DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Amendment
The amendment filed 20 July 2026 has been entered. Applicant amended claims 1, 4, and 8; and canceled claims 2-3. Accordingly, claims 1 and 4-8 remain pending.
Applicant’s amendment to the abstract overcomes the abstract objection of 05 June 2026. Therefore, the abstract objection of 05 June 2026 is withdrawn.
Response to Arguments
35 USC 112(b) rejection:
Applicant's arguments filed 20 July 2026 have been fully considered but they are not persuasive.
Applicant’s amendment did not address every limitation rejected under 35 USC 112(b) mailed 05 June 2026. For example, the recitation of subsystem and system can encompass any/every software and/or hardware systems which can render the claims indefinite. Additionally, Applicant has failed to provide in the remarks and claims whether the system include hardware and/or software systems components, and whether the measures and rule information pertains to hardware components in a system or software components or both.
The claims do not particularity point out whether the rule information, constraint condition information, and the measure information pertains to software components, hardware components, and/or both in a system/subsystem. The claims do not particularity point out whether the system/subsystem pertains to hardware system or software system. The examiner has interpreted the claims as best understood.
35 USC 101 rejection:
Applicant's arguments filed 20 July 2026 have been fully considered but they are not persuasive.
Applicant’s remarks:
Applicant respectfully submits that at least Applicant's independent claims 1 and 8, as presented herein, are directed to patent-eligible subject matter under 35 U.S.C. § 101 for at least the following reasons.
Applicant’s support:
When considering claim 1 as a whole, as required, the claimed apparatus improves the functioning of operational technology (OT) system security design, which is a specific technical field, by implementing a constraint-matching architecture of subsystems of a system and the components of a subsystem that solves a concrete technical problem the prior art could not, which is the selection of security measures that are both regulation-compliant and physically implementable on the specific embedded hardware (PLCs, SCADAs, IoTGWs) constituting the OT system. The improvement is a technical solution to a technical problem specific to OT systems, as explained in the specification. In view of the trend of the security regulations within and outside Japan, the infrastructure companies are demanded to address the rules including security acts and regulations for the OT systems and OT products of themselves and/or their clients. The presently claimed invention sets forth a computer-implemented specific technical processes under technically relevant conditions. The improvement is also recited in the claims. For example, claim 1 recites "select a subsystem specific measure and a component specific measure from the determined subsystem specific measures and component specific measures based on a priority rank of each component to implement a component specific measure, the priority rank being determined in accordance with predefined policies about the roles and the severity of impact, and generate data to display information indicating the s elected subsystem specific measure and component specific measure, wherein the priority rank is determined depending on the combination of a role and a severity of impact and the predetermined policies are defined to assign a higher priority to a higher severity of impact, wherein the measure information holds information indicating a role and a severity of impact of each component to implement a component specific measure, and wherein the processor is configured to determine subsystem specific measures for a subsystem included in the system and component specific measures for components included in the subsystem from the extracted combinations, based on results of comparison of first constraints and third constraints for the subsystem, results of comparison of second constraints and fourth constraints for each of the components included in the subsystem, and results of comparison of a role and a severity of impact of each of the components indicated in the role information and roles and severity of impact of each of the components indicated in the measure information."
Examiner’s remarks:
The abstract idea mental process involves the limitations “extract one or more of the plurality of combinations to address the first requirement from the measure information, determine subsystem specific measures for a subsystem included in the system and component specific measures for components included in the subsystem from the extracted combinations, based on results of comparison of first constraints and third constraints for the subsystem and results of comparison of second constraints and fourth constraints for each of the components included in the subsystem…select a subsystem specific measure and a component specific measure from the determined subsystem specific measures and component specific measures based on a priority rank of each component to implement a component specific measure, the priority rank being determined in accordance with predefined policies about the roles and the severity of impact, wherein the priority rank is determined depending on the combination of a role and a severity of impact and the predetermined policies are defined to assign a higher priority to a higher severity of impact, wherein the measure information holds information indicating a role and a severity of impact of each component to implement a component specific measure; determine subsystem specific measures for a subsystem included in the system and component specific measures for components included in the subsystem from the extracted combinations, based on results of comparison of first constraints and third constraints for the subsystem, results of comparison of second constraints and fourth constraints for each of the components included in the subsystem, and results of comparison of a role and a severity of impact of each of the components indicated in the role information and roles and severity of impact of each of the components indicated in the measure information”.
Except for the steps being run on a processor, nothing in the claims preclude the steps from being an done in the human mind using pencil and paper, thus an abstract idea mental process. The processor is recited a high level of generality such that it amounts to no more than mere instructions to apply the exception using generic computing components.
Furthermore, the improvements which the Applicant discussed in the remarks appear to be the judicial exception/abstract idea mental process. It is important to note, the judicial exception alone cannot provide the improvement. The improvement can be provided by one or more additional elements. See the discussion of Diamond v. Diehr, 450 U.S. 175, 187 and 191-92, 209 USPQ 1, 10 (1981)). In addition, the improvement can be provided by the additional element(s) in combination with the recited judicial exception. See MPEP 2106.05(a).
However, the claims do not provide additional element that amounts to more than the abstract idea. The additional elements were noted to be the steps being executing by a processor, memory holding/storage information, and generate data to display information. It has been determine that these elements in combination with the abstract idea do not amount to more than the abstract idea, see 35 USC 101 rejection below.
35 USC 103 rejection:
Applicant's arguments filed 20 July 2026 have been fully considered but they are not persuasive.
Applicant’s remarks:
However, Kanai does not disclose "select a subsystem specific measure and a component specific measure from the determined subsystem specific measures and component specific measures based on a priority rank of each component to implement a component specific measure, the priority rank being determined in accordance with predefined policies about the roles and the severity of impact, ... wherein the measure information holds information indicating a role and a severity of impact of each component to implement a component specific measure, and wherein the processor is configured to determine subsystem specific measures for a subsystem included in the system and component specific measures for components included in the subsystem from the extracted combinations, based on results of comparison of first constraints and third constraints for the subsystem, results of comparison of second constraints and fourth constraints for each of the components included in the subsystem, and results of comparison of a role and a severity of impact of each of the components indicated in the role information and roles and severity of impact of each of the components indicated in the measure information," as set forth in claim 1.
