Prosecution Insights
Last updated: October 02, 2026
Application No. 19/175,335

METHOD AND SYSTEM FOR HOSTED ACCESS AND PROCESSING OF DATA

Non-Final OA §103
Filed
Apr 10, 2025
Priority
Apr 23, 2024 — EU 24315211.3
Examiner
NIPA, WASIKA
Art Unit
Tech Center
Assignee
Amadeus S.A.S.
OA Round
1 (Non-Final)
76%
Grant Probability
Favorable
1-2
OA Rounds
1y 4m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 76% — above average
76%
Career Allowance Rate
237 granted / 314 resolved
+15.5% vs TC avg
Strong +30% interview lift
Without
With
+30.0%
Interview Lift
resolved cases with interview
Typical timeline
2y 10m
Avg Prosecution
9 currently pending
Career history
325
Total Applications
across all art units

Statute-Specific Performance

§101
14.2%
-25.8% vs TC avg
§103
55.8%
+15.8% vs TC avg
§102
2.5%
-37.5% vs TC avg
§112
15.1%
-24.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 314 resolved cases

Office Action

§103
Detailed Action The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This is the initial office action that has been issued in response to patent application, 19/175,335, filed on 04/10/2025. Claims 1-17 are currently pending and have been considered below. Claim 1, 9 and 17 are independent claim. Claim 1 has been cancelled. Information Disclosure Statement The information disclosure statements (IDS's) submitted on 07/11/2025 are in compliance with provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Priority The application claims the foreign priority EP 24315211.3 filed on 04/23/2024. Drawings The drawings filed on 04/10/2025 are accepted by the examiner. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim 1-17 are rejected under 35 U.S.C. 103 as being unpatentable over Horton (US Patent No 10,404,757 B1) in view of Kim (US Patent Application Publication No 2020/0311306 A1). Regarding Claim 1, Horton discloses a method, comprising: establishing, at a server, a connection with a data source storing a plurality of records (Horton, Fig-1, col 5, line 15-20, the client 102 may submit data retrieval request. Col5, line 60-65 & col 6, line 1-5, the data store may be database that is organized into one or more database tables, each table having one or more rows and columns, the rows corresponding to individual data entries and the columns corresponding to properties); storing, at the server, mapping data defining a set of access category indicators, and for each access category indicator, a plurality of corresponding access type indicators (Horton, col 6, line 40-50, data entries from the annotation store may encode foreign key or references to the location of the corresponding annotation entries. The data access service may submit receive the data retrieval request from the client and map it to a corresponding request. Col 12, line 45-50, if the privacy policy indicates that the data element should only be used for internal use of an organization, the data privacy processor may use the client’s credential to determine whether the data element should be excluded from a list of data entries); storing, at the server, an access definition including (i) a record identification criterion, (ii) one of the access category indicators, and (iii) an access restriction associated with the access category indicator (Horton, Fig-5, col 15, line 20-60, the client may utilize the public interface to submit a request to store data, wherein the request may include the data, privacy policies and a request context. The data and annotation may be stored in the data store and annotation store); receiving, from a client device, a request to access a portion of the plurality of records, the request including one of the access type indicators (Horton, Fig-5 & 6, col 16, line 25-30, the metadata is received to write or update data. Col 16, line 55-65, the request context may include information such as IP address of the requestor, an intended use indicating how the requested data is to be used, identify information of the requestor (whether the requestor is part of an organization the data belongs to)); determining, from the mapping data, that the access type indicator corresponds to the access category indicator of the access definition (Horton, Col 18, line 40-45, the system may evaluate whether access to the data element should be allowed, wherein the evaluation is based at least in part on the access scheme, an intended use for data element associated with the request and the requestor); and in response to determining that the portion of the plurality of records satisfies the record identification criterion, responding to the request according to the access restriction (Horton, Col 18, line 60-65, the system may determine whether access is allowed. If access is allowed, the system fulfills the request according to the access granted. If the requestor is granted limited or partial access to a result set (access to only a subset of data elements is granted), then the subset may be returned to the user as if the subset was the entire result). Horton does not explicitly teach the following limitation that Kim teaches: portion of plurality of record (Kim, ¶[0013], acquiring a security parameter, applying an obfuscation algorithm to the data using the security parameter and transmitting the data to which the obfuscation algorithm is applied to the external server). Horton in view of Kim are analogous art because they are from the “same field of endeavor” and are from the same “problem solving area”. Namely, they pertain to the field of “accessing data and privacy enforcement”. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the invention to modify the invention of Horton in view of Kim to include the idea of efficiently collecting various data generated, modified and provided by the user, while protecting the user’s personal information (Kim, ¶[0011]). Regarding Claim 2, Horton in view of Kim discloses the method of claim 1, further comprising: providing, at the server, a plurality of hosted data access functions to the client device (Horton, col 14, line 40-50, the client may submit requests to store data and the data access service may perform the business logic to receive data, determine privacy policies applicable to the data, encode the applicable privacy policies as annotation, associate the annotation to the data and coordinate the storage of the data and annotations); wherein receiving the request from the client device includes receiving a selection of one of the hosted data access functions (Horton, col 14, line 55-65, the data request may be routed by the data access service to a database system that is controlled or accessible to the data access service). Regarding Claim 3, Horton in view of Kim discloses the method of claim 2, wherein the plurality of hosted data access functions corresponds to respective ones of the access type indicators (Horton, Col 18, line 40-45, the system may evaluate whether access to the data element should be allowed, wherein the evaluation is based at least in part on the access scheme, an intended use for data element associated with the request and the requestor). Regarding Claim 4, Horton in view of Kim discloses the method of claim 1, wherein the access definition includes: a plurality of access category indicators (Horton, Fig-5 & 6, col 16, line 25-30, the metadata is received to write or update data. Col 16, line 55-65, the request context may include information such as IP address of the requestor, an intended use indicating how the requested data is to be used, identify information of the requestor (whether the requestor is part of an organization the data belongs to)); and for each access category indicator, a corresponding access restriction (Horton, Col 2, line 15-25, these restrictions may include, for example, laws governing or restricting the manner in which the data element may be used, accessed, modified, stored and presented, security policies of an organization collecting the data element which define parameters for how the data element is to be collected, a set of conditions upon which a customer agrees to provide the data element. The same type of data element (biographical information such as age, address, and interests) collected from multiple sources (different individuals) may be subject to different restrictions). Regarding Claim 5, Horton in view of Kim discloses the method of claim 4, wherein the access restriction includes an obfuscation indicator (Kim, ¶[0013], acquiring a security parameter, applying an obfuscation algorithm to the data using the security parameter and transmitting the data to which the obfuscation algorithm is applied to the external server); and wherein responding to the request includes providing access to a first portion of a requested record, and obfuscating a second portion of the requested record (Kim, ¶[0013], acquiring a security parameter, applying an obfuscation algorithm to the data using the security parameter and transmitting the data to which the obfuscation algorithm is applied to the external server). Regarding Claim 6, Horton in view of Kim discloses the method of claim 4, wherein the access restriction includes a time period (Horton, col 3, line 55-65, an annotation may include a restriction that is based on an organization’s policy to delete personal information after 90 days. Col 20, line 15-30, the annotated data element may include one or more rules that specify the manner in which the data element is to be stored, including but not limited to a predetermined or predefined period for which the data can be stored for, a timestamp); and wherein responding to the request includes providing access to the portion of the plurality of records until the time period expires (Horton, col 3, line 55-65, an annotation may include a restriction that is based on an organization’s policy to delete personal information after 90 days. Col 20, line 15-30, the annotated data element may include one or more rules that specify the manner in which the data element is to be stored, including but not limited to a predetermined or predefined period for which the data can be stored for, a timestamp). Regarding Claim 7, Horton in view of Kim discloses the method of claim 6, wherein providing access to the portion of the plurality of records includes generating a copy of the plurality of records in hosted storage at the server (Horton, col 18, line 60-65, if the requestor is granted limited or partial access to a result et (access to only a subset of a data