Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
1. Claims 1-20 have been examined.
Information Disclosure Statement
2. The information disclosure statement (IDS) submitted on 10/17/2025 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
3. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
4. Claims 1-2, 6-8, 10-18 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Agarwal (U.S. Patent Application Publication 2021/0182413; hereafter “Agarwal”), and further in view of Kundu et al. (U.S. Patent Application Publication 2025/0045422; hereafter “Kundu”).
For claims 1, 12 and 20, Agarwal teaches a method, a security object compliance management platform and non-transitory computer-readable medium comprising:
a computing system including a processor and memory, the memory storing instructions executable by the processor (note paragraphs [0088]-[0090], computer system with a processor and memory store program instructions) to:
register, at the security object compliance management platform, a security object storage location (note paragraphs [0024] and [0058], repository zone registers scans from first and second databases, i.e. security object storage locations), wherein the security object storage location maintains one or more security objects (note paragraph [0018], databases maintain security objects, e.g. account credentials, financial information, classified reports);
for each security object maintained in the security object storage location:
receive metadata associated with the security object (note paragraphs [0084] and [0086], scan of objects determines characteristics of the objects and the type of data the object is, i.e. metadata); and
assign a risk score to the security object based on the received metadata (note paragraphs [0034] and [0085]-[0086], based on the characteristics, rules for the objects are determined and if the objects adhere to the rules; these determinations are used to assign a risk score); and
generate an administrative user interface at the security object compliance management platform (note paragraphs [0040] and [0071], risk analyses results are depicted in a user interface for administrators to use).
Agarwal differs from the claimed invention in that they fail to teach:
calculate an overall risk score for the security object storage location based on the risk scores of the one or more security objects;
the administrative user interface including a display of the overall risk score for the security object storage location
Kundu teaches:
calculate an overall risk score for the security object storage location based on the risk scores of the one or more security objects (note paragraph [0030], a risk score per entity, i.e. storage location, may be generated which is an aggregate of risk scores generate from entity data characteristics); and
generate an administrative user interface at the security object compliance management platform, the administrative user interface including a display of the overall risk score for the security object storage location (note paragraphs [0018] and [0066] and Fig. 4A-4B, aggregate risk scores are displayed on a user interface).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the of Agarwal and the aggregate risk score per entity of Kundu to form a system that determines risk scores for security data objects stored in a database (Agarwal) where an aggregate risks score is generated per entity for display in an user interface (Kundu). One of ordinary skill would have been motivated to combine Agarwal and Kundu because it would be more convenient for the user to see a single, aggregated risk score when viewing the user interface to determine the severity of risk for the database entity.
For claim 2, the combination of Agarwal and Kundu teaches claim 1, wherein the metadata associated with the security object is received without receiving the security object (note paragraph [0058] of Agarwal, results of the scans are conveyed to the repository without conveying the data objects).
For claim 6, the combination of Agarwal and Kundu teaches claim 1, wherein a type of metadata received is based on a risk score template (note paragraphs [0022] and [0086] of Agarwal, type of information about data objects received is based on security rules, i.e. risk score template).
For claim 7, the combination of Agarwal and Kundu teaches claim 6, wherein the risk score template is customizable (note paragraphs [0022], [0030] and [0077] of Agarwal, administrator sets security rules).
For claim 8, the combination of Agarwal and Kundu teaches claim 1, wherein calculating the overall risk score for the security object storage location based on the risk scores of the one or more security objects includes:
calculating a weighted average of the risk scores of the one or more security objects (note paragraph [0030] of Kundu, aggregate score could be a weighted average of risk scores).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the of Agarwal and the aggregate risk score per entity of Kundu to form a system that determines risk scores for security data objects stored in a database (Agarwal) where an aggregate risks score is generated per entity for display in an user interface (Kundu). One of ordinary skill would have been motivated to combine Agarwal and Kundu because it would be more convenient for the user to see a single, aggregated risk score when viewing the user interface to determine the severity of risk for the database entity.
