DETAILED ACTION
Notice of Pre-AIA or AIA Status
1. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
2. Claims 1-17, and 19-21 are pending. Claims 1 and 20-21 are in independent forms. Claims 4-10, 12-14, 16-17, and 19 has been amended. Claims 18 and 22-48 has been cancelled.
Priority
3. No foreign priority is claimed.
Information Disclosure Statement
4. The information disclosure statements (IDS's) submitted on 05/05/2025 is in compliance with provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Drawings
5. The drawings filed on 11/21/2024 are accepted by the examiner.
Double Patenting
6. The non-statutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A non-statutory obviousness-type double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); and In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on a non-statutory double patenting ground provided the conflicting application or patent either is shown to be commonly owned with this application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement.
Effective January 1, 1994, a registered attorney or agent of record may sign a terminal disclaimer. A terminal disclaimer signed by the assignee must fully comply with 37 CFR 3.73(b).
Claims 1-17 are provisionally rejected on the ground of non-statutory obviousness-type double patenting as being unpatentable over claims 1, 3-8, 10-15, and 17-21 of patent No. 12,032,715 in view of Ventura (US 2018/0239897 A1) in further view of Saleh et al. (US 2022/0019901 A1) in further view of Arya (US 2014/0283089 A1). Although the conflicting claims are not identical, they are not patentably distinct from each other because the instant application merely attempts to broaden the scope of the invention by omitting “compile the distributed identifier with one or more preexisting distributed identifiers into a block; initiate a block consensus, wherein the block consensus comprises a miner node verifying the originality of the distributed identifier and the one or more preexisting distributed identifiers of the block; obtain the block consensus from at least one of the miner nodes of the plurality of nodes, wherein the miner node has confirmed that the distributed identifier and the one or more preexisting distributed identifiers is unique by comparing the block to any recorded distributed identifiers in the distributed ledger; and transmit the block to the distributed network, wherein the block is appended to the distributed ledger.”
Since it has been held that omission of an element and its function in a combination where the remaining elements perform the same functions as before involves only routine skill in the art. In re Karison, 136 USPQ 184, Application 19/178784 is an obvious variant of patent No. 12,361,157.
This is a provisional obviousness-type double patenting rejection.
Instant Application 19/178784
Patent No. 12,361,157
Claim 1: A system for securing information in a distributed network via a distributed identifier, the system comprising:
a memory device with computer-readable program code stored thereon;
a communication device;
a processing device operatively coupled to the memory device and the communication device, wherein the processing device is configured to execute the computer-readable program code to:
receive an information entry from one or more domains, wherein the one or more domains comprise one or more nodes of a distributed network, and wherein the information entry is provided to an originating node;
store the information entry on a distributed ledger of the distributed network;
receive a command to generate a distributed identifier for the information entry, wherein the distributed identifier is a generated number associated with the information entry based on information contained in the information entry;
broadcast the distributed identifier generation to a plurality of nodes in the distributed network upon receiving the command; and
generate the distributed identifier, wherein the distributed identifier masks the information entry, wherein generating the distributed identifier comprises:
initiating the distributed identifier generation;
receiving the information entry from the one or more domains;
applying a hash function to the information entry, wherein the information entry comprises one or more character strings;
applying a summing function to outputs of the hash function, wherein the outputs of the hash function comprise a value for each of the one or more character strings based on a hash table; and
summing with a maximum distributed identifier, wherein the maximum distributed identifier is determined from the distributed ledger.
Claim 2: The system of Claim 1, wherein the processing device is further configured to execute the computer-readable program code to: compile the distributed identifier with one or more preexisting distributed identifiers into a block; initiate a block consensus, wherein the block consensus comprises a miner node verifying the originality of the distributed identifier and the one or more preexisting distributed identifiers of the block; obtain the block consensus from at least one of the miner nodes of the plurality of nodes, wherein the miner node has confirmed that the distributed identifier and the one or more preexisting distributed identifiers is unique by comparing the block to any recorded distributed identifiers in the distributed ledger; and transmit the block to the distributed network, wherein the block is appended to the distributed ledger.
