DETAILED ACTION
1. Claims 1-20 are pending in this examination.
Notice of Pre-AIA or AIA Status
2. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
3. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Claim Objections
4. The claims 4, 6-8, 10, 15, and 17-19 are objected to because they include reference numbers which are enclosed within parentheses. i.e. claim 4, (115); claim 6, (125), (107), and (125); similar issues also in claims 7-8, 10, 15, and 17-19.
The examiner request to delete reference numbers which are enclosed within parentheses.
Specification
5. The title of the invention is not descriptive. A new title is required that is clearly indicative of the invention to which the claims are directed.
Double Patenting
6.1. The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the claims at issue are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); and In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on a nonstatutory double patenting ground provided the reference application or patent either is shown to be commonly owned with this application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The USPTO internet Web site contains terminal disclaimer forms which may be used. Please visit http://www.uspto.gov/forms/. The filing date of the application will determine what form should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to http://www.uspto.gov/patents/process/file/efs/guidance/eTD-info-I.jsp.
6.2. Claims 1-5, 7, 11-14, 16, are rejected on the ground of nonstatutory double patenting as being unpatentable over claims US Patent No.12282568, in view of US Patent Application No. 20030088520 to Bohrer et al (“Bohrer”).
Instant application
Claims: 1-5, 7, 11-14, 16
US Patent No.12282568
Claims: 1-2, 4-6, 8, 11, 14-15, 17-18
1. A computer processing device for baggage data processing, the device comprising: one or more processors; and memory coupled with the one or more processors, the memory storing executable instructions that when executed by the one or more processors cause the one or more processors to effectuate operations comprising:
receiving a requestor identifier associated with a data requestor and a unique identifier associated with an item of baggage;
determining, based on the requestor identifier, a trust level associated with the data requestor;
determining a data category associated with each data element of the one or more data elements, wherein each data category has an associated ranking; and
constructing, based on the ranking associated with each data category and the trust level associated with the data requestor,
a set of data elements for the data requestor from the received one or more data elements,
wherein one or more values associated with a data element are removed from data returned to the data requestor based on the determined ranking associated with each data category and the trust level associated with the data requestor.
2. A computer processing device according to claim 1, wherein the operations further comprise receiving a message comprising the plurality of data elements and wherein at least some of the plurality of different data elements or data categories are associated with different rankings.
3. A computer processing device according to claim 1, wherein the operations further comprise sending the set of constructed data elements to the data requestor in response to receiving a data request from the data requestor.
4. A computer processing device according to claim 1, wherein the operations further comprise storing a plurality of different data categories in a database (115) and wherein each category is preferably further sub-divided into a plurality of different sub-categories wherein each sub-category preferably further comprises one or more definitions of sub-sets of related data objects
.
5. A computer processing device according to claim 1, wherein the operations further comprise storing the one or more data elements wherein preferably each data element has an associated data source field or data owner field defining a party providing the data and preferably wherein the party providing is a system or device associated with an airline or airport.
7. A computer processing device according to claim 1, wherein the operations further comprise receiving an authentication token from the data requestor (121).
11. A computer processing device according to claim 1 wherein the module application is configured to filter data based on an event and a category.
Claims 12-15, 16, are rejected for similar reasons as stated above,
US Patent No. 12282568 does not explicitly disclose however in the same field of endeavor, Bohrer discloses receiving one or more data elements associated with the unique identifier and one or more baggage events of the item of baggage ([0078], [0082], FIG. 4a is a block diagram of a Data Request Structure. A request for data is sent from a Data Requester to the Profile Responder, and shown in FIG. 1. A data request identifies a data subject, and includes a request for specific items of data from the data subject. The data request also specifies how it will use the data in the request, in the form of privacy declarations).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of COMI with the teaching of Nagasundaram/Bohrer by including the feature of identification, in order for COMI’s system to enforce privacy preferences on exchanges of personal data across a network.