Further, resort to Lei does not cure the deficiencies in Kanai. For at least the reasons presented herein, the cited combination of documents does not teach or suggest all of the elements of claim 1. The arguments for patentability of claim 1 also apply to claim 8. Accordingly, Applicant submits that the cited combination of documents does not render independent claims 1 or 8 unpatentable, and respectfully requests that the Office withdraw the § 103 rejection of claims 1 and 8.
The presently pending dependent claims are also allowable over the cited combination of documents at least due to the dependency of these claims from an allowable base claim, as well as for the additional features that each recites. In view of the foregoing, Applicant respectfully requests that the Office withdraw the §103 rejection of the presently pending dependent claims.
Examiner’s remarks:
The generality of the claims do not prevent the prior art of record applied in the 35 USC 103 rejection. Therefore, the examiner maintains that the prior art in the 35 USC rejection teaches the limitations of the claims.
Kanai discloses in Figures 8-15 and paragraph 128 of primary ranking unit that select/identifies and uses suitability information which can corresponds to both the subsystem specific measure and the component specific measure because the suitability is a score that corresponds to the magnitude of the constraint of the system requirements (component specific measure from determined subsystem specific measures) and the magnitude of the influence of the security measures technologies to be ranked on the system (specific measure for a subsystem).
Paragraph 44 of Kanai discloses the limitations of “wherein the measure information holds information indicating a role and a severity of impact of each component to implement a component specific measure”, see OA below.
Paragraphs 91-92 and 128 and Figures 8-15 of Kanai disclose the limitations of “wherein the processor is configured to determine subsystem specific measures for a subsystem included in the system and component specific measures for components included in the subsystem from the extracted combinations, based on results of comparison for each of the components included in the subsystem, and results of comparison of a role and a severity of impact of each of the components indicated in the role information and roles and severity of impact of each of the components indicated in the measure information” as disclosed in the office action below. Lei teaches comparison of first constraints and third constraints and results of comparison of second constraints and fourth constraints (page 4, lines 5- 21 disclose characteristic value of the first data to be compared. If the characteristic value of the first data (first constraint) to be compared with the characteristic value of the vulnerability data (third constraint) is the same, then judging that the target data exists in the target file. A first characteristic value of the first sample data (second constraint) and the second characteristic value of the second sample data (fourth constraint). Therefore, Lei teaches the concepts of comparing different constraints) and based on results of comparison of first constraints and third constraints for the subsystem, results of comparison of second constraints and fourth constraints for each of the components included in the system (page 4, lines 5- 21 disclose characteristic value of the first data to be compared. If the characteristic value of the first data (first constraint) to be compared with the characteristic value of the vulnerability data (third constraint) is the same, then judging that the target data exists in the target file. A first characteristic value of the first sample data (second constraint) and the second characteristic value of the second sample data (fourth constraint). Therefore, Lei teaches the concepts of comparing different constraint). Thus, Lei discloses the deficient limitations which Kanai lacks as disclosed in the OA below.
Examiner’s further remarks:
As indicated in the examiner’s remarks above and the in current office action, the argued limitations in the independent claims do not overcome the prior art applied in the 35 USC 103 rejection. Thus, the independent claims are not allowable over the prior art of record and their dependent claims are not allowed based on their dependencies.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
Claims 1 and 4-8 are rejected under 35 U.S.C. 112(b) as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor regards as the invention.
Claim 1 recites “components included in the system”, however, this language can render the claim indefinite. It is unclear whether components refer to hardware component, software components, or both of a system. It is unclear whether the system include hardware and/or software systems, and whether the measures and rule information pertains to hardware components in a system or software components or both. The examiner has interpreted the limitation as best understood.
Claim 1 further recites “ according to security rules to be satisfied by a system”; however, this limitation can render the claim indefinite. The claim fail to provide the parts or elements or components of the system. It is unclear whether the system pertains to a software system, a mechanical system, electrical system, etc. The examiner has interpreted the limitation as best understood.
Claim 1 further recites a subsystem; however, this limitation can render the claim indefinite. It is unclear whether the subsystem pertains to a software subsystem, a mechanical subsystem, electrical subsystem, etc. The examiner has interpreted the limitation as best understood.
Claim 1 recites “measure information indicating a plurality of combinations”. The claim fails to particularity point out what the combinations entails.
Claim 1 further recites “extract combinations” but fails to define what the combinations are and what they pertain to. Thus the claim does not distinctly claim and particularly point out combinations in “extract combinations”. The examiner has interpreted the limitation as best understood.
Claim 1 recites “role information” and roles, but fails to distinctly claim and particularly point out role information and roles. It is unclear whether the role information pertain to administrative roles by an operator, or function assumed by the system/subsystem components. The examiner has interpreted the limitation as best understood.
Claim 1 further recites “severities of impact onto the system” but fails to distinctly claim and particularly point out severities of impact. The claims do not define these severities nor provide metric that define whether the severity are minor/minimal or major. The claims also do not define what these impacts are on the system of components.
Claims 1 and 7 further recites “generate data” but fail to distinctly claim and particularly point out the data and type of data that is generated. The examiner has interpreted the limitation as best understood.
Claims 4-7 are rejected as being dependent on, and failing to cure the deficiencies of, rejected independent claim 1
Claim 8 recites “components included in the system”, however, this language can render the claim indefinite. It is unclear whether components refer to hardware component, software components, or both of a system. The examiner has interpreted the limitation as best understood.
Claim 8 further recites “a system”; however, this limitation can render the claim indefinite. The claim fail to provide the components of the system. It is unclear whether the system pertains to a software system, a mechanical system, electrical system, etc. The examiner has interpreted the limitation as best understood.
Claim 8 further recites a subsystem; however, this limitation can render the claim indefinite.. It is unclear whether the subsystem pertains to a software subsystem, a mechanical subsystem, electrical subsystem, etc. The examiner has interpreted the limitation as best understood.
Claim 8 recites “measure information indicating a plurality of combinations”. The claim fails to particularity point out what the combinations entails.
Claim 8 further recites “extract combinations” but fail to define what the combinations are and what they pertain to. Thus the claim does not distinctly claim and particularly point out combinations in “extract combinations”. The examiner has interpreted the limitation as best understood.
Claim 8 further recites “generate data” but fail to distinctly claim and particularly point out the type of data that is generated. The examiner has interpreted the limitation as best understood.
Claim 8 recites “role information” and roles, but fails to distinctly claim and particularly point out role information and roles. It is unclear whether the role information pertain to administrative roles by an operator, or function assumed by the system/subsystem components. The examiner has interpreted the limitation as best understood.
