object comprises determining a membership conflict between a particular object and memberships associated with the particular object corresponding to another administrative unit (O’Byrne para. [0052], “There can be instances where there is a conflict between a setting and an effective value, due to an inheritance of permissions. An example of a conflict between a setting and an effective value due to inheritance permissions is discussed with respect to the permission “Collaboration Tools” in FIG. 1. For the permission “Send Links”, the setting control 120 has been set to “Allow” by the administrator. However, the effective permission is set as “Denied”, and “infotip” 122 is provided. That is, the “Allow” value in setting control 120 conflicts with other permission settings, as indicated by the presence of “infotip” 122. In this case the conflict is due to the inheritance of a “Deny” value from the “Senior Buyers” group, as shown in dialog box 124. Rather than manually search through all of “Jane Doe's” group memberships (and their respective privileges) and other security settings, the administrator can open “infotip” 122 to see dialog box 124 with an explanation of the source of the denial. The dialog box 124 indicates that “Jane Doe's” permission to “Send Links” is set by membership to two different groups: “Senior Buyers” and “Business Users”. While “Business Users” allow all members of the group to “Send Links”, members of the groups “Senior Buyers” are denied permission for such action. Since a denial overrides an allowance, the effective value is set to “Denied”, due to “Jane Doe's” membership in the group “Senior Buyers”.”).
Per claim 7: O’Byrne disclosed the method of claim 6. O’Byrne further discloses an arrangement further comprising displaying on a user interface at a client device a membership conflict resolution notification for the membership conflict (O’Byrne para. [0052], “There can be instances where there is a conflict between a setting and an effective value, due to an inheritance of permissions. An example of a conflict between a setting and an effective value due to inheritance permissions is discussed with respect to the permission “Collaboration Tools” in FIG. 1. For the permission “Send Links”, the setting control 120 has been set to “Allow” by the administrator. However, the effective permission is set as “Denied”, and “infotip” 122 is provided. That is, the “Allow” value in setting control 120 conflicts with other permission settings, as indicated by the presence of “infotip” 122. In this case the conflict is due to the inheritance of a “Deny” value from the “Senior Buyers” group, as shown in dialog box 124. Rather than manually search through all of “Jane Doe's” group memberships (and their respective privileges) and other security settings, the administrator can open “infotip” 122 to see dialog box 124 with an explanation of the source of the denial. The dialog box 124 indicates that “Jane Doe's” permission to “Send Links” is set by membership to two different groups: “Senior Buyers” and “Business Users”. While “Business Users” allow all members of the group to “Send Links”, members of the groups “Senior Buyers” are denied permission for such action. Since a denial overrides an allowance, the effective value is set to “Denied”, due to “Jane Doe's” membership in the group “Senior Buyers”.”).
Per claim 10: O’Byrne disclosed the method of claim 1. O’Byrne further discloses an arrangement wherein in response to adjusting the first administrative unit to at least one of add or remove the object, or adjust the authorization of the object, the management service is configured to distribute a corresponding membership change action to each of the plurality of administrative units (O’Byrne para. [0122], ’’The administrator may also choose to change setting values (step 622), after which the changes can be cancelled (step 624) or saved to the server (step 626 and step 628), before closing the UI (step 630).”; [NOTE: “saved to the server” is being interpreted as a distribution of the changes, in that any administrative unit which accesses data for that user, from the server, will receive the changes.]).
Per claim 12: O’Byrne disclosed the method of claim 1. O’Byrne further discloses an arrangement wherein the object qualifications for each object of the list of objects is obtained from a directory service, a file, or a management service configuration database (O’Byrne para. [0012], ’”The methods and systems to manage permissions in a structured user-environment disclosed herein can be applied to, for example, a system that has a software environment accessed through user accounts, permissions (values that control whether an account is able to use various capabilities in the system), and administrators (people responsible for controlling accounts and their permissions). Examples include computer operating systems; cloud-based software services and databases” The methods and systems to manage permissions in a structured user-environment disclosed herein can be applied to, for example, a system that has a software environment accessed through user accounts, permissions (values that control whether an account is able to use various capabilities in the system), and administrators (people responsible for controlling accounts and their permissions). Examples include computer operating systems; cloud-based software services and databases.”).