1. A computer processing device for data processing, the device comprising: one or more processors; and memory coupled with the one or more processors, the memory storing executable instructions that when executed by the one or more processors cause the one or more processors to effectuate operations comprising:
receiving a requestor identifier associated with a data requestor and a search key;
determining, based on the requestor identifier, a trust level associated with the data requestor;
obtaining a plurality of access rules associated with one or more data elements of a plurality of data elements, wherein the one or more data elements are associated with the search key and the plurality of access rules are received from a plurality of data authorities; determining a rule clash between at least two of the access rules; determining, based on the rule clash, a most restrictive rule of the at least two access rules; receiving, based on the most restrictive rule, the one or more data elements associated with the search key;
determining a data category associated with each data element of the one or more data elements associated with the search key, wherein each data category has an associated ranking; and
constructing, based on the ranking associated with each data category and the trust level associated with the data requestor,
a set of data elements for the data requestor from the received one or more data elements,
wherein one or more values associated with a data element are removed from data returned to the data requestor based on the determined ranking associated with each data category and the determined trust level associated with the data requestor.
2. The computer processing device according to claim 1, wherein the operations further comprise receiving a message comprising the plurality of data elements and wherein at least some of the plurality of different data elements are associated with different rankings.
4. The computer processing device according to claim 1, wherein the operations further comprise sending the set of constructed data elements to the data requestor in response to receiving a data request from the data requestor.
5. The computer processing device according to claim 1, wherein the operations further comprise storing a plurality of different data categories in a database and wherein each category is further sub-divided into a plurality of different sub-categories wherein each sub-category further comprises one or more definitions of sub-sets of related data objects.
6. The computer processing device according to claim 1, wherein the operations further comprise storing the one or more data elements wherein each data element has an associated data source field or data owner field defining a party providing the data and wherein the party providing is a system or device associated with an airline or airport.
8. The computer processing device according to claim 1, wherein the operations further comprise receiving an authentication token from the data requestor.
11. The computer processing device according to claim 1, wherein the operations further comprise filtering data based on an event and a category.
Claims 14-15, 17-18, are same as as stated above
This is nonstatutory double patenting rejection.
Claim Rejections - 35 USC § 103
7.1. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
7.2. Claims 1-4, and 6-8 are rejected under 35 U.S.C. 103 as being unpatentable over US Patent Application No. 20120246150 to COMI et al (“COMI”) in view of US Patent No. 9665722 issued to Nagasundaram et al (“Nagasundaram”), and in view of US Patent Application No. 20030088520 to Bohrer et al (“Bohrer”).
Referring to claim 1, COMI teaches a computer processing device for baggage data processing, the device comprising: one or more processors; and memory coupled
with the one or more processors, the memory storing executable instructions that when executed by the one or more processors cause the one or more processors to effectuate operations comprising (COMI, [¶0006]” system for storing data in a data store and providing multi-level access thereto based on a query from a client”):
receiving a requestor identifier associated with a data requestor and identifier associated with an item of baggage (COMI, [¶0031, FIG.3] “the query module receives a query from the client comprised of search parameters and an identity token”);
determining, based on the requestor identifier, a trust level associated with the data requestor (COMI, [¶0032, FIG.3] “At step 304, query module 108 sends the identity token to the database 102 to check for and retrieve credentials based thereon.”, [¶0020]” Database 102 in one embodiment of the present disclosure may be comprised of various account information for users of system 100 including usernames with associated passwords, certificates and credentials therefor. The credentials can vary widely depending upon the specific application system 100 is being used for. Such as, for example, one application may be in the financial services arena. In such an application, one embodiment of system 100 may employ possible credentials in the form of an access level (e.g., uncontrolled, sensitive and proprietary), a compartment (e.g., risk, accounts, and HR), and an association (e.g., client, employee, and auditor)”;
receiving one or more data elements associated with the unique identifier and one or more baggage events of the item of baggage (COMI, [¶0034, FIG.3]” At step 316, the query module 108 receives the search results from the data store 104 along with the filters intact. The search results may be comprised of any tagged data contained in the data store 104 that was identified based on the search parameters.”);