Claim 8 further recites “severities of impact onto the system” but fails to distinctly claim and particularly point out severities of impact. The claims do not define these severities nor provide metric that define whether the severity are minor/minimal or major. The claims also do not define what these impacts are on the system of components.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-8 are rejected under 35 U.S.C. 101 because the claimed invention is directed to abstract idea mental process without significantly more. The claim(s) recite(s) “the memory holds: rule information indicating requirements according to security rules to be satisfied by a system to be secured; constraint condition information indicating first constraints on operating states assigned to subsystems included in the system and second constraints on specifications assigned to components included in the system; and possible measure information indicating combinations to satisfy the requirements, each combination including a subsystem specific measure of a measure for a subsystem and a component specific measure of a measure for a subsystem, third constraints to be satisfied by the subsystem to implement the subsystem specific measure, and fourth constraints to be satisfied by the component to implement the component specific measure, and wherein the processor is configured to: receive designation of a first requirement; extract combinations to address the first requirement from the possible measure information; determine subsystem specific measures for a subsystem included in the system and component specific measures for components included in the subsystem from the extracted combinations, based on results of comparison of first constraints and third constraints for the subsystem and results of comparison of second constraints and fourth constraints for each of the components included in the subsystem; and generate data to display information indicating the determined subsystem specific measures and component specific measures.”
The limitations of “extract one or more of the plurality of combinations to address the first requirement from the measure information, determine subsystem specific measures for a subsystem included in the system and component specific measures for components included in the subsystem from the extracted combinations, based on results of comparison of first constraints and third constraints for the subsystem and results of comparison of second constraints and fourth constraints for each of the components included in the subsystem…select a subsystem specific measure and a component specific measure from the determined subsystem specific measures and component specific measures based on a priority rank of each component to implement a component specific measure, the priority rank being determined in accordance with predefined policies about the roles and the severity of impact, wherein the priority rank is determined depending on the combination of a role and a severity of impact and the predetermined policies are defined to assign a higher priority to a higher severity of impact, wherein the measure information holds information indicating a role and a severity of impact of each component to implement a component specific measure; determine subsystem specific measures for a subsystem included in the system and component specific measures for components included in the subsystem from the extracted combinations, based on results of comparison of first constraints and third constraints for the subsystem, results of comparison of second constraints and fourth constraints for each of the components included in the subsystem, and results of comparison of a role and a severity of impact of each of the components indicated in the role information and roles and severity of impact of each of the components indicated in the measure information” pertain to a security measure determination method and are directed to steps under its broadest reasonable interpretation covers performance of the limitation being a mental process abstract idea. The steps recited can manually be performed by a human using pencil and paper. Therefore, nothing in the claimed elements preclude the steps from being an abstract idea. If a claim under its broadest reasonable interpretation covers performance in the mind or by a human using pencil and paper, then the claim falls under the mental process grouping of abstract ideas. Accordingly, claims 1 and 8 recite an abstract idea.
This judicial exception is not integrated into a practical application. The independent claims recite the following additional elements of (a) a processor; and a memory, (b) wherein the memory holds: rule information indicating requirements according to security rules to be satisfied by a system to be secured; constraint condition information indicating first constraints on operating states assigned to subsystems included in the system and second constraints on specifications assigned to components included in the system; and possible measure information indicating combinations to satisfy the requirements, each combination including a subsystem specific measure of a measure for a subsystem and a component specific measure of a measure for a subsystem, third constraints to be satisfied by the subsystem to implement the subsystem specific measure, and fourth constraints to be satisfied by the component to implement the component specific measure; (c) receive designation of a first requirement; and (d) generate data to display information indicating the determined subsystem specific measures and component specific measures.
The additional elements of generic computing components such as memory and processor which executes instructions pertaining to the method as recited in the independent claims are recited at a high level of generality such that it amounts to no more than mere instructions to apply the exception using generic computing components. These additional elements do not integrate the abstract idea into a practical application and are not elements that are sufficient to amount to significantly more than the judicial exception because these generic computing components do not impose meaningful limits on practicing the abstract idea. Thus, the independent claims are not patent eligible under 35 USC 101.
The additional element of “wherein the memory holds: rule information indicating requirements according to security rules to be satisfied by a system to be secured; constraint condition information indicating first constraints on operating states assigned to subsystems included in the system and second constraints on specifications assigned to components included in the system; and possible measure information indicating combinations to satisfy the requirements, each combination including a subsystem specific measure of a measure for a subsystem and a component specific measure of a measure for a subsystem, third constraints to be satisfied by the subsystem to implement the subsystem specific measure, and fourth constraints to be satisfied by the component to implement the component specific measure” is merely storage of data. The limitation of “memory holds role information indicating roles in the system of the components included in the system and severities of impact onto the system of the components further narrow the memory holding limitation”. Storage of data is activity that is routine, well-understood, and conventional activity. Such limitations do not integrate the abstract idea into a practical application and are not elements that are sufficient to amount to significantly more than the judicial exception because the storage of data is routine, well-understood, and conventional activity.
The additional element of “receive designation of a first requirement” is merely transmission of data which is also activity that is routine, well-understood, and conventional activity. Such limitation does not integrate the abstract idea into a practical application and is not an element that is sufficient to amount to significantly more than the judicial exception because the transmission of data is routine, well-understood, and conventional activity.
The additional element of “generate data to display information indicating the determined subsystem specific measures and component specific measures” is extra solution activity or post solution activity of displaying data which is activity that is routine, well-understood, and conventional activity. The limitation of generate data to display information indicating the selected subsystem specific measure and component specific measure is extra solution activity or post solution activity of displaying data which is activity that is routine, well-understood, and conventional activity. Such limitation does not integrate the abstract idea into a practical application and is not an element that is sufficient to amount to significantly more than the judicial exception because the display of data is routine, well-understood, and conventional activity.
Thus, the independent claims are not patent eligible under 35 USC 101.