Per claim 13: O’Byrne disclosed the method of claim 1. O’Byrne further discloses an arrangement wherein the object qualifications for each object of the list of objects is obtained during, or prior to, an evaluation of the adjusting of the first administrative unit to at least one of add or remove an object or an evaluation of the adjusting the authorization of an object (O’Byrne para. [0013], “a computer-implemented method for managing a set of permissions on a user interface, the method comprising: retrieving, by a client, from a server, a setting value and an inherited value for each permission in the set of permissions; generating, by the client, an effective value for each permission from the setting value and the inherited value; … displaying, by the client, the user interface on a device to an administrator; changing, by the administrator, a selected setting value via the user interface;”).
Per claim 14: O’Byrne disclosed the method of claim 1. O’Byrne further discloses an arrangement further comprising:
tracking membership change results associated with the adjusting step in a management configuration database (O’Byrne para. [0122], ’’The administrator may also choose to change setting values (step 622), after which the changes can be cancelled (step 624) or saved to the server (step 626 and step 628), before closing the UI (step 630).”; O’Byrne para. [0012], ’”The methods and systems to manage permissions in a structured user-environment disclosed herein can be applied to, for example, a system that has a software environment accessed through user accounts, permissions (values that control whether an account is able to use various capabilities in the system), and administrators (people responsible for controlling accounts and their permissions). Examples include computer operating systems; cloud-based software services and databases.”).
Per claim 15: O’Byrne disclosed the method of claim 14. O’Byrne further discloses an arrangement further comprising:
reversing the adjusting step to each of the plurality of administrative units based on the tracked membership change results (O’Byrne para. [0052], “There can be instances where there is a conflict between a setting and an effective value, due to an inheritance of permissions. An example of a conflict between a setting and an effective value due to inheritance permissions is discussed with respect to the permission “Collaboration Tools” in FIG. 1. For the permission “Send Links”, the setting control 120 has been set to “Allow” by the administrator. However, the effective permission is set as “Denied”, and “infotip” 122 is provided. That is, the “Allow” value in setting control 120 conflicts with other permission settings, as indicated by the presence of “infotip” 122. In this case the conflict is due to the inheritance of a “Deny” value from the “Senior Buyers” group, as shown in dialog box 124. Rather than manually search through all of “Jane Doe's” group memberships (and their respective privileges) and other security settings, the administrator can open “infotip” 122 to see dialog box 124 with an explanation of the source of the denial. The dialog box 124 indicates that “Jane Doe's” permission to “Send Links” is set by membership to two different groups: “Senior Buyers” and “Business Users”. While “Business Users” allow all members of the group to “Send Links”, members of the groups “Senior Buyers” are denied permission for such action. Since a denial overrides an allowance, the effective value is set to “Denied”, due to “Jane Doe's” membership in the group “Senior Buyers”.”).
Per claim 16: O’Byrne disclosed the method of claim 1. O’Byrne further discloses an arrangement wherein each object comprises a user account object, a computer account object, one of a group of objects, an object container object, or a combination thereof (O’Byrne para. [0041], ”The skeleton user interface 100 is accessed by an individual who controls permissions (or privileges) of users in the structured user-environment. As an example, this may be an administrator. In some embodiments, this can be a user administrator or a system administrator. In FIG. 1, the user interface 100 is for permissions accorded to user “Jane Doe”.).
Per claim 17: O’Byrne disclosed the method of claim 1. O’Byrne further discloses an arrangement wherein the plurality of administrative units each comprise an administrative object that defines a set of member objects to which membership change actions are configured to be applied and/or enforced (O’Byrne para. [0041], ”The skeleton user interface 100 is accessed by an individual who controls permissions (or privileges) of users in the structured user-environment. As an example, this may be an administrator. In some embodiments, this can be a user administrator or a system administrator.”; O’Byrne para. [0055], “The next permission, “User Administrator” in the heading “Administrator” has its setting control 132 rendered inaccessible. That is, the setting control cannot be edited. This inaccessibility is indicated by setting control 132 fully shaded in grey, and implies there are no means to alter setting control 132. This implies that the administrator cannot make any changes to the effective value for the permission “User Administrator”.”; [NOTE: See also, FIG. 1’s “setting control 128” for a “System Administrator”).).