determining a data category associated with each data element of the one or more data elements, wherein each data category has an associated ranking (COMI, [¶0028]” the data module 106 inspects the nature of the data, applies a rule set to create an appropriate security tag and assigns the security tag to the data thereby forming tagged data.”, [¶0029]” the security tag may implement access control attributes in the form of classification, [¶0008]” The access control attributes and filter attributes in one embodiment may each be comprised of a plurality of levels to accommodate addressing individual data having varying degrees of sensitivity.”); and
constructing, based on the ranking associated with each data category and the trust level associated with the data requestor, a set of data elements for the data requestor from the received one or more data elements (COMI, [¶0034]” the query module 108 then applies the search results against the filters to obtain filtered results.”, [¶0036]” filters are created based on the credentials of various users (i.e., clients 120). In such a scenario, the data may be tagged using three different access control attributes, namely, “Classification”, “Compartment”, and “Releasability”. Classification may be the overall sensitivity of the data as related to the risk (such as in legal, financial, or national security) associated with disclosing the data to someone not authorized to see it Compartments may be applied within a classification to restrict access to data to only those communities with a need to use it”, [¶0036]” the access control attributes may be in the form of direct match access control attributes where a direct match is required, or in the form of hierarchical access control attributes where a match is achieved, for example, by having a filter level that is equal to or less than a particular level of an access control attribute.”, [¶0036]” Classification may be in the form of a hierarchical access control attribute such that anyone with a certain clearance level is allowed to see the classification they are cleared for and anything below that level in the hierarchy.”; [¶0028]” the data module 106 inspects the nature of the data, applies a rule set to create an appropriate security tag and assigns the security tag to the data thereby forming tagged data.”, [¶0029]” the security tag may implement access control attributes in the form of classification, [¶0008]” The access control attributes and filter attributes in one embodiment may each be comprised of a plurality of levels to accommodate addressing individual data having varying degrees of sensitivity.”);).
COMI does not explicitly disclose however in the same field of endeavor, Nagasundaram discloses receiver one or more values associated with a data element are removed from data returned to the data requestor based on the determined ranking associated with each data category and the trust level associated with the data requestor ([0096] At step 304, the privacy rules determination module 133 of the privacy computer 130 determines a set of a plurality of privacy rules associated with the recipient computer 140. The plurality of privacy rules may be stored in a privacy rules database 131 that is coupled to the privacy computer 130 and comprises privacy rules that may be used to anonymize private or sensitive data in a message or secure data record. Once the recipient computer 140 is identified, the privacy rules associated with the recipient computer 140 may be determined through any suitable method. For example, a set of privacy rules may be stored at the privacy computer 130 for the recipient computer 140. The set of privacy rules may be customized to the trust or security level of the recipient computer 140 by the secure organization 120. The set of privacy rules identify the private information that should be anonymized before a message is allowed to be transferred. In some embodiments, each recipient computer 140 that may communicate with the secure organization 120 may be provided with a set of privacy rules that correspond to particular access rights. In other embodiments, all recipient computers 140 located outside the secure organization or area 120 may have the same privacy rules applied sent, [0085] Alternatively, in some embodiments, the anonymization modules 136-139 could merely flag the private data to be removed, masked, scrubbed, separated, or de-contexted by the anonymization engine 134 after all the privacy rules have been applied. The anonymization processing modules 136-139 may also save the removed, masked, and/or scrubbed data to a corresponding database for later recreation of the message. [0086] The masking and/or scrubbing module 137 may include a software module configured to mask and/or scrub identified private information that is found in a message, according to one or more privacy rules).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of COMI with the teaching of Nagasundaram by including the feature of Removing data, in order for COMI’s system for implementing an anonymization engine that may be used to provide data protection, access control, and privacy control for sensitive information. Embodiments of the invention relate to systems and methods for providing an anonymization engine. One embodiment of the present invention relates to a method comprising receiving a message directed at a recipient computer located outside a secure area by a privacy computer located within a secure area. The privacy computer may identify private information using a plurality of privacy rules and anonymize the message according to the plurality of privacy rules. Another embodiment may be directed to a method comprising receiving a request for sensitive data from a requesting computer. An anonymization computer may determine a sensitive data record associated with the request and may anonymize the sensitive data record by performing at least two of: removing unnecessary sensitive data entries from the sensitive data record, masking the sensitive data entries to maintain format, separating the sensitive data entries into associated data groupings, and de-contexting the data (Nagasundaram, abstract).