Claim 4 limitation of “wherein the memory holds a data flow indicating control data and/or communication data for the components included in the system” is merely storage of data. Storage of data is activity that is routine, well-understood, and conventional activity. Such limitations do not integrate the abstract idea into a practical application and are not elements that are sufficient to amount to significantly more than the judicial exception because the storage of data is routine, well-understood, and conventional activity. The limitations of “identify at least one of data size, frequency of communication, and communication protocol of the control data and/or the communication data; and identify the roles in the system of the components included in the system based on the at least one and predetermined conditions on the at least one and store information on the identified roles to the role information” are limitations that applying the broadest reasonable interpretation can be performed in the human mind using pencil and paper. The limitation of the processor is recited at a high level of generality such that it amounts to no more than mere instructions to apply the exception using generic computing components. Thus, claim 4 is not patent eligible under 35 USC 101.
Claim 5 limitations of “wherein the processor is configured to generate data to display information indicating the subsystem and the components to implement the determined subsystem specific measures and component specific measures”. The limitation of generate data to display information is extra solution activity or post solution activity of displaying data which is activity that is routine, well-understood, and conventional activity. The limitation of the processor is recited at a high level of generality such that it amounts to no more than mere instructions to apply the exception using generic computing components. Thus, claim 5 is not patent eligible under 35 USC 101.
Claim 6 merely limits the information stored/held in memory. Storage of data is activity that is routine, well-understood, and conventional activity. Such limitations do not integrate the abstract idea into a practical application and are not elements that are sufficient to amount to significantly more than the judicial exception because the storage of data is routine, well-understood, and conventional activity. For the same reasons above, claim 6 is not patent eligible under 35 USC 101.
Claim 7 limitation of “wherein the memory holds system information indicating components related to each other in the system” is merely storage of data. Storage of data is activity that is routine, well-understood, and conventional activity. Such limitations do not integrate the abstract idea into a practical application and are not elements that are sufficient to amount to significantly more than the judicial exception because the storage of data is routine, well-understood, and conventional activity. The limitations of “in a case of determining that there exists a combination of a subsystem specific measure applicable to a subsystem included in the system and a component specific measure not applicable to a component included in the subsystem in the extracted combinations as a result of determination based on the results of comparison of the first constraints and the third constraints and the results of comparison of the second constraints and the fourth constraints” and “determine an inter-component measure to be implemented to a path between the component and a component related thereto in the system information to address the first requirement.. and wherein inter-component measures are predetermined for individual requirements” are limitations that applying the broadest reasonable interpretation can be performed in the human mind using pencil and paper. The limitation of the processor is recited at a high level of generality such that it amounts to no more than mere instructions to apply the exception using generic computing components. The limitation of generate data to display information is extra solution activity or post solution activity of displaying data which is activity that is routine, well-understood, and conventional activity. For the same reasons above, claim 7 is not patent eligible under 35 USC 101.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1 and 4-8 is/are rejected under 35 U.S.C. 103 as being unpatentable over Kanai et al US 20210288989 (hereinafter Kanai) in view of Lei et al CN 114896473 English Machine Translation (hereinafter Lei).
As to claim 1, Kanai teaches a security measure determination apparatus (abstract and paragraphs 33-34 disclose system into which security measures are introduced/determined. An information processing device ranks security measures. Figure 2 reveals a block diagram showing an example of the hardware configuration of the information processing device) comprising:
a processor (Figure 2, reference number 11 “Processor” and paragraph 59); and
a memory (Figure 2, reference number 14 “Main storage unit”, wherein paragraph 61 reveals the main storage unit is a memory), wherein the memory holds:
rule information indicating requirements according to security rules to be satisfied by a system to be secured (Figure 19, reference number 212 and paragraph 168 reveal security requirement determination unit obtain from the requirement information obtaining unit the security requirements information. Paragraph 68 reveals that each functional blocks -such as the security requirement determination unit and the requirement information obtaining unit are loaded onto the main storage unit. Paragraph 36 discloses the security requirements are conditions for security characteristic of a security measures technology to be introduced into the target system),
constraint condition information indicating first constraints on operating states assigned to subsystems included in the system and second constraints on specifications assigned to components included in the system (Figure 19, reference number 213, Figure 6, and paragraph 163 disclose configuration information management unit that divides the target system into a plurality of subsystems. Paragraph 169 discloses the system requirements determination unit obtains, from the requirement information unit, the system requirements information on the sub system (thus obtaining second constraint). Paragraph 37 discloses the system requirements are conditions that the system must meet in operation of the system (first constraints). Paragraph 4 discloses designing security measures is required with system requirements of the target system taken into consideration. Paragraph 68 reveals that each functional blocks -such as the configuration information management unit, the system requirements determination unit, the security requirement determination unit and the requirement information obtaining unit are loaded onto the main storage unit. Therefore, according to paragraphs 4, 37, 163, 169 the device determine the applicable security measures by considering the constraints on the components included in the system and constraints on the operation of the subsystem included in the system), and
measure information indicating a plurality of combinations to satisfy the requirements, each combination including a subsystem specific measure and a component specific measure for a subsystem (paragraph 128 further reveals primary ranking unit obtains and uses suitability information/possible measure information. The suitability is a score corresponding to the magnitude of the constraint on the system requirements (magnitude of demand) (thus subsystem specific measure for a subsystem) and the magnitude of the influence of the security measures technologies to be ranked on the system (component specific measure of a measure for a subsystem), third constraints to be satisfied by the subsystem to implement the subsystem specific measure (paragraph 128 discloses third constraint corresponding to the magnitude of the constraint on the system requirements in the requirements information), and fourth constraints to be satisfied by one or more the components included in the system to implement the component specific measure (paragraph 128 discloses fourth constraint corresponding an influence of each of the security measures technologies on the system in the influence information . Paragraph 40 discloses threat measure information obtaining unit has a function to obtain security measures technology effective against the threat. Paragraph 43 discloses influence information obtaining unit has a function to obtain influence on system occurring in the introduction of the security measures technology into the target system. Paragraph 49 discloses primary ranking unit can rank the security measures technologies on the basis of the system requirements information and the influence information of the target system (paragraph 190 reveals the processing performed on the target system is performed on the subsystem). Thus, paragraphs 40, 43, 49, and 128 disclose determining possible security measure for a subsystem and a component by considering constraints that have to be satisfied by the subsystem and the component to implement the possible security measure), and
wherein the processor is configured (paragraph 68 discloses the processor reads out and executes the programs from the storage so that each of the functional blocks is loaded onto the main storage unit) to:
receive designation of a first requirement (Figure 19, reference number 203 and 212 and paragraph 168 disclose security requirement determination unit obtains, from the requirements information unit, the security requirements information on the subsystem),