Per claim 18: O’Byrne disclosed the method of claim 1. O’Byrne further discloses an arrangement wherein the management service is hosted by a cloud-based management server and accessed by the client device based on the client device comprising correct permissions to access the cloud-based management server (O’Byrne para. [0012], ’”The methods and systems to manage permissions in a structured user-environment disclosed herein can be applied to, for example, a system that has a software environment accessed through user accounts, permissions (values that control whether an account is able to use various capabilities in the system), and administrators (people responsible for controlling accounts and their permissions). Examples include computer operating systems; cloud-based software services and databases” The methods and systems to manage permissions in a structured user-environment disclosed herein can be applied to, for example, a system that has a software environment accessed through user accounts, permissions (values that control whether an account is able to use various capabilities in the system), and administrators (people responsible for controlling accounts and their permissions). Examples include computer operating systems; cloud-based software services and databases.”).
Per claim 19: O’Byrne discloses a system comprising:
a non-transitory computer-readable storage medium (O’Byrne para. [0149],” system 1100 can also include additional storage (removable and/or non-removable) including, but not limited to, magnetic or optical disks or tape. Such additional storage is illustrated in FIG. 11 by memory 1106 and disk 1108. Storage media can include volatile and nonvolatile, removable, and non-removable media implemented in any method or technology for storage of information such as computer-readable instructions, data structures, program modules or other data. Memory 1106 and disk 1108 are examples of non-transitory computer-readable storage media.”); and
one or more processors coupled to the non-transitory computer-readable storage medium, wherein the non-transitory computer-readable storage medium comprises program instructions that, when executed on the one or more processors (O’Byrne para. [0153],”Any of the methods, modules, algorithms, implementations, or procedures described herein can include machine-readable instructions for execution by: (a) a processor, (b) a controller, and/or (c) any other suitable processing device.”), cause the one or more processors to perform operations comprising:
obtaining membership data for a list of objects associated with a plurality of administrative units (O’Byrne para. [0041], “the user interface 100 is for permissions accorded to user “Jane Doe”; O’Byrne para. [0004], “Administrators responsible for configuring permissions”);
identifying, at a management service and based on the membership data, a list of associated qualities for each object of the list of objects for a first administrative unit of the plurality of administrative units (O’Byrne FIG. 1: see “”User Permissions” as claimed management service; see vertical “Start Page” column for claimed “list of associated qualities” for “Jane Doe” as claimed object; see “interface 100” which can be accessed by any of the “administrators”);
accessing a list of object qualifications for each object of the list of objects associated with the first administrative unit (O’Byrne FIG 1: see vertical “menu controls 106” column for claimed “object qualifications,“);
comparing the object qualities (O’Byrne’s FIG. 1 vertical “Start Page” column for claimed “list of associated qualities”) to object qualifications (O’Byrne’s FIG 1 vertical “menu controls 106” column for claimed “object qualifications,“) for each object of the list of objects associated with the first administrative unit; and
based on the comparing step, adjusting the first administrative unit to at least one of add or remove an object, or adjust an authorization of an object (O’Byrne para. [0048], “User interface 100 lists a number of permissions “Jane Doe”. For the permission “Start Page”, setting control 108 is set at its default value, namely, “Blank”. At the outset of the UI, the default effective value is set as “Denied”. However, the present UI indicates that the effective value is now “Allowed”. Since the effective value was not changed from “Denied” to “Allowed” due to the presence of an “Allow” value in setting control 108, this implies that the change has occurred elsewhere. This is indicated by an indicator, or “Infotip” 110, that provides information about the source of the change.”).