Claim 3: The system of Claim 2, wherein comparing the distributed identifier to the one or more pre-existing distributed identifiers in the distributed network further comprises initiating the generation of a new distributed identifier if the distributed identifier is not unique.
Claim 4: The system of Claim 1, wherein receiving a command to generate a distributed identifier for the information entry, comprises receiving from the domain the command to generate the distributed identifier for the information entry, wherein miner nodes of the distributed network prioritize the command to generate the distributed identifier with a plurality of commands to generate distributed identifiers.
Claim 5: The system of Claim 1, wherein the distributed network and distributed ledger are controlled by an entity, such that only a superuser and the domain are capable of accessing the information entry associated with the distributed identifier.
Claim 6: The system of Claim 1, wherein masking the information entry further comprises supplying a hash table to the originating node and a superuser, while not allowing access to the hash table by other nodes in the distributed network.
Claim 7: A computer program product for securing information in a distributed network via a distributed identifier, the computer program product comprising at least one non-transitory computer-readable medium having computer-readable program code portions embodied therein, the computer-readable program code portions comprising:
receiving an information entry from one or more domains, wherein the one or more domains comprise one or more nodes of a distributed network, and wherein the information entry is provided to an originating node;
storing the information entry on a distributed ledger of the distributed network;
receiving a command to generate a distributed identifier for the information entry, wherein the distributed identifier is a generated number associated with the information entry based on information contained in the information entry;
broadcasting the distributed identifier generation to a plurality of nodes in the distributed network upon receiving the command; and
generating the distributed identifier, wherein the distributed identifier masks the information entry, wherein generating the distributed identifier comprises:
initiating the distributed identifier generation;
receiving the information entry from the one or more domains;
applying a hash function to the information entry, wherein the information entry comprises one or more character strings;
applying a summing function to outputs of the hash function, wherein the outputs of the hash function comprise a value for each of the one or more character strings based on a hash table; and
summing with a maximum distributed identifier, wherein the maximum distributed identifier is determined from the distributed ledger.
Claim 8: The computer program product of Claim 7, the computer-readable program code portion further comprising: compiling the distributed identifier with one or more preexisting distributed identifiers into a block; initiating a block consensus, wherein the block consensus comprises a miner node verifying the originality of the distributed identifier and the one or more preexisting distributed identifiers of the block; obtaining the block consensus from at least one of the miner nodes of the plurality of nodes, wherein the miner node has confirmed that the distributed identifier and the one or more preexisting distributed identifiers is unique by comparing the block to any recorded distributed identifiers in the distributed ledger; and transmitting the block to the distributed network, wherein the block is appended to the distributed ledger.
Claim 9: The computer program product of Claim 8, wherein comparing the distributed identifier to the one or more pre-existing distributed identifiers in the distributed network further comprises initiating the generation of a new distributed identifier if the distributed identifier is not unique.
Claim 10: The computer program product of Claim 7, the computer-readable program code portion further comprising: receiving from the domain a command to generate the distributed identifier for the information entry further, wherein miner nodes of the distributed network prioritize the command to generate the distributed identifier with a plurality of commands to generate distributed identifiers.
Claim 11: The computer program product of Claim 7, wherein the distributed network and distributed ledger are controlled by an entity, such that only a superuser and the domain are capable of accessing the information entry associated with the distributed identifier.
Claim 12: The computer program product of Claim 7, wherein masking the information entry further comprises supplying a hash table to the originating node and a superuser, while not allowing access to the hash table by other nodes in the distributed network.
Claim 13: A computer-implemented method for securing information in a distributed network via a distributed identifier, the method comprising:
providing a computing system comprising a computer processing device and a non- transitory computer readable medium, where the non-transitory computer readable medium comprises configured computer program instruction code, such that when said computer program instruction code is operated by said computer processing device, said computer processing device performs the following operations:
receiving an information entry from one or more domains, wherein the one or more domains comprise one or more nodes of a distributed network, and wherein the information entry is provided to an originating node;
storing the information entry on a distributed ledger of the distributed network;
receiving a command to generate a distributed identifier for the information entry, wherein the distributed identifier is a generated number associated with the information entry based on information contained in the information entry;
broadcasting the distributed identifier generation to a plurality of nodes in the distributed network upon receiving the command; and
generating the distributed identifier, wherein the distributed identifier masks the information entry, wherein generating the distributed identifier comprises:
initiating the distributed identifier generation;
receiving the information entry from the one or more domains;
applying a hash function to the information entry, wherein the information entry comprises one or more character strings;
applying a summing function to outputs of the hash function, wherein the outputs of the hash function comprise a value for each of the one or more character strings based on a hash table; and
summing with a maximum distributed identifier, wherein the maximum distributed identifier is determined from the distributed ledger.