COMI and Nagasundaram does not explicitly disclose however in the same field of endeavor, Bohrer discloses receiving one or more data elements associated with the unique identifier and one or more baggage events of the item of baggage ([0078], [0082], FIG. 4a is a block diagram of a Data Request Structure. A request for data is sent from a Data Requester to the Profile Responder, and shown in FIG. 1. A data request identifies a data subject, and includes a request for specific items of data from the data subject. The data request also specifies how it will use the data in the request, in the form of privacy declarations).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of COMI with the teaching of Nagasundaram/Bohrer by including the feature of identification, in order for COMI’s system to enforce privacy preferences on exchanges of personal data across a network. The current invention consists of improved methods, systems and business methods to enforce privacy preferences on exchanges of personal data across a network. The invention allows a data subject (the person or entity whose data is being exchanged and whose privacy is being dealt with) to specify privacy preferences on subject data that is owned by the subject itself, or owned/held by third parties such as enterprises. These privacy preferences act as constraints on the release of such data that must be satisfied prior to its release. Any request for such data from a requester must be accompanied by a privacy statement describing how each of the requested data will be used by the requester. The data is released only if the privacy declaration of the requester matches the constraints imposed by the data subject via its privacy preferences (Bohrer, [0016]).
Referring to claim 2, the combination of COMI, Nagasundaram and Bohrer discloses a computer processing device according to claim 1, wherein the operations further comprise receiving a message comprising the plurality of data elements and wherein at least some of the plurality of different data elements or data categories are associated with different rankings (COMI, [¶0023]” system 100 is further capable of receiving various forms of information from a data source 118 (shown in ghost form) for scrutinizing, tagging and storing in the data store 104”, [¶0037]” assuming system 100 is being applied to a financial services organization, the different Classification levels may be “uncontrolled”, “sensitive”, and “proprietary”. The different Compartments may be “risk”, “accounts”, and “HR”. The Releasability may be based on the user's “association” with the organization such as with “client”, “employee”, and “auditor”. Now assume there is tagged data in the data store 104 having security tags as set forth in Table 1”).
Referring to claim 3, the combination of COMI, Nagasundaram and Bohrer discloses a computer processing device according to claim 1, wherein the operations further comprise sending the set of constructed data elements to the data requestor in response to receiving a data request from the data requestor (COMI, [¶0006]” The query module is operable to receive the query from the client, retrieve credentials from the database based on the identity token, create filters based on the credentials, search the data store based on the search parameters to obtain search results, apply the search results against the filters to obtain filtered results, and provide the filtered results to the client to thereby provide multi-level access to the data.”, [¶0023]” the access control attributes may be in the form of direct match access control attributes where a direct match is required, or in the form of hierarchical access control attributes where a match is achieved, for example, by having a filter level that is equal to or less than a particular level of an access control attribute. The exact nature of the individual filter attributes and access control attributes implemented in system 100 will largely depend upon that which is most appropriate and suitable for a particular application”).