Per claim 20: O’Byrne discloses a non-transitory computer-readable storage medium (O’Byrne para. [0149],” system 1100 can also include additional storage (removable and/or non-removable) including, but not limited to, magnetic or optical disks or tape. Such additional storage is illustrated in FIG. 11 by memory 1106 and disk 1108. Storage media can include volatile and nonvolatile, removable, and non-removable media implemented in any method or technology for storage of information such as computer-readable instructions, data structures, program modules or other data. Memory 1106 and disk 1108 are examples of non-transitory computer-readable storage media.”) storing program instructions executable via one or more processors (O’Byrne para. [0153],”Any of the methods, modules, algorithms, implementations, or procedures described herein can include machine-readable instructions for execution by: (a) a processor, (b) a controller, and/or (c) any other suitable processing device.”) to perform operations comprising:
obtaining membership data for a list of objects associated with a plurality of administrative units (O’Byrne para. [0041], “the user interface 100 is for permissions accorded to user “Jane Doe”; O’Byrne para. [0004], “Administrators responsible for configuring permissions”);
identifying, at a management service and based on the membership data, a list of associated qualities for each object of the list of objects for a first administrative unit of the plurality of administrative units (O’Byrne FIG. 1: see “”User Permissions” as claimed management service; see vertical “Start Page” column for claimed “list of associated qualities” for “Jane Doe” as claimed object; see “interface 100” which can be accessed by any of the “administrators”);
accessing a list of object qualifications for each object of the list of objects associated with the first administrative unit (O’Byrne FIG 1: see vertical “menu controls 106” column for claimed “object qualifications);
comparing the object qualities (O’Byrne’s FIG. 1 vertical “Start Page” column for claimed “list of associated qualities”) to object qualifications (O’Byrne’s FIG 1 vertical “menu controls 106” column for claimed “object qualifications,“) for each object of the list of objects associated with the first administrative unit; and
based on the comparing step, adjusting the first administrative unit to at least one of add or remove an object, or adjust an authorization of an object (O’Byrne para. [0048], “User interface 100 lists a number of permissions “Jane Doe”. For the permission “Start Page”, setting control 108 is set at its default value, namely, “Blank”. At the outset of the UI, the default effective value is set as “Denied”. However, the present UI indicates that the effective value is now “Allowed”. Since the effective value was not changed from “Denied” to “Allowed” due to the presence of an “Allow” value in setting control 108, this implies that the change has occurred elsewhere. This is indicated by an indicator, or “Infotip” 110, that provides information about the source of the change.”).
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 8-9 and 11 are rejected under 35 U.S.C. 103 as being unpatentable over by O’Byrne et al. (“O’Byrne”; US20210329037A1) in view of SECURITY GUIDE I PUBLIC, SAP Adaptive Server Enterprise 16.0 SP03, Document Version: 1.0 - 2019-06-06 (“SAP ASE 16.0”).
Per claim 8: O’Byrne disclosed the method of claim 1. O’Byrne did not explicitly disclose an arrangement wherein the plurality of administrative units comprises a first set of administrative units that enforce mutually exclusive object memberships and a second set of administrative units that do not enforce mutually exclusive object memberships.
However, in an analogous art, SAP ASE 16.0 disclosed an arrangement wherein the plurality of administrative units comprises a first set of administrative units that enforce mutually exclusive object memberships and a second set of administrative units that do not enforce mutually exclusive object memberships (SAP ASE 16.0, p. 99, “the "chief_financial_officer" role might contain both the "financial_analyst" and the "salary_administrator" roles. ….can define a role's mutual exclusivity to enforce static or dynamic separation of duty policies. Roles can be defined to be mutually exclusive for: • Membership - one user cannot be granted two different roles. For example, you might not want the "payment_requestor" and "payment_approver" roles to be granted to the same user. …System roles, as well as user-defined roles, can be defined … to be mutually exclusive. For example, you might want a "super user" role to contain the system administrator, operator, and Technical Support roles. To enforce a separation of roles, you may want to define the system administrator and system security officer roles to be mutually exclusive for membership; that is, one user cannot be granted both roles.”).
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention, to modify O’Byrne to include, as taught by SAP ASE 16.0, an arrangement wherein the plurality of administrative units comprises a first set of administrative units that enforce mutually exclusive object memberships and a second set of administrative units that do not enforce mutually exclusive object memberships. Motivation for modifying would have been to include long-known “mutual exclusivity” membership options in order to increase a user-friendliness, versatility, attractiveness and broadened adoption of the O’Byrne/ SAP ASE 16.0 combination within the security field.
Per claim 9: O’Byrne disclosed the method of claim 8. O’Byrne did not explicitly disclose an arrangement wherein in response to adjusting the first administrative unit to at least one of add or remove the object, or adjust the authorization of the object, the management service is configured to provide instructions to a first administrative unit of the first plurality of administrative units and a first administrative unit of the second set of administrative units to implement the adjusting of the first administrative unit to at least one of add or remove an object or adjusting the authorization of an object, and providing instructions to a second administrative unit of the first set of administrative units to deny the adjusting of the first administrative unit to at least one of add or remove an object or deny the adjusting the authorization of an object.