Claim 14: The computer-implemented method of Claim 13, wherein the operations of the computer processing device further comprise: compiling the distributed identifier with one or more preexisting distributed identifiers into a block; initiating a block consensus, wherein the block consensus comprises a miner node verifying the originality of the distributed identifier and the one or more preexisting distributed identifiers of the block; obtaining the block consensus from at least one of the miner nodes of the plurality of nodes, wherein the miner node has confirmed that the distributed identifier and the one or more preexisting distributed identifiers is unique by comparing the block to any recorded distributed identifiers in the distributed ledger; and transmitting the block to the distributed network, wherein the block is appended to the distributed ledger.
Claim 15: The computer-implemented method of Claim 14, wherein comparing the distributed identifier to the one or more pre-existing distributed identifiers in the distributed network further comprises initiating the generation of a new distributed identifier if the distributed identifier is not unique.
Claim 16: The computer-implemented method of Claim 13 further comprising receiving from the domain the command to generate the distributed identifier for the information entry, wherein miner nodes of the distributed network prioritize the command to generate the distributed identifier with a plurality of commands to generate distributed identifiers.
Claim 17: The computer-implemented method of Claim 13, wherein masking the information entry further comprises supplying a hash table to the originating node and a superuser, while not allowing access to the hash table by other nodes in the distributed network.
Claim 1: A system for securing information in a distributed network via a distributed identifier, the system comprising:
a memory device with computer-readable program code stored thereon;
a communication device;
a processing device operatively coupled to the memory device and the communication device, wherein the processing device is configured to execute the computer-readable program code to:
receive an information entry from one or more domains, wherein the one or more domains comprise one or more nodes of a distributed network, and wherein the information entry is provided to an originating node;
store the information entry on a distributed ledger of the distributed network;
receive a command to generate a distributed identifier for the information entry, wherein the distributed identifier is a generated number associated with the information entry based on information contained in the information entry;
broadcast the distributed identifier generation to a plurality of nodes in the distributed network upon receiving the command;
generate the distributed identifier, wherein the distributed identifier masks the information entry, wherein generating the distributed identifier comprises:
initiating the distributed identifier generation;
receiving the information entry from the one or more domains;
applying a hash function to the information entry, wherein the information entry comprises one or more character strings;
applying a summing function to outputs of the hash function, wherein the outputs of the hash function comprise a value for each of the one or more character strings based on a hash table; and
summing with a maximum distributed identifier, wherein the maximum distributed identifier is determined from the distributed ledger;
compile the distributed identifier with one or more preexisting distributed identifiers into a block;
initiate a block consensus, wherein the block consensus comprises a miner node verifying the originality of the distributed identifier and the one or more preexisting distributed identifiers of the block;
obtain the block consensus from at least one of the miner nodes of the plurality of nodes, wherein the miner node has confirmed that the distributed identifier and the one or more preexisting distributed identifiers is unique by comparing the block to any recorded distributed identifiers in the distributed ledger; and
transmit the block to the distributed network, wherein the block is appended to the distributed ledger.
2. (Canceled).
Claim 3: The system of Claim 1, wherein comparing the distributed identifier to the one or more pre-existing distributed identifiers in the distributed network further comprises initiating the generation of a new distributed identifier if the distributed identifier is not unique.
Claim 4: The system of Claim 1, wherein receiving a command to generate a distributed identifier for the information entry, comprises receiving from the domain the command to generate the distributed identifier for the information entry, wherein miner nodes of the distributed network prioritize the command to generate the distributed identifier with a plurality of commands to generate distributed identifiers.