For claim 10, the combination of Agarwal and Kundu teaches claim 1, wherein assigning the risk score to the security object based on the received metadata includes:
determining one or more properties of the security object based on metadata (note paragraphs [0085]- [0086] of Agarwal, determination is made whether object properties adhere to security rules);
mapping a score to each of the one or more properties (note paragraphs [0034], [0038] and [0086] of Agarwal, adherence to security rules is mapped to a risk score); and
calculating the risk score as an average of the scores mapped to the one or more properties (note paragraph [0058] of Agarwal, risk score may be a composite average of multiple risk scores of the object).
For claim 11, the combination of Agarwal and Kundu teaches claim 10, wherein the one or more proper properties and the score mapped to each of the one or more properties are defined by a risk score template (note paragraphs [0022] and [0086] of Agarwal, type of information about data objects received is based on security rules, i.e. risk score template).
For claim 13, the combination of Agarwal and Kundu teaches claim 12, wherein the metadata includes properties of the security object associated with compliance with a compliance policy (note paragraphs [0063] and [0086] of Agarwal, data object properties are associated with compliance with security rules).
For claim 14, the combination of Agarwal and Kundu teaches claim 12, wherein the display of the overall risk score for the security object storage location includes a display of the risk scores of the one or more security objects maintained in the security object storage location (note paragraphs [0018]-[0019] of Kundu, user interface includes display of object risk factor).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the of Agarwal and the aggregate risk score per entity of Kundu to form a system that determines risk scores for security data objects stored in a database (Agarwal) where an aggregate risks score is generated per entity for display in an user interface (Kundu). One of ordinary skill would have been motivated to combine Agarwal and Kundu because it would be more convenient for the user to see a single, aggregated risk score when viewing the user interface to determine the severity of risk for the database entity.
For claim 15, the combination of Agarwal and Kundu teaches claim 12, wherein the display of the overall risk score includes a numerical representation of the overall risk score (note paragraphs [0017]-[0018] of Kundu, aggregate score represented as a number).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the of Agarwal and the aggregate risk score per entity of Kundu to form a system that determines risk scores for security data objects stored in a database (Agarwal) where an aggregate risks score is generated per entity for display in an user interface (Kundu). One of ordinary skill would have been motivated to combine Agarwal and Kundu because it would be more convenient for the user to see a single, aggregated risk score when viewing the user interface to determine the severity of risk for the database entity.
For claim 16, the combination of Agarwal and Kundu teaches claim 12, wherein the display of the overall risk score includes a classification of the overall risk score (note paragraph [0017] of Kundu, risk score could be classified as “unsafe” and presented as a red color).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the of Agarwal and the aggregate risk score per entity of Kundu to form a system that determines risk scores for security data objects stored in a database (Agarwal) where an aggregate risks score is generated per entity for display in an user interface (Kundu). One of ordinary skill would have been motivated to combine Agarwal and Kundu because it would be more convenient for the user to see a single, aggregated risk score when viewing the user interface to determine the severity of risk for the database entity.
For claim 17, the combination of Agarwal and Kundu teaches claim 12, wherein to assign the risk score to the security object based on the received metadata includes to:
map one or more scores to one or more properties of the security object identified in the metadata (note paragraph [0019] of Kundu, object property is mapped to a risk factor score); and
calculate an average of the scores mapped to the one or more properties of the security object (note paragraph [0030] of Kundu, aggregate score could be a weighted average of risk scores).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the of Agarwal and the aggregate risk score per entity of Kundu to form a system that determines risk scores for security data objects stored in a database (Agarwal) where an aggregate risks score is generated per entity for display in an user interface (Kundu). One of ordinary skill would have been motivated to combine Agarwal and Kundu because it would be more convenient for the user to see a single, aggregated risk score when viewing the user interface to determine the severity of risk for the database entity.
For claim 18, the combination of Agarwal and Kundu teaches claim 17, wherein when a property is not defined in the metadata, a maximum value is mapped to the property (note paragraph [0058] of Agarwal, when compiling risk scores, worst-case, i.e. maximum value, may be given to object).
5. Claims 3-5 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over the combination of Agarwal and Kundu as applied to claims 1 and 12 above, and further in view of Mahabir et al. (U.S. Patent Application Publication 2020/0304536; hereafter “Mahabir”).