Referring to claim 4, the combination of COMI, Nagasundaram and Bohrer discloses a computer processing device according to claim 1, wherein the operations further comprise storing a plurality of different data categories in a database (115) and wherein each category is preferably further sub-divided into a plurality of different sub-categories wherein each sub-category preferably further comprises one or more definitions of sub-sets of related data objects (COMI, [¶0036]” the data may be tagged using three different access control attributes, namely, “Classification”, “Compartment”, and “Releasability”. Classification may be the overall sensitivity of the data as related to the risk (such as in legal, financial, or national security) associated with disclosing the data to someone not authorized to see it Compartments may be applied within a classification to restrict access to data to only those communities with a need to use it. Releasability may relate to subgroups (possibly nationality based) which are allowed to access the data. In this particular example of an implementation of the teachings of the present disclosure, Classification may be in the form of a hierarchical access control attribute such that anyone with a certain clearance level is allowed to see the classification they are cleared for and anything below that level in the hierarchy. Compartment and Releasability may require a direct match to the user's approved level. Furthermore, the Compartment and Releasability categories may differ in that the users may have more than one Compartment access control attribute assigned to them while only having a single Releasability related access control attribute assigned.”).
Referring to claim 6, the combination of COMI, Nagasundaram and Bohrer discloses a computer processing device according to claim 1, further comprising a module application (125) for filtering data wherein the module application is preferably coupled to a further application (107) for determining one or more data processing rules wherein the further application is configured to receive a request from the module application (125) and to determine one or more rules stored in a storage means based on data within the request (COMI, [¶0017]” system 100 is comprised of a plurality of databases (namely, a database 102 and a data store 104) in communication with and accessible by a plurality of modules (namely, a data module 106 and a query module 108)”, [¶0032]” At step 310, the query module 108 creates filters based on the credentials retrieved from database 102. As for example, in an application of system 100 to a financial services organization, one embodiment of system 100 may retrieve credentials in the categories of an access level (uncontrolled, sensitive and proprietary), a compartment (risk, accounts, and HR), and an association (client, employee, and auditor) where one or none of the options in each category may be designated. The filters created may preferably be in the form of one or more filter attributes corresponding to the access control attributes in the security tags.”, [¶0034]” The search results may be comprised of any tagged data contained in the data store 104 that was identified based on the search parameters. From step 316, the process proceeds to step 318. At step 318, the query module 108 then applies the search results against the filters to obtain filtered results. In one embodiment, query module 108 may apply the search results against the filters by way of matching the filter attributes to corresponding access control attributes in the security tags of the tagged data contained in the search results.”).
Referring to claim 7, the combination of COMI, Nagasundaram and Bohrer discloses a computer processing device according to claim 1, wherein the operations further comprise receiving an authentication token from the data requestor (121) (COMI, [¶0031]” the query module 108 receives a query from the client 120 comprised of search parameters and an identity token. The identity token may preferably be in the form of a username with a password”).
Referring to claim 8, the combination of COMI, Nagasundaram and Bohrer discloses a computer processing device according to claim 6 wherein the module application (125) is coupled to an application programming interface, API,(123) application and wherein either the module application (125) or application programming interface is configured to validate the received token (COMI, [¶0031]” query module 108 sends the identity token to the database 102 to check for and retrieve credentials based thereon. From step 304, the process proceeds to step 306.”, [¶0032]” At step 306, the query module 108 determines if credentials were retrieved from the database 102. If yes, the process proceeds to step 310. However, if no credentials were retrieved from database 102 based on the identity token, then the process proceeds to step 308. At step 308, query module 108 denies client 120 access to system 100”).
Claim 12, is rejected for similar reasons as stated above, and claim 1.
Claim 13, is rejected for similar reasons as stated above, and claim 2.
Claim 14, is rejected for similar reasons as stated above, and claim 4.
Claim 15, is rejected for similar reasons as stated above, and claim 6.
Claim 16, is rejected for similar reasons as stated above, and claim 7.
Claim 17, is rejected for similar reasons as stated above, and claim 8.
Claim 20, is rejected for similar reasons as stated above, and claim 1.