extract one or more of the plurality of combinations to address the first requirement from the possible measure information (paragraph 92 and claim 17 disclose the primary ranking unit ranks the security measures. The processing device ranks the combination based on a degree of satisfaction of the system requirements information and the influence information for each of the one or more security measures. (recall paragraph 190 discloses processing performed on the target system in the first embodiment is performed on the subsystem) ),
determine subsystem specific measures for a subsystem included in the system and component specific measures for components included in the subsystem from the extracted combinations, based on results of comparison of constraints for the subsystem and results of comparison of constraints for each of the components included in the subsystem (paragraph 128 further reveals primary ranking unit obtains and uses suitability information/possible measure information. The suitability is a score corresponding to the magnitude of the constraint on the system requirements (magnitude of demand) (thus subsystem specific measure for a subsystem) and the magnitude of the influence of the security measures technologies to be ranked on the system (component specific measure of a measure for a subsystem. Paragraph 91 also discloses the primary ranking unit obtains information indicating a security measure and information indicating the security characteristics of the security measures. The primary ranking unit also obtains security requirements on the target system. Paragraph 92 and claim 17 disclose the primary ranking unit ranks the security measures. The processing device ranks the combination based on a degree of satisfaction of the system requirements information and the influence information for each of the one or more security measures. (recall paragraph 190 discloses processing performed on the target system in the first embodiment is performed on the subsystem). Therefore the system determines and ranks subsystem specific security measures to address the received security requirement based on comparison of the subsystem constraints and constraints imposed on the subsystem by the security measure. The determining and ranking component specific security measure is based on comparison of the component constraints and constraints imposed on the component by the security measure), and
generate data to display information indicating the determined subsystem specific measures and component specific measures (paragraphs 123 discloses security measures technology is displayed on the display unit of the information processing device or an external display unit of the information processing device so that the proper security measure technology can be presented to the user),
wherein the memory holds role information indicating roles in the system of the components included in the system and severities of impact onto the system of the components (paragraph 44 discloses influence information obtaining unit obtains from the auxiliary storage unit information indicating correspondence between a security measures technology and “influence on system” (thus role on the system components) occurring in the introduction of the security measures technology into the target system and to manage the obtained information in tabular form. “Influence on system” refers to an influence of hindering anticipated functions of the target system in operation of the target system (thus severity of impact onto the system component )) and;
wherein the processor is configured to (paragraph 68 discloses the processor reads out and executes the programs from the storage so that each of the functional blocks is loaded onto the main storage unit):
select a subsystem specific measure and a component specific measure from the determined subsystem specific measures and component specific measures based on a priority rank of each component to implement a component specific measure, the priority rank being determined in accordance with predefined policies about the roles and the severities of impact (paragraph 128 further reveals primary ranking unit obtains/selects and uses suitability information/ measure information. The suitability is a score corresponding to the magnitude of the constraint on the system requirements (magnitude of demand) (thus component specific measure from determined subsystem specific measures) and the magnitude of the influence of the security measures technologies to be ranked on the system (specific measure for a subsystem). Paragraph 91 also discloses the primary ranking unit obtains information indicating a security measure and information indicating the security characteristics of the security measures. The primary ranking unit also obtains security requirements on the target system. Paragraph 92 and claim 17 disclose the primary ranking unit ranks the security measures. The processing device ranks the combination based on a degree of satisfaction of the system requirements information and the influence information for each of the one or more security measures. (recall paragraph 190 discloses processing performed on the target system in the first embodiment is performed on the subsystem)) and
generate data to display information indicating the selected subsystem specific measure and component specific measure (paragraph 123 discloses security measures technology is displayed on the display unit of the information processing device or an external display unit of the information processing device so that the proper security measure technology can be presented to the user), and
wherein the priority rank is determined depending on the combination of a role and a severity of impact and the predetermined policies are defined to assign a higher priority to a higher severity of impact (paragraph 49 discloses the concept of result of ranking of the security measures technologies by the primary ranking unit is sometimes referred to as a primary/priority ranking. The primary ranking unit can rank the security measures technologies on the basis of at least the system requirements information (role information/predetermined policies) and the influence information (severity of impact) of the target system. Further, the number of security measures technologies to be ranked may be one. In a case where the number of security measures technologies to be ranked is one, this security measures technology takes the first place),
wherein the measure information holds information indicating a role and a severity of impact of each component to implement a component specific measure (paragraph 44 discloses influence information obtaining unit obtains from the auxiliary storage unit information indicating correspondence between a security measures technology and “influence on system” (thus role on the system components) occurring in the introduction of the security measures technology into the target system and to manage the obtained information in tabular form. “Influence on system” refers to an influence of hindering anticipated functions of the target system in operation of the target system (thus severity of impact onto the system component )), and
wherein the processor is configured to (paragraph 68 discloses the processor reads out and executes the programs from the storage so that each of the functional blocks is loaded onto the main storage unit) determine subsystem specific measures for a subsystem included in the system and component specific measures for components included in the subsystem from the extracted combinations based on comparison of a role and a severity of impact of each of the components indicated in the role information and roles and severity of impact of each of the components indicated in the measure information (paragraph 128 further reveals primary ranking unit obtains and uses suitability information/possible measure information. The suitability is a score corresponding to the magnitude of the constraint on the system requirements (magnitude of demand) (thus subsystem specific measure for a subsystem) and the magnitude of the influence of the security measures technologies to be ranked on the system (component specific measure of a measure for a subsystem. Paragraph 91 also discloses the primary ranking unit obtains information indicating a security measure and information indicating the security characteristics of the security measures. The primary ranking unit also obtains security requirements on the target system. Paragraph 92 and claim 17 disclose the primary ranking unit ranks the security measures. The processing device ranks the combination based on a degree of satisfaction of the system requirements information and the influence information for each of the one or more security measures. (recall paragraph 190 discloses processing performed on the target system in the first embodiment is performed on the subsystem). Therefore the system determines and ranks subsystem specific security measures to address the received security requirement based on comparison of the subsystem constraints and constraints imposed on the subsystem by the security measure. The determining and ranking component specific security measure is based on comparison of the component constraints and constraints imposed on the component by the security measure. Paragraph 49 discloses a result of ranking of the security measures technologies by the primary ranking unit is sometimes referred to as a primary/priority ranking. The primary ranking unit can rank the security measures technologies on the basis of at least the system requirements information (role information/predetermined policies) and the influence information (severity of impact) of the target system. Further, the number of security measures technologies to be ranked may be one. In a case where the number of security measures technologies to be ranked is one, this security measures technology takes the first place).