However, in an analogous art, SAP ASE 16.0 disclosed an arrangement wherein in response to adjusting the first administrative unit to at least one of add or remove the object, or adjust the authorization of the object, the management service is configured to provide instructions to a first administrative unit of the first plurality of administrative units and a first administrative unit of the second set of administrative units to implement the adjusting of the first administrative unit to at least one of add or remove an object or adjusting the authorization of an object, and providing instructions to a second administrative unit of the first set of administrative units to deny the adjusting of the first administrative unit to at least one of add or remove an object or deny the adjusting the authorization of an object (SAP ASE 16.0, p. 99, “the "chief_financial_officer" role might contain both the "financial_analyst" and the "salary_administrator" roles. ….can define a role's mutual exclusivity to enforce static or dynamic separation of duty policies. Roles can be defined to be mutually exclusive for: • Membership - one user cannot be granted two different roles. For example, you might not want the "payment_requestor" and "payment_approver" roles to be granted to the same user. …System roles, as well as user-defined roles, can be defined … to be mutually exclusive. For example, you might want a "super user" role to contain the system administrator, operator, and Technical Support roles. To enforce a separation of roles, you may want to define the system administrator and system security officer roles to be mutually exclusive for membership; that is, one user cannot be granted both roles.”; SAP ASE 16.0, p. 101, “The system security officer cannot grant one role to another role that is explicitly or implicitly mutually exclusive at the membership level with the first role. For example, in Mutual exclusivity at membership figure, if the "intern" role is defined as mutually exclusive at the membership level with the "consultant" role, the system security officer cannot grant "intern" to the "doctor.").
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention, to modify O’Byrne to include, as taught by SAP ASE 16.0, an arrangement wherein in response to adjusting the first administrative unit to at least one of add or remove the object, or adjust the authorization of the object, the management service is configured to provide instructions to a first administrative unit of the first plurality of administrative units and a first administrative unit of the second set of administrative units to implement the adjusting of the first administrative unit to at least one of add or remove an object or adjusting the authorization of an object, and providing instructions to a second administrative unit of the first set of administrative units to deny the adjusting of the first administrative unit to at least one of add or remove an object or deny the adjusting the authorization of an object. Motivation for modifying would have been to include long-known “mutual exclusivity” membership options in order to increase a user-friendliness, versatility, attractiveness and broadened adoption of the O’Byrne/ SAP ASE 16.0 combination within the security field.
Per claim 11: O’Byrne disclosed the method of claim 1. O’Byrne did not explicitly disclose an arrangement wherein adjusting the first administrative unit to at least one of add or remove an object or adjust an authorization of an object is based on determining that there are mutually exclusive memberships between two or more administrative units.
However, in an analogous art, SAP ASE 16.0 disclosed an arrangement wherein adjusting the first administrative unit to at least one of add or remove an object or adjust an authorization of an object is based on determining that there are mutually exclusive memberships between two or more administrative units (SAP ASE 16.0, p. 106, “Use the rnut excl roles function to determine whether any two roles assigned to you are mutually exclusive, and the level at which they are mutually exclusive. The syntax is: rnut_excl_roles(<rolel>, <role2> , {membership I activation}) Any user can execute rnut excl roles. It the specified roles, or any role contained by either specified role, are mutually exclusive, rnut excl roles returns 1; if the roles are not mutually exclusive, rnut excl roles returns 0.”; SAP ASE 16.0, p. 101, “The system security officer cannot grant one role to another role that is explicitly or implicitly mutually exclusive at the membership level with the first role. For example, in Mutual exclusivity at membership figure, if the "intern" role is defined as mutually exclusive at the membership level with the "consultant" role, the system security officer cannot grant "intern" to the "doctor.").
It would have been prima facie obvious to one of ordinary skill in the art before the effective filing date of the claimed invention, to modify O’Byrne to include, as taught by SAP ASE 16.0, an arrangement wherein adjusting the first administrative unit to at least one of add or remove an object or adjust an authorization of an object is based on determining that there are mutually exclusive memberships between two or more administrative units. Motivation for modifying would have been to include long-known “mutual exclusivity” membership options in order to increase a user-friendliness, versatility, attractiveness and broadened adoption of the O’Byrne/ SAP ASE 16.0 combination within the security field.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Paul J Skwierawski whose telephone number is (571)272-2642. The examiner can normally be reached 6:00am-3:30pm weekdays.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisory primary examiner (SPE) Luu Pham can be reached on (571) 270-5002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/Paul Skwierawski/
Patent Examiner, Art Unit 2439
/LUU T PHAM/Supervisory Patent Examiner, Art Unit 2439