7.4. Claim 5 are rejected under 35 U.S.C. 103 as being unpatentable over COMI, Nagasundaram and Bohrer as applied to claim above, and in view of US Patent Application No. 20190155940 to LECUE et al (“LECUE”).
Regarding claim 5, the combination of COMI, Nagasundaram and Bohrer discloses the invention as described above. COMI, Nagasundaram and Bohrer do not explicitly disclose however, in the same field of endeavor, LECUE teaches the a computer processing device according to claim 1, wherein the operations further comprise storing the one or more data elements wherein preferably each data element has an associated data source field or data owner field defining a party providing the data and preferably wherein the party providing is a system or device associated with an airline or airport (LECUE, [¶ 0030]” The case evaluation engine 210 queries the case database 220 to retrieve a set of cases. In some examples, the case database 220 is queried for the particular entity (e.g., airport) that the event is associated with, and a set of cases is returned from the case database, the set of cases including cases associated with that entity.”, (LECUE, [¶0019]” system 100 also includes a plurality of domain-specific data sources 120. In accordance with the example context, example domain-specific data sources include, without limitation, a flight data source 122, an aircraft data source 124, and an airport context data source 126. In some examples, one or more domain-specific data sources can be provided from a single provider. For example, an airline operator can provide one or more of the flight data source 122, the aircraft data source 124, and the airport context data source 126. In some examples, one or more domain-specific data sources can be provided from multiple providers. For example, an airline operator can provide the flight data source 122, and the aircraft data source 124, and an airport operator can provide the airport context data”).
It would have been obvious to one of ordinary skill in the art before the effective
filing date of the claimed invention to have modified COMI to incorporate the
teaching of LECUE/ Nagasundaram/ Bohrer to enhance the security through Diagnosis (prediction, description, etc.) of events based on semantic sequences to provide context for a particular domain, and one or more actions to resolve, as recognized by (LECUE [0002]).
7.5. Claim 9 are rejected under 35 U.S.C. 103 as being unpatentable over COMI, Nagasundaram and Bohrer as applied to claim above, and in view of US Patent Application No. 20030154171 to Karp et al (“Karp”).
Regarding claim 9, the combination of COMI, Nagasundaram and Bohrer discloses the invention as described above. COMI, Nagasundaram and Bohrer do not explicitly disclose however, in the same field of endeavor, Karp teaches the computer processing device according to claim 7 wherein the token comprises data identifying the data requestor and an associated search key ([0057]-[0058], [0048]-[0049], also see [0052]-[0055]).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of COMI with the teaching of Karp/ Nagasundaram/ Bohrer by including the feature of toke, in order for COMI’s system to maintaining sensitive information and releasing based on the owner policy. Another method consistent with the present invention also provides for selling personal information. It includes receiving from a requester a request for personal information of a particular owner and specifying a policy related to sale of the personal information. The personal information is validated through a trusted third party, which also determines if the requestor is permitted to receive the requested personal information based upon the policy. The trusted third party provides the requested personal information to the requestor if the requestor is permitted to receive it. (Karp, [0006]).
Claim 18, is rejected for similar reasons as stated above, and claim 9.
7.6. Claim 10 are rejected under 35 U.S.C. 103 as being unpatentable over COMI, Nagasundaram and Bohrer as applied to claim above, and in view of US Patent Application No. 20160191464 to HANSEN et al (“HANSEN”).
Regarding claim 10, the combination of COMI, Nagasundaram and Bohrer discloses the invention as described above. COMI, Nagasundaram and Bohrer do not explicitly disclose however, in the same field of endeavor, HANSEN teaches a computer processing device according to claim 8wherein the API, 123 and module application 125 are embedded within a pre-application module (122) and preferably wherein the pre-application module (122) is configured to distinguish between different types of requests based on the received data and preferably wherein the received data is communicated to one of a plurality of different modules based on the request type (HANSEN, [¶ 0008]” An API call filtering system filters {i.e. represent API 122 which include both functions API 123 and API 123} responses to API call requests received {i.e. represent API 123 functions (call and initiate and response to request)}, via a network, from user devices. The API call filtering system {i.e. represent API 125 functions (in, out, and filtering)} is configured to require personalized API call requests {i.e. personalized the request represent the distinguish process} wherein each API call (except for some minor exceptions) includes a unique endpoint identifier (“UEID”) of the user device making the request.”).