elements is granted), then subset may be returned to the user as if the subset were the entire result (fixed length array is re-sized to have an allocated memory size corresponding to the subset rather than the entire result set that had elements excluded from the response)). Regarding Claim 8, Horton in view of Kim discloses the method of claim 1, wherein the access definition further includes a requestor type indicator, and an access restriction criterion corresponding to the requestor type indicator (Horton, col 9, line 1-10, an implied policy may refer to a privacy policy that is not explicitly provided by the requestor, but is determined from other information provided by the requestor, such as an IP address that may be utilized to determine whether a state’s privacy policy or relevant law is applicable). Regarding Claim 9, Horton discloses a computing device, comprising: a memory storing (Horton, Fig-1): mapping data defining a set of access category indicators, and for each access category indicator, a plurality of corresponding access type indicators (Horton, col 6, line 40-50, data entries from the annotation store may encode foreign key or references to the location of the corresponding annotation entries. The data access service may submit receive the data retrieval request from the client and map it to a corresponding request. Col 12, line 45-50, if the privacy policy indicates that the data element should only be used for internal use of an organization, the data privacy processor may use the client’s credential to determine whether the data element should be excluded from a list of data entries); and an access definition including (i) a record identification criterion, (ii) one of the access category indicators, and (iii) an access restriction associated with the access category indicator a processor configured to (Horton, Fig-5, col 15, line 20-60, the client may utilize the public interface to submit a request to store data, wherein the request may include the data, privacy policies and a request context. The data and annotation may be stored in the data store and annotation store): establish a connection with a data source storing a plurality of records (Horton, Fig-1, col 5, line 15-20, the client 102 may submit data retrieval request. Col5, line 60-65 & col 6, line 1-5, the data store may be database that is organized into one or more database tables, each table having one or more rows and columns, the rows corresponding to individual data entries and the columns corresponding to properties); receive, from a client device, a request to access a portion of the plurality of records, the request including one of the access type indicators (Horton, Fig-5 & 6, col 16, line 25-30, the metadata is received to write or update data. Col 16, line 55-65, the request context may include information such as IP address of the requestor, an intended use indicating how the requested data is to be used, identify information of the requestor (whether the requestor is part of an organization the data belongs to)); determine, from the mapping data, that the access type indicator corresponds to the access category indicator of the access definition (Horton, Col 18, line 40-45, the system may evaluate whether access to the data element should be allowed, wherein the evaluation is based at least in part on the access scheme, an intended use for data element associated with the request and the requestor); and in response to determining that the portion of the plurality of records satisfies the record identification criterion, respond to the request according to the access restriction (Horton, Col 18, line 60-65, the system may determine whether access is allowed. If access is allowed, the system fulfills the request according to the access granted. If the requestor is granted limited or partial access to a result set (access to only a subset of data elements is granted), then the subset may be returned to the user as if the subset was the entire result). Horton does not explicitly teach the following limitation that Kim teaches: portion of plurality of record (Kim, ¶[0013], acquiring a security parameter, applying an obfuscation algorithm to the data using the security parameter and transmitting the data to which the obfuscation algorithm is applied to the external server) Horton in view of Kim are analogous art because they are from the “same field of endeavor” and are from the same “problem solving area”. Namely, they pertain to the field of “accessing data and privacy enforcement”. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the invention to modify the invention of Horton in view of Kim to include the idea of efficiently collecting various data generated, modified and provided by the user, while protecting the user’s personal information (Kim, ¶[0011]). Regarding Claim 10, Horton in view of Kim discloses the computing device of claim 9, wherein the processor is configured to: provide a plurality of hosted data access functions to the client device (Horton, col 14, line 40-50, the client may submit requests to store data and the data access service may perform the business logic to receive data, determine privacy policies applicable to the data, encode the applicable privacy policies as annotation, associate the annotation to the data and coordinate the storage of the data and annotations); and receive the request from the client device by receiving a selection of one of the hosted data access functions (Horton, col 14, line 55-65, the data request may be routed by the data access service to a database system that is controlled or accessible to the data access service). Regarding Claim 11, Horton in view of Kim discloses the computing device of claim 10, wherein the plurality of hosted data access functions correspond to respective ones of the access type indicators (Horton, Col 18, line 40-45, the system may evaluate whether access to the data element should be allowed, wherein the evaluation is based at least in part on the access scheme, an intended use for data element associated with the request and the requestor). Regarding Claim 12, Horton in view of Kim discloses the computing device of claim 9, wherein the access definition includes: a plurality of access category indicators (Horton, Fig-5 & 6, col 16, line 25-30, the metadata is received to write or update data. Col 16, line 55-65, the request context may include information such as IP address of the requestor, an intended use indicating how the requested data is to be used, identify information of the requestor (whether the requestor is part of an organization the data belongs to)); and for each access category indicator, a corresponding access restriction (Horton, Col 2, line 15-25, these restrictions may include, for example, laws governing or restricting the manner in which the data element may be used, accessed, modified, stored and presented, security policies of an organization collecting the data element which define parameters for how the data element is to be collected, a set of conditions upon which a customer agrees to provide the data element. The same type of data element (biographical information such as age, address, and interests) collected from multiple sources (different individuals) may be subject to different restrictions). Regarding Claim 13, Horton in view of Kim discloses the computing device of claim 12, wherein the access restriction includes an obfuscation indicator; and wherein the processor is configured to respond to the request by providing access to a first portion of a requested record, and obfuscating a second portion of the requested record (Kim, ¶[0013], acquiring a security parameter, applying an obfuscation algorithm to the data using the security parameter and transmitting the data to which the obfuscation algorithm is applied to the external server). Regarding Claim 14, Horton in view of Kim discloses the computing device of claim 12, wherein the access restriction includes a time period (Horton, col 3, line 55-65, an annotation may include a restriction that is based on an organization’s policy to delete personal information after 90 days. Col 20, line 15-30, the annotated data element may include one or more rules that specify the manner in which the data element is to be stored, including but not limited to a predetermined or predefined period for which the data can be stored for, a timestamp); and wherein the processor is configured to respond to the request by providing access to the portion of the plurality of records until the time period expires (Horton, col 3, line 55-65, an annotation may include a restriction that is based on an organization’s policy to delete personal information after 90 days. Col 20, line 15-30, the annotated data element may include one or more rules that specify the manner in which the data element is to be stored, including but not limited to a predetermined or predefined period for which the data can be stored for, a timestamp). Regarding Claim 15, Horton in view of Kim discloses the computing device of claim 14, wherein the processor is configured to provide access to the portion of the plurality of records by generating a copy of the plurality of records in hosted storage at the server (Horton, col 18, line 60-65, if the requestor is granted limited or partial access to a result et (access to only a subset of a data elements is granted), then subset may be returned to the user as if the subset were the entire result (fixed length array is re-sized to have an allocated memory size corresponding to the subset rather than the entire result set that had elements excluded from the response)). Regarding Claim 16, Horton in view of Kim discloses the computing device of claim 15, wherein the access definition further includes a requestor type indicator, and an access restriction criterion corresponding to the requestor type indicator (Horton, col 9, line 1-10, an implied policy may refer to a privacy policy that is not explicitly provided by the requestor, but is determined from other information provided by the requestor, such as an IP address that may be utilized to determine whether a state’s privacy policy or relevant law is applicable). Regarding Claim 17, Horton discloses a non-transitory computer-readable medium storing a plurality of instructions executable by a processor of a computing device to: store mapping data defining a set of access category indicators, and for each access category