Claim 5: The system of Claim 1, wherein the distributed network and distributed ledger are controlled by an entity, such that only a superuser and the domain are capable of accessing the information entry associated with the distributed identifier.
Claim 6: The system of Claim 1, wherein masking the information entry further comprises supplying a hash table to the originating node and a superuser, while not allowing access to the hash table by other nodes in the distributed network.
Claim 7: A computer program product for securing information in a distributed network via a distributed identifier, the computer program product comprising at least one non-transitory computer- readable medium having computer-readable program code portions embodied therein, the computer-readable program code portions comprising:
receiving an information entry from one or more domains, wherein the one or more domains comprise one or more nodes of a distributed network, and wherein the information entry is provided to an originating node;
storing the information entry on a distributed ledger of the distributed network;
receiving a command to generate a distributed identifier for the information entry, wherein the distributed identifier is a generated number associated with the information entry based on information contained in the information entry;
broadcasting the distributed identifier generation to a plurality of nodes in the distributed network upon receiving the command;
generating the distributed identifier, wherein the distributed identifier masks the information entry, wherein generating the distributed identifier comprises:
initiating the distributed identifier generation;
receiving the information entry from the one or more domains;
applying a hash function to the information entry, wherein the information entry comprises one or more character strings;
applying a summing function to outputs of the hash function, wherein the outputs of the hash function comprise a value for each of the one or more character strings based on a hash table; and
summing with a maximum distributed identifier, wherein the maximum distributed identifier is determined from the distributed ledger;
compiling the distributed identifier with one or more preexisting distributed identifiers into a block; initiating a block consensus, wherein the block consensus comprises a miner node verifying the originality of the distributed identifier and the one or more preexisting distributed identifiers of the block; obtaining the block consensus from at least one of the miner nodes of the plurality of nodes, wherein the miner node has confirmed that the distributed identifier and the one or more preexisting distributed identifiers is unique by comparing the block to any recorded distributed identifiers in the distributed ledger; and transmitting the block to the distributed network, wherein the block is appended to the distributed ledger.
8. (Canceled).
Claim 9: The computer program product of Claim 7, wherein comparing the distributed identifier to the one or more pre-existing distributed identifiers in the distributed network further comprises initiating the generation of a new distributed identifier if the distributed identifier is not unique.
Claim 10: The computer program product of Claim 7 the computer-readable program code portion further comprising: receiving from the domain a command to generate the distributed identifier for the information entry further, wherein miner nodes of the distributed network prioritize the command to generate the distributed identifier with a plurality of commands to generate distributed identifiers.
Claim 11: The computer program product of Claim 7, wherein the distributed network and distributed ledger are controlled by an entity, such that only a superuser and the domain are capable of accessing the information entry associated with the distributed identifier.
Claim 12: The computer program product of Claim 7, wherein masking the information entry further comprises supplying a hash table to the originating node and a superuser, while not allowing access to the hash table by other nodes in the distributed network.
Claim 13: A computer-implemented method for securing information in a distributed network via a distributed identifier, the method comprising:
providing a computing system comprising a computer processing device and a non- transitory computer readable medium, where the non-transitory computer readable medium comprises configured computer program instruction code, such that when said computer program instruction code is operated by said computer processing device, said computer processing device performs the following operations:
receiving an information entry from one or more domains, wherein the one or more domains comprise one or more nodes of a distributed network, and wherein the information entry is provided to an originating node;
storing the information entry on a distributed ledger of the distributed network;
receiving a command to generate a distributed identifier for the information entry, wherein the distributed identifier is a generated number associated with the information entry based on information contained in the information entry;
broadcasting the distributed identifier generation to a plurality of nodes in the distributed network upon receiving the command;
generating the distributed identifier, wherein the distributed identifier masks the information entry, wherein generating the distributed identifier comprises:
initiating the distributed identifier generation;
receiving the information entry from the one or more domains;
applying a hash function to the information entry, wherein the information entry comprises one or more character strings;
applying a summing function to outputs of the hash function, wherein the outputs of the hash function comprise a value for each of the one or more character strings based on a hash table; and
summing with a maximum distributed identifier, wherein the maximum distributed identifier is determined from the distributed ledger;
compiling the distributed identifier with one or more preexisting distributed identifiers into a block; initiating a block consensus, wherein the block consensus comprises a miner node verifying the originality of the distributed identifier and the one or more preexisting distributed identifiers of the block; obtaining the block consensus from at least one of the miner nodes of the plurality of nodes, wherein the miner node has confirmed that the distributed identifier and the one or more preexisting distributed identifiers is unique by comparing the block to any recorded distributed identifiers in the distributed ledger; and transmitting the block to the distributed network, wherein the block is appended to the distributed ledger.