For claim 3, the combination of Agarwal and Kundu differs from the claimed invention in that they fail to teach:
wherein the metadata includes documentation information describing attributes of the security object from a user input.
Mahabir teaches:
wherein the metadata includes documentation information describing attributes of the security object from a user input (note paragraph [0187], risk scan values may be received as user inputs).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the combination of Agarwal and Kundu and the user inputs for a risk scan of Mahabir. It would have been obvious because a simple substitution of one known method (user inputs for collecting risk scan data of Mahabir) for another (automated scan collecting data of Agarwal) would yield the predictable results of a system that determines risk scores for security data objects stored in a database (Agarwal) properties of the objects are collected as user inputs to a scan request (Mahabir).
For claim 4, the combination of Agarwal, Kundu and Mahabir teaches claim 3, wherein a type of documentation information included in the user input is defined by a documentation template (note paragraphs [0031] and [0046] of Agarwal, type of information about data objects received is based on scan model, i.e. documentation template).
For claim 5, the combination of Agarwal, Kundu and Mahabir teaches claim 4, wherein the documentation template is customizable (note paragraph [0050] of Agarwal, administrator can make changes to scan model).
For claim 19, the combination of Agarwal, Kundu and Mahabir teaches claim 12, wherein the computing system is further configured to receive a user input of documentation information associated with a security object of the one or more security objects, wherein documentation information is included in the metadata received for the security object (note paragraph [0187] of Mahabir, risk scan values may be received as user inputs).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the combination of Agarwal and Kundu and the user inputs for a risk scan of Mahabir. It would have been obvious because a simple substitution of one known method (user inputs for collecting risk scan data of Mahabir) for another (automated scan collecting data of Agarwal) would yield the predictable results of a system that determines risk scores for security data objects stored in a database (Agarwal) properties of the objects are collected as user inputs to a scan request (Mahabir).
6. Claim 9 is rejected under 35 U.S.C. 103 as being unpatentable over the combination of Agarwal and Kundu as applied to claim 1 above, and further in view of Cooney (U.S. Patent Application Publication 2024/0275842; hereafter “Cooney”).
For claim 9, the combination of Agarwal and Kundu differs from the claimed invention in that they fail to teach:
wherein registering the security object storage location includes:
receiving, at the compliance management platform, connection parameters for the security object storage location, the connection parameters including a vault location and account details useable for access to the one or more security objects maintained within the security object storage location; and
based on the connection parameters, communicatively connecting the compliance management platform to the security object storage location.
Cooney teaches:
wherein registering the security object storage location includes:
receiving, at the compliance management platform, connection parameters for the security object storage location, the connection parameters including a vault location and account details useable for access to the one or more security objects maintained within the security object storage location (note paragraphs [0104], [0107], [0111] and Fig. 7, scan target address and credentials are received); and
based on the connection parameters, communicatively connecting the compliance management platform to the security object storage location (note paragraph [0113], address and credentials are used to connect to the scan target).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the combination of Agarwal and Kundu and the credentialed scan of Cooney. One of ordinary skill would have been motivated to combine Agarwal, Kundu and Cooney because a credentialed scan can provide highly accurate host based data without the need for a client side agent (note paragraph [0064] of Cooney).
Conclusion
7. The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Mradul et al. (U.S. Patent Application Publication 2024/0394377) discloses generating a risk score for assets (note paragraphs [0021]-[0024]).
Lounsberry (U.S. Patent Application Publication 2022/0261487) discloses augmented secrets (note Fig. 5-6) where a risk score is calculated (note Fig. 13); risk score is based on secret age (note paragraphs [0121]-[0122] and being stored in a TPM (note paragraph [0113]).
8. Any inquiry concerning this communication or earlier communications from the examiner should be directed to DAVID J PEARSON whose telephone number is (571)272-0711. The examiner can normally be reached 8:30 - 6:00 pm; Monday through Friday.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Catherine Thiaw can be reached at (571)270-1138. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
DAVID J. PEARSON
Primary Examiner
Art Unit 2407
/David J Pearson/Primary Examiner, Art Unit 2407