It would have been obvious to one of ordinary skill in the art before the effective
filing date of the claimed invention to have modified COMI to incorporate the
teaching of HANSEN/ Nagasundaram/ Bohrer to utilize the above feature, with the motivation of enhancing the network computer system security and more particularly to defense against some automated attacks on the network computer system, as recognized by (HANSEN [0002]).
Claim 19, is rejected for similar reasons as stated above, and claim 10.
7.7. Claim 11 are rejected under 35 U.S.C. 103 as being unpatentable over COMI, Nagasundaram and Bohrer as applied to claim above, and in view of US Patent Application No. 20130081141 to ANURAG et al (“ANURAG”).
Regarding claim 11, the combination of COMI, Nagasundaram and Bohrer discloses the invention as described above. COMI, Nagasundaram and Bohrer do not explicitly disclose however, in the same field of endeavor, ANURAG teaches a computer processing device according to claim 1 wherein the module application is configured to filter data based on an event and a category (ANURAG, [¶0011] According to an embodiment, a security information and event management system (SIEM) collects event data from sources including network devices and applications, and analyzes the data to identify network security threats. Analyzing may be performed using hierarchal actor category models that organize user data according to predetermined categories.”).
It would have been obvious to one of ordinary skill in the art before the effective
filing date of the claimed invention to have modified COMI to incorporate the
teaching of ANURAG/ Nagasundaram/ Bohrer to utilize the above feature, with the motivation of facilitate acquisitions, searches, and providing results of structured and unstructured data sets, as recognized by (ANURAG [0004]).
8. The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
a). US Patent Application No. 20130159021 to Felsher et al discloses a method of controlling access to records stored within databases, each record having associated access rules, a location identifier, and a content identifier maintained in a centralized index, comprising: receiving a request, communicated from a requestor to a security processor, the request containing a specified content identifier; querying the centralized index to find entries corresponding to the specified content identifier; for each entry, applying the access rules for the record to determine whether the record is accessible; for each accessible record, automatically communicating from the security processor to the database storing the accessible record sufficient information to determine whether it is releasable per a set of native access rules of the database; logically associating the releasable accessible records into a linked set of releasable records; and communicating the linked set of releasable records to the requestor.
b). US Patent Application No. 20160210464 to NÄSLUND el al discloses a method of performing an operation on a data storage for storing data being encrypted with a key K.sup.D associated with an owner of the data is provided. The method includes deriving, for each authorized client C.sub.j, a first key K.sub.Cj and a second key K.sub.Tj, providing the client C.sub.j with the first key K.sub.Cj, and providing a Trusted Third Party (TTP) with the second key K.sub.Tj. The method further includes, at a Policy Enforcement Point, receiving a request for performing the operation on the data storage from a client C.sub.k of the authorized clients, acquiring a first key K.sub.Ck from the client C.sub.k, acquiring a second key K.sub.Tk from the TTP, deriving the key K.sup.D from the first key K.sub.Ck and the second key K.sub.Tk, and performing the operation on the data storage using the derived key K.sup.D. The disclosed trust model uses two-part secret sharing.
Conclusion
9. Any inquiry concerning this communication or earlier communications from the examiner should be directed to HARUNUR RASHID whose telephone number is (571)270-7195. The examiner can normally be reached 9 AM to 5PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Eleni A. Shiferaw can be reached on (571) 272-3867. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
HARUNUR . RASHID
Primary Examiner
Art Unit 2497
/HARUNUR RASHID/Primary Examiner, Art Unit 2497