14. (Canceled).
Claim 15: The computer-implemented method of Claim 13, wherein comparing the distributed identifier to the one or more pre-existing distributed identifiers in the distributed network further comprises initiating the generation of a new distributed identifier if the distributed identifier is not unique.
Claim 16: The computer-implemented method of Claim 13 further comprising receiving from the domain the command to generate the distributed identifier for the information entry, wherein miner nodes of the distributed network prioritize the command to generate the distributed identifier with a plurality of commands to generate distributed identifiers.
Claim 17: The computer-implemented method of Claim 13, wherein masking the information entry further comprises supplying a hash table to the originating node and a superuser, while not allowing access to the hash table by other nodes in the distributed network.
Claim Rejections - 35 USC § 103
7. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
8. Claims 1, 4-7, 10-13, and 16-17 are rejected under 35 U.S.C. 103 as being unpatentable over Ventura US Patent Application Publication No. 2018/0239897 (hereinafter Ventura) in view of Saleh et al. US Patent Application Publication No. 2022/0019901 (hereinafter Saleh) in further view of Arya US Patent Application Publication No. 2014/0283089 (hereinafter Arya).
Regarding claim 1, Ventura discloses a system for resource transfer monitoring and authorization, the system comprising:
“a memory device with computer-readable program code stored thereon” (see Ventura par. 0023, a computer program product for securely executing a function of a distributed system is provided. In an example embodiment, the computer program product comprises at least one non-transitory computer-readable storage medium having computer-executable program code instructions stored therein);
“a communication device” (Fig. 2, communication interface);
a processing (Fig. 2, processing element) device operatively coupled to the memory device and the communication device, wherein the processing device is configured to execute the computer-readable program code to:
“receive an information entry from one or more domains, wherein the one or more domains comprise one or more nodes of a distributed network, and wherein the information entry is provided to an originating node” (see Ventura par. 0044, a user computing entity 30 may be a computing entity configured for user interaction (e.g., via a user interface thereof) for receiving, generating, and/or providing requests from a user to the distributed system. In various embodiments, a user may be a person interacting with a user computing entity 30 (e.g., via the user interface thereof) or a machine user (e.g., an application, service, and/or the like operating on the user computing entity 30). In various embodiments, the user computing entity may receive, generate, and/or provide requests to create or generate a TA-NET, add a node computing entity 200, 200′ to an existing TA-NET, update a trusted application (e.g., the TA-SEC and/or the supplemental domain of a trusted application (TA-SUP)), execute and/or provide a function of a trusted application of the TA-NET, and/or the like);
“store the information entry on a distributed ledger of the distributed network” (see Ventura par. 0094, if the secure ledger is a distributed ledger, posting the new entry to the secure ledger 430 may comprise storing the new entry in the local ledger files 432 and distributing and/or disseminating the new entry via the distributed ledger in accordance with the validation and/or consensus process of the ledger);
“receive a command to generate a distributed identifier for the information entry, wherein the distributed identifier is a generated number associated with the information entry based on information contained in the information entry” (see Ventura par. 0092, At 816, the first TA-SEC 428A may request (e.g., provide a get call/command) to the secure ledger 430 (or another secured shared resource) to access the information/data stored in the secure ledger 430 (or other secured shared resource) that is required for executing and/or performing the requested function. The requested data may be received from the secure ledger 430 (or other secured shared resource) at the first TA-SEC 428A. In an example embodiment, the secure ledger 430 is a distributed ledger and a copy of the