Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
This Office Action is in response to the application 19/057,764 filed 2/19/2025
Claims 1-20 have been examined and are pending in this application.This Action is made Non-FINAL
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 2/19/2025, 12/16/2025 and 12/30/2025 are in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Claim Interpretation
The following is a quotation of 35 U.S.C. 112(f):
(f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof.
The following is a quotation of pre-AIA 35 U.S.C. 112, sixth paragraph:
An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof.
The claims in this application are given their broadest reasonable interpretation using the plain meaning of the claim language in light of the specification as it would be understood by one of ordinary skill in the art. The broadest reasonable interpretation of a claim element (also commonly referred to as a claim limitation) is limited by the description in the specification when 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is invoked.
As explained in MPEP § 2181, subsection I, claim limitations that meet the following three-prong test will be interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph:
(A) the claim limitation uses the term “means” or “step” or a term used as a substitute for “means” that is a generic placeholder (also called a nonce term or a non-structural term having no specific structural meaning) for performing the claimed function;
(B) the term “means” or “step” or the generic placeholder is modified by functional language, typically, but not always linked by the transition word “for” (e.g., “means for”) or another linking word or phrase, such as “configured to” or “so that”; and
(C) the term “means” or “step” or the generic placeholder is not modified by sufficient structure, material, or acts for performing the claimed function.
Use of the word “means” (or “step”) in a claim with functional language creates a rebuttable presumption that the claim limitation is to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites sufficient structure, material, or acts to entirely perform the recited function.
Absence of the word “means” (or “step”) in a claim creates a rebuttable presumption that the claim limitation is not to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is not interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites function without reciting sufficient structure, material or acts to entirely perform the recited function.
Claim limitations in this application that use the word “means” (or “step”) are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. Conversely, claim limitations in this application that do not use the word “means” (or “step”) are not being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action.
This application includes one or more claim limitations that do not use the word “means,” but are nonetheless being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, because the claim limitation(s) uses a generic placeholder that is coupled with functional language without reciting sufficient structure to perform the recited function and the generic placeholder is not preceded by a structural modifier. Such claim limitation is “one processing device configured to receive/store/filter/transmit” as recited in claim 8.
Because these claim limitations are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, they are being interpreted to cover the corresponding structure described in the specification as performing the claimed function, and equivalents thereof.
If applicant does not intend to have these limitations interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, applicant may: (1) amend the claim limitation(s) to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph (e.g., by reciting sufficient structure to perform the claimed function); or (2) present a sufficient showing that the claim limitation(s) recite(s) sufficient structure to perform the claimed function so as to avoid them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103(a) which forms the basis for all obviousness rejections set forth in this Office action:
(a) A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-5, 7-12 and 14-19 are rejected under 35 U.S.C. 103 as being unpatentable over Nobuto Hotta et al. (“Hotta,” US9934378B1) filed April 21, 2015, in view of Google (“Google,” “Android Enterprise Security Paper”), published in April 2021 and further in view of Purvi Desai et al. (“Desai,” US20160050227) filed on August 08, 2014.
Regarding claim 1, Hotta discloses a method of detecting security threats to an enterprise mobile device (Hotta: Fig. 2 steps 210 and 202; Col. 6 Lines 30-35; Col. 7 Lines 20-25; detect security threats in any processes 210 across the mobile computing device 202), the method comprising:
receiving, from one or more detection modules stored on the enterprise mobile device, events describing security threats detected in data (Hotta: Col. 6 Line 23-29; Fig. 2 steps 104, 202 and 208; Fig. 3 steps 302; identification Module 104 [i.e. detection module] monitors for security threats events received from log files 208 in the mobile computing device 202; Col. 7 Lines 20-25; log files 208 record security events of any processes 302 across the device);
storing the events in a security log on the enterprise mobile device (Hotta: Abstract and Fig. 3, step 302; log files are recorded security events performed by processes executing on the computing device);
receiving a request from a remote entity for events to evaluate security threats against the enterprise mobile device (Hotta: Col. 9 Lines 54-64; the logs are requested by the security server [i.e. remote entity] in several ways, which include intervals, real-time or in batches; Col. 11 Lines 30-35; security server may recommend an appropriate security action based on the evaluation of the security threat);
prior to transmitting the events to the remote entity, filtering the events (Hotta: Fig. 2 steps 102 and 206; Fig. 3 step 304; prior to sending the log file from the endpoint computing device to a security server 206 for analysis, filter [i.e. filter module 102] out the non-suspicious events.)
transmitting the filtered events to the remote entity (Hotta: Abstract; sending the filtered log files from the endpoint computing device [i.e. mobile device] to a security server for analysis)
Hotta does not explicitly disclose enterprise mobile device with a personal profile and a work profile; and security threats detected in data from the personal profile and the work profile;
However, in an analogous art, Google discloses an enterprise mobile device wherein said mobile device has a personal profile and a work profile; and security threats detected in data from the personal profile and the work profile (Google: Section "Device and Profile Management" Fig. 6 page 44; BYOD configuration shows Personal Profile and Work Profile; Section "Device Policies" page 45-46; via Device Policy Controller (DPC), an Enterprise Mobility Management (EMM) server can require Google Play Protect and enforce app verification across all users on the device using ENSURE_VERIFY_APPS [i.e., detection spanning both the work profile and personal profile]);
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teaching of Google with the method of Hotta. One would be motivated to implement security threat detection across personal and work profiles to prevent compromising the privacy of one profile by attacking the other. (Google: Section “Work Profile Privacy Model”, page 8).
The combination of Hotta and Google discloses filtering events as recited above, but do not explicitly disclose filtering the events to remove private data such that the events are anonymized.
However, in an analogous art, Desai discloses a method to handle cloud-based security events including the steps of filtering the events to remove private data such that the events are anonymized (Desai: pars. 0027 and 0064 threat data can be anonymized so that data identifying an account is removed or obfuscated).
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teaching of Desai with the method of Hotta and Google. One would have been motivated to anonymize the events and logs transmitted to the remote entity in order to maintain data privacy of the personal profile (Desai: par. 0027).
Regarding claim 2, Hotta, Google and Desai disclose the method of claim 1.
Google further discloses detection modules that are based on machine learning models, heuristics, or rule-based engines (Google: Section “Google Play App Review” page 37; automated application risk analyzer that performs static and dynamic analysis of apps to detect potentially harmful app behavior; the analyzer also leverages machine learning to detect harmful behaviors within applications).
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teaching of Google with the method of Hotta and Desai. One would be motivated to implement detection modules that perform static (e.g. rules-based and heuristics) and dynamic (e.g. machine learning) analysis on security events to detect potentially harmful threats. (Google: Section “Google Play App Review”, page 37).
Regarding claim 3, Hotta, Google and Desai disclose the method of claim 2.
Google further discloses a detection module based on trained machine-learning models deployed on the enterprise mobile device (Google: Section “Google Play App Review” page 37; the analyzer also leverages machine learning to detect harmful behaviors within applications; Section “Conclusion” page 56; Google Play Protect delivers built-in protection on every device, and it is powered machine learning).
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teaching of Google with the method of Hotta and Desai. One would be motivated to use machine learning models in the detection modules to improve the detection accuracy of potentially harmful threats. (Google: Section “Google Play App Review”, page 37).
Regarding claim 4, Hotta, Google and Desai disclose the method of claim 1.
Hotta discloses one or more detection modules are under an operating system (OS) layer of the enterprise mobile device (Hotta: Col 5, lines 63-67; an operating system (OS) creates and/or populate a log file in response to detecting or completing events involved in the process of executing a computing task).
Regarding claim 5, Hotta, Google and Desai disclose the method of claim 1.
Hotta discloses the method of filtering the events occurs prior to storing the events in the security log (Hotta: Fig. 2 steps 102 and 206; Fig. 3 step 304; Prior to sending the log file from the endpoint computing device to a security server 206 for analysis, filter [i.e. filter module 102] out the non-suspicious events.)
Regarding claim 7, Hotta, Google and Desai disclose the method of claim 1.
The combination of Hotta and Desai disclose filtering the events based on rules defining types of details in the events as private (Hotta: Fig. 2 steps 102; filter module 102; Desai: pars. 0060 and 0065; rules to filter private data are defined per organization/violation type, which governs which information is private and kept in the organization’s domain versus sent to the cloud; rules can include, without limitation, not storing data related to a security incident event (e.g., a data leakage event, etc.), not storing data related to specific users, etc.).
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teaching of Desai with the method of Hotta and Google. One would have been motivated to create rules to filter out private data from events transmitted to the remote entity in order to maintain data privacy of the personal profile (Desai: par. 0060).
Regarding claims 8-12, and 14, claim 8-12, and 14 are directed to an electronic device corresponding to the method recited in claims 1-5, and 7, respectively. These claims are similar in scope to claim 1, 2, 3, 4, 5, and 7, respectively, and are therefore rejected under similar rationale.
Regarding claims 15-19, claims 15-19 are directed to a non-transitory machine readable medium corresponding to the method recited in claims 1-5, respectively. These claims are similar in scope to claim 1, 2, 3, 4, and 5, respectively, and are therefore rejected under similar rationale.
Claims 6, 13, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Nobuto Hotta et al. (“Hotta,” US9934378B1) filed April 21, 2015, in view of Google (“Google,” “Android Enterprise Security Paper”), published in April 2021, in view of Purvi Desai et al. (“Desai,” US20160050227) filed on August 08, 2014, and further in view of Abhradeep Guha Thakurta et al. (“Guha,” US20170359364), filed June 30, 2017.
Regarding claim 6, Hotta, Google and Desai disclose the method of claim 1.
The combination of Hotta, Google and Desai discloses filtering events as recited previously in claim 5 above, but does not explicitly disclose filtering the events based on a privacy budget limiting an amount of information relating to a particular user identity from being transmitted to the remote entity.
However, in an analogous art, Guha discloses a method of filtering the events based on a privacy budget limiting an amount of information relating to a particular user [i.e. client] identity from being transmitted to the remote entity (Guha: Abstract, Fig. 1 steps 110 and 130; privacy budget ensures that a client 110 does not transmit too much information to a frequency server 130 [i.e. remote server], thereby compromising the privacy of the client device; pars. 0033; client devices can comprise any type of computing device; Hotta: Fig. 3 steps 304; filter events prior to sending).
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teaching of Guha with the method of Hotta, Google and Desai. One would have been motivated to improve the privacy of particular users by filtering the security events given a privacy budget in order to prevent the unauthorized disclosure of sensitive client information to the remote entity (Guha: par. 0019).
Regarding claim 13, claim 13 is directed to the electronic device corresponding to the method recited in claim 6. Claim 13 is similar in scope to claim 6, and is therefore rejected under similar rationale.
Regarding claim 20, claim 20 is directed to the non-transitory machine readable medium corresponding to the method recited in claim 6. Claim 20 is similar in scope to claim 6, and is therefore rejected under similar rationale.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to RICHARD HERNANDEZ whose telephone number is (571)270-0662. The examiner can normally be reached Monday Friday, 8 a.m. 5 p.m. ET..
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Luu T. Pham can be reached at (571) 270-5002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/R.H./ Examiner, Art Unit 2439
/LUU T PHAM/ Supervisory Patent Examiner, Art Unit 2439