indicator, a plurality of corresponding access type indicators (Horton, col 6, line 40-50, data entries from the annotation store may encode foreign key or references to the location of the corresponding annotation entries. The data access service may submit receive the data retrieval request from the client and map it to a corresponding request. Col 12, line 45-50, if the privacy policy indicates that the data element should only be used for internal use of an organization, the data privacy processor may use the client’s credential to determine whether the data element should be excluded from a list of data entries); store an access definition including (i) a record identification criterion, (ii) one of the access category indicators, and (iii) an access restriction associated with the access category indicator (Horton, Fig-5, col 15, line 20-60, the client may utilize the public interface to submit a request to store data, wherein the request may include the data, privacy policies and a request context. The data and annotation may be stored in the data store and annotation store); establish a connection with a data source storing a plurality of records (Horton, Fig-1, col 5, line 15-20, the client 102 may submit data retrieval request. Col5, line 60-65 & col 6, line 1-5, the data store may be database that is organized into one or more database tables, each table having one or more rows and columns, the rows corresponding to individual data entries and the columns corresponding to properties); receive, from a client device, a request to access a portion of the plurality of records, the request including one of the access type indicators (Horton, Fig-5 & 6, col 16, line 25-30, the metadata is received to write or update data. Col 16, line 55-65, the request context may include information such as IP address of the requestor, an intended use indicating how the requested data is to be used, identify information of the requestor (whether the requestor is part of an organization the data belongs to)); determine, from the mapping data, that the access type indicator corresponds to the access category indicator of the access definition (Horton, Col 18, line 40-45, the system may evaluate whether access to the data element should be allowed, wherein the evaluation is based at least in part on the access scheme, an intended use for data element associated with the request and the requestor); and in response to determining that the portion of the plurality of records satisfies the record identification criterion, respond to the request according to the access restriction (Horton, Col 18, line 60-65, the system may determine whether access is allowed. If access is allowed, the system fulfills the request according to the access granted. If the requestor is granted limited or partial access to a result set (access to only a subset of data elements is granted), then the subset may be returned to the user as if the subset was the entire result). Horton does not explicitly teach the following limitation that Kim teaches: portion of plurality of record (Kim, ¶[0013], acquiring a security parameter, applying an obfuscation algorithm to the data using the security parameter and transmitting the data to which the obfuscation algorithm is applied to the external server) Horton in view of Kim are analogous art because they are from the “same field of endeavor” and are from the same “problem solving area”. Namely, they pertain to the field of “accessing data and privacy enforcement”. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the invention to modify the invention of Horton in view of Kim to include the idea of efficiently collecting various data generated, modified and provided by the user, while protecting the user’s personal information (Kim, ¶[0011]). Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure (see PTO-Form 892). Any inquiry concerning this communication or earlier communications from the examiner should be directed to WASIKA NIPA whose telephone number is (571)272-8923. The examiner can normally be reached on M-F, 8 am to 5 pm. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey Pwu can be reached on 571-272-6798. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, Applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /WASIKA NIPA/ Primary Examiner, Art Unit 2433
Read full office action

Prosecution Timeline

Apr 10, 2025
Application Filed
Aug 12, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750674
SECURE COMMUNICATION FOR COMMISSIONING AND DECOMMISSIONING CIRCUIT BREAKERS AND PANEL SYSTEM
1y 9m to grant Granted Sep 29, 2026
Patent 12744818
IDENTIFYING SERVERLESS FUNCTIONS WITH OVER-PERMISSIVE ROLES
2y 4m to grant Granted Sep 22, 2026
Patent 12732819
DETECTING CELL SITE SIMULATOR
2y 9m to grant Granted Sep 08, 2026
Patent 12726359
SYSTEM AND METHOD FOR PROVIDING INFORMATION USABLE TO IDENTIFY TRUST IN DATA
3y 4m to grant Granted Sep 01, 2026
Patent 12712863
SYSTEM FOR SECURE DATA TRANSMISSION
1y 12m to grant Granted Aug 18, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
76%
Grant Probability
99%
With Interview (+30.0%)
2y 10m (~1y 4m remaining)
Median Time to Grant
Low
PTA Risk
Based on 314 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month