Kanai does not teach, but Lei teaches comparison of first constraints and third constraints and results of comparison of second constraints and fourth constraints (page 4, lines 5- 21 disclose characteristic value of the first data to be compared. If the characteristic value of the first data (first constraint) to be compared with the characteristic value of the vulnerability data (third constraint) is the same, then judging that the target data exists in the target file. A first characteristic value of the first sample data (second constraint) and the second characteristic value of the second sample data (fourth constraint). Therefore, Lei teaches the concepts of comparing different constraints) and based on results of comparison of first constraints and third constraints for the subsystem, results of comparison of second constraints and fourth constraints for each of the components included in the system (page 4, lines 5- 21 disclose characteristic value of the first data to be compared. If the characteristic value of the first data (first constraint) to be compared with the characteristic value of the vulnerability data (third constraint) is the same, then judging that the target data exists in the target file. A first characteristic value of the first sample data (second constraint) and the second characteristic value of the second sample data (fourth constraint). Therefore, Lei teaches the concepts of comparing different constraint).
It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify Kanai’s teachings of comparing constraints with Lei’s teaching of comparing multiple constraints to provide an accurate vulnerability data retrieval for operating system (page 4, lines 28-29 of Lei).
As to claim 4, the combination of Kanai in view of Lei teaches wherein the memory holds a data flow indicating control data and/or communication data for the components included in the system (Kanai: Figure 20 and paragraphs 80-82 disclose influence information/data flow indicating communication data of increase in communication delay for the system), and
wherein the processor is configured to (Kanai: paragraph 68 discloses the processor reads out and executes the programs from the storage so that each of the functional blocks is loaded onto the main storage unit):
identify at least one of data size, frequency of communication, and communication protocol of the control data and/or the communication data (Kanai: paragraph 82 discloses for the case where the amount of “increase in communication delay” is quantified), a specific value (X [ms], may be described. Thus, the time in millisecond provides specific value/frequency for the communication delay); and
identify the roles in the system of the components included in the system based on the at least one and predetermined conditions on the at least one and store information on the identified roles to the role information (Kanai: paragraph 44 discloses influence information obtaining unit obtains from the auxiliary storage unit information indicating correspondence between a security measures technology and “influence on system” (thus role on the system components) occurring in the introduction of the security measures technology into the target system and to manage the obtained information in tabular form. “Influence on system” refers to an influence of hindering anticipated functions of the target system in operation of the target system. Recall, paragraph 68 reveals that each functional blocks -such as the configuration information management unit, the system requirements determination unit, the security requirement determination unit and the requirement information obtaining unit are loaded onto the main storage unit).
As to claim 5, the combination of Kanai in view of Lei teaches wherein the processor is configured to (Kanai: paragraph 68 discloses the processor reads out and executes the programs from the storage so that each of the functional blocks is loaded onto the main storage unit) generate data to display information indicating the subsystem and the components to implement the determined subsystem specific measures and component specific measures (Kanai: paragraph 123 discloses security measures technology is displayed on the display unit of the information processing device or an external display unit of the information processing device so that the proper security measure technology can be presented to the user).
As to claim 6, the combination of Kanai in view of Lei teaches wherein each component has an OS, a CPU, and a memory (Kanai: paragraphs 59-60 reveal the device includes processor and memory. The processor executes a program read out to the main storage unit. Paragraph 61 reveals the processor is a CPU. Lei: page 2, Background section reveals an operating system is a program set running on the system/vehicle),
wherein each of the first constraints and the third constraints includes at least either a constraint on the output rate of a subsystem or a constraint on the control cycle of a subsystem (Kanai: paragraph 37 discloses the system requirements are conditions that the system must meet in operation of the system (first constraints). Paragraph 128 discloses third constraint corresponding to the magnitude of the constraint on the system requirements in the requirements information. Paragraph 158 further reveals target systems have a multi-stage system configuration including a plurality of sub systems. In the present specification, a sub system refers to a partial system of a target system including some of devices (sometimes referred to as a constituent device or constituent element) constituting the target system. For example, in a case where a control system is configured of a plurality of network systems such as a field network system, a control network system, and an information network system, the individual network systems correspond to the sub systems of the control system. Therefore, these constraints are constraints on the output of a subsystem) and
wherein each of the second constraints and the fourth constraints includes at least one of a constraint on the kind of the OS of a component, a constraint on a capability of the CPU of a component, a constraint on the capacity of the memory of a component, and a constraint on the control cycle of a component (Kanai: paragraph 169 discloses the system requirements determination unit obtains, from the requirement information unit, the system requirements information on the sub system (thus obtaining second constraint). Paragraph 128 discloses fourth constraint corresponding an influence of each of the security measures technologies on the system in the influence information. Therefore, these constraints can be on the control cycle of a component).
As to claim 7, the combination of Kanai in view of Lei teaches wherein the memory holds system information indicating components related to each other in the system (Kanai: Figure 19, reference number 212 and paragraph 168 reveal security requirement determination unit obtain from the requirement information obtaining unit the security requirements information. Paragraph 68 reveals that each functional blocks -such as the security requirement determination unit and the requirement information obtaining unit are loaded onto the main storage unit. Paragraph 36 discloses the security requirements are conditions for security characteristic of a security measures technology to be introduced into the target system),
wherein, in a case of determining that there exists a combination of a subsystem specific measure applicable to a subsystem included in the system and a component specific measure not applicable to a component included in the subsystem in the extracted combinations as a result of determination based on the results of comparison of the first constraints and the third constraints and the results of comparison of the second constraints and the fourth constraints (Kanai: paragraph 102 discloses security measures technologies for the threat intrusion over network, the IPS takes the first place (recommended measures technology), the host-based FW takes the second place. Paragraph 164 discloses information processing device servers to perform ranking processing of security measure technologies for each sub system of a plurality of subsystem. Therefore, inter-component measures are implemented when the component specific measure is not applicable. The intrusion detection or prevention system is implemented which is commonly and generally known an intercomponent security measure when an antivirus software or host based firewall as component specific security measure is not applicable), the processor is configured to (Kanai: paragraph 68 discloses the processor reads out and executes the programs from the storage so that each of the functional blocks is loaded onto the main storage unit):
determine an inter-component measure to be implemented to a path between the component and a component related thereto in the system information to address the first requirement (Kanai: paragraph 102 discloses security measures technologies for the threat intrusion over network, the IPS takes the first place (recommended measures technology), the host-based FW takes the second place. Paragraph 164 discloses information processing device servers to perform ranking processing of security measure technologies for each sub system of a plurality of subsystem. Therefore, inter-component measures are implemented when the component specific measure is not applicable. The intrusion detection or prevention system is implemented which is commonly and generally known an intercomponent security measure when an antivirus software or host based firewall as component specific security measure is not applicable); and
generate data to display information indicating the determined inter- component measure (Kanai: paragraph 123 discloses security measures technology is displayed on the display unit of the information processing device or an external display unit of the information processing device so that the proper security measure technology can be presented to the user), and
wherein inter-component measures are predetermined for individual requirements (Kanai: paragraph 102 discloses security measures technologies for the threat intrusion over network, the IPS takes the first place (recommended measures technology), the host-based FW takes the second place. Paragraph 164 discloses information processing device servers to perform ranking processing of security measure technologies for each sub system of a plurality of subsystem. Therefore, inter-component measures are implemented when the component specific measure is not applicable. The intrusion detection or prevention system is implemented which is commonly and generally known an intercomponent security measure when an antivirus software or host based firewall as component specific security measure is not applicable).
As to claim 8, Kanai teaches a security measure determination method by a security measure determination apparatus (abstract and paragraphs 33-34 disclose system into which security measures are introduced/determined. An information processing device ranks security measures. Figure 2 reveals a block diagram showing an example of the hardware configuration of the information processing device):
wherein the security measure determination apparatus includes a processor (Figure 2, reference number 11 “Processor” and paragraph 59) and a memory (Figure 2, reference number 14 “Main storage unit”, wherein paragraph 61 reveals the main storage unit is a memory),
wherein the memory holds:
rule information indicating requirements according to security rules to be satisfied by a system to be secured (Figure 19, reference number 212 and paragraph 168 reveal security requirement determination unit obtain from the requirement information obtaining unit the security requirements information. Paragraph 68 reveals that each functional blocks -such as the security requirement determination unit and the requirement information obtaining unit are loaded onto the main storage unit. Paragraph 36 discloses the security requirements are conditions for security characteristic of a security measures technology to be introduced into the target system);
constraint condition information indicating first constraints on operating states assigned to subsystems included in the system and second constraints on specifications assigned to components included in the system (Figure 19, reference number 213, Figure 6, and paragraph 163 disclose configuration information management unit that divides the target system into a plurality of subsystems. Paragraph 169 discloses the system requirements determination unit obtains, from the requirement information unit, the system requirements information on the sub system (thus obtaining second constraint). Paragraph 37 discloses the system requirements are conditions that the system must meet in operation of the system (first constraints). Paragraph 4 discloses designing security measures is required with system requirements of the target system taken into consideration. Paragraph 68 reveals that each functional blocks -such as the configuration information management unit, the system requirements determination unit, the security requirement determination unit and the requirement information obtaining unit are loaded onto the main storage unit. Therefore, according to paragraphs 4, 37, 163, 169 the device determine the applicable security measures by considering the constraints on the components included in the system and constraints on the operation of the subsystem included in the system); and
measure information indicating a plurality of combinations to satisfy the requirements, each combination including a subsystem specific measure and a component specific measure (paragraph 128 further reveals primary ranking unit obtains and uses suitability information/possible measure information. The suitability is a score corresponding to the magnitude of the constraint on the system requirements (magnitude of demand) (thus subsystem specific measure for a subsystem) and the magnitude of the influence of the security measures technologies to be ranked on the system (component specific measure of a measure for a subsystem), third constraints to be satisfied by the subsystem to implement the subsystem specific measure (paragraph 128 discloses third constraint corresponding to the magnitude of the constraint on the system requirements in the requirements information), and fourth constraints to be satisfied by one or more of the components included in the system to implement the component specific measure (paragraph 128 discloses fourth constraint corresponding an influence of each of the security measures technologies on the system in the influence information . Paragraph 40 discloses threat measure information obtaining unit has a function to obtain security measures technology effective against the threat. Paragraph 43 discloses influence information obtaining unit has a function to obtain influence on system occurring in the introduction of the security measures technology into the target system. Paragraph 49 discloses primary ranking unit can rank the security measures technologies on the basis of the system requirements information and the influence information of the target system (paragraph 190 reveals the processing performed on the target system is performed on the subsystem). Thus, paragraphs 40, 43, 49, and 128 disclose determining possible security measure for a subsystem and a component by considering constraints that have to be satisfied by the subsystem and the component to implement the possible security measure)), and
role information indicating roles in the system of the components included in the system and severities of impact onto the system of the components (paragraph 44 discloses influence information obtaining unit obtains from the auxiliary storage unit information indicating correspondence between a security measures technology and “influence on system” (thus role on the system components) occurring in the introduction of the security measures technology into the target system and to manage the obtained information in tabular form. “Influence on system” refers to an influence of hindering anticipated functions of the target system in operation of the target system (thus severity of impact onto the system component )) and;
wherein the measure information holds information indicating a role and a severity of impact of each component to implement a component specific measure (paragraph 44 discloses influence information obtaining unit obtains from the auxiliary storage unit information indicating correspondence between a security measures technology and “influence on system” (thus role on the system components) occurring in the introduction of the security measures technology into the target system and to manage the obtained information in tabular form. “Influence on system” refers to an influence of hindering anticipated functions of the target system in operation of the target system (thus severity of impact onto the system component ))
the security measure determination method comprising:
receiving, by the processor (paragraph 68 discloses the processor reads out and executes the programs from the storage so that each of the functional blocks is loaded onto the main storage unit), designation of a first requirement (Figure 19, reference number 203 and 212 and paragraph 168 disclose security requirement determination unit obtains, from the requirements information unit, the security requirements information on the subsystem);
extracting, by the processor (paragraph 68 discloses the processor reads out and executes the programs from the storage so that each of the functional blocks is loaded onto the main storage unit), one or more of the plurality of combinations to address the first requirement from the possible measure information (paragraph 92 and claim 17 disclose the primary ranking unit ranks the security measures. The processing device ranks the combination based on a degree of satisfaction of the system requirements information and the influence information for each of the one or more security measures. (recall paragraph 190 discloses processing performed on the target system in the first embodiment is performed on the subsystem));
determining, by the processor (paragraph 68 discloses the processor reads out and executes the programs from the storage so that each of the functional blocks is loaded onto the main storage unit), subsystem specific measures for a subsystem included in the system and component specific measures for components included in the subsystem from the extracted combinations, based on results of comparison of constraints for the subsystem, results of comparison of constraints for each of the components included in the subsystem (paragraph 128 further reveals primary ranking unit obtains and uses suitability information/possible measure information. The suitability is a score corresponding to the magnitude of the constraint on the system requirements (magnitude of demand) (thus subsystem specific measure for a subsystem) and the magnitude of the influence of the security measures technologies to be ranked on the system (component specific measure of a measure for a subsystem. Paragraph 91 also discloses the primary ranking unit obtains information indicating a security measure and information indicating the security characteristics of the security measures. The primary ranking unit also obtains security requirements on the target system. Paragraph 92 and claim 17 disclose the primary ranking unit ranks the security measures. The processing device ranks the combination based on a degree of satisfaction of the system requirements information and the influence information for each of the one or more security measures. (recall paragraph 190 discloses processing performed on the target system in the first embodiment is performed on the subsystem). Therefore the system determines and ranks subsystem specific security measures to address the received security requirement based on comparison of the subsystem constraints and constraints imposed on the subsystem by the security measure. The determining and ranking component specific security measure is based on comparison of the component constraints and constraints imposed on the component by the security measure), and results of comparison of a role and severity of impact of each of the components indicated in the role information and roles and a severity of impact of each of the components indicated in the measure information(paragraph 128 further reveals primary ranking unit obtains and uses suitability information/possible measure information. The suitability is a score corresponding to the magnitude of the constraint on the system requirements (magnitude of demand) (thus subsystem specific measure for a subsystem) and the magnitude of the influence of the security measures technologies to be ranked on the system (component specific measure of a measure for a subsystem. Paragraph 91 also discloses the primary ranking unit obtains information indicating a security measure and information indicating the security characteristics of the security measures. The primary ranking unit also obtains security requirements on the target system. Paragraph 92 and claim 17 disclose the primary ranking unit ranks the security measures. The processing device ranks the combination based on a degree of satisfaction of the system requirements information and the influence information for each of the one or more security measures. (recall paragraph 190 discloses processing performed on the target system in the first embodiment is performed on the subsystem). Therefore the system determines and ranks subsystem specific security measures to address the received security requirement based on comparison of the subsystem constraints and constraints imposed on the subsystem by the security measure. The determining and ranking component specific security measure is based on comparison of the component constraints and constraints imposed on the component by the security measure. Figures 8-10 show the ranking of threats by primary ranking unit, wherein paragraph 128 reveals the ranking is based on requirement of the secure measure technology. Figures 8-15 reveal ranking based on the influence of hindering anticipating functions of the target. Figures 8-15 further reveal each security measure technology is ranked/compared and the influence of the security measure technology on system, the comparison is based on the number of unsatisfied security requirement and type of threat. The score value is the severity of impact); and
select a subsystem specific measure and a component specific measure from the determined subsystem specific measures and component specific measures based on a priority rank of each component to implement a component specific measure, the priority rank being determined in accordance with predefined policies about the roles and the severities of impact, wherein the priority rank is determined depending on the combination of role and severity of impact and the predetermined policies are defined to assign a higher priority to a higher severity of impact(paragraph 128 further reveals primary ranking unit obtains/selects and uses suitability information/ measure information. The suitability is a score corresponding to the magnitude of the constraint on the system requirements (magnitude of demand) (thus component specific measure from determined subsystem specific measures) and the magnitude of the influence of the security measures technologies to be ranked on the system (component specific measure for a subsystem. Paragraph 91 also discloses the primary ranking unit obtains information indicating a security measure and information indicating the security characteristics of the security measures. The primary ranking unit also obtains security requirements on the target system. Paragraph 92 and claim 17 disclose the primary ranking unit ranks the security measures. The processing device ranks the combination based on a degree of satisfaction of the system requirements information and the influence information for each of the one or more security measures. (recall paragraph 190 discloses processing performed on the target system in the first embodiment is performed on the subsystem). Figures 8-10 show the ranking of threats by primary ranking unit, wherein paragraph 128 reveals the ranking is based on requirement of the secure measure technology. Figures 8-15 reveal ranking based on the influence of hindering anticipating functions of the target. Figures 8-15 further reveal score in relations to priority/demand, wherein in Figure 10, IDS score -1 corresponds to a large demand/high priority/severe impact. Paragraph 49 discloses the concept of result of ranking of the security measures technologies by the primary ranking unit is sometimes referred to as a primary/priority ranking. The primary ranking unit can rank the security measures technologies on the basis of at least the system requirements information (role information/predetermined policies) and the influence information (severity of impact) of the target system. Further, the number of security measures technologies to be ranked may be one. In a case where the number of security measures technologies to be ranked is one, this security measures technology takes the first place)); and
generating data to display information indicating the selected subsystem specific measures and component specific measures (paragraphs 123 discloses security measures technology is displayed on the display unit of the information processing device or an external display unit of the information processing device so that the proper security measure technology can be presented to the user).
Kanai does not teach, but Lei teaches comparison of first constraints and third constraints and results of comparison of second constraints and fourth constraints (page 4, lines 5- 21 disclose characteristic value of the first data to be compared. If the characteristic value of the first data (first constraint) to be compared with the characteristic value of the vulnerability data (third constraint) is the same, then judging that the target data exists in the target file. A first characteristic value of the first sample data (second constraint) and the second characteristic value of the second sample data (fourth constraint). Therefore, Lei teaches the concepts of comparing different constraints).
It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify Kanai’s teachings of comparing constraints with Lei’s teaching of comparing multiple constraints to provide an accurate vulnerability data retrieval for operating system (page 4, lines 28-29 of Lei).
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: Shinke et al US 20220179966 (hereinafter Shinke).
Shinke discloses obtaining for system components: rule information (paragraph 120) ; measure information (paragraph 117); and priority ranking (paragraphs 145-147).
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to FELICIA FARROW whose telephone number is (571)272-1856. The examiner can normally be reached M - F 7:30am-4:00pm (EST).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached at (571)270-5143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/F.F/Examiner, Art Unit 2437
/ALI S ABYANEH/Primary Examiner, Art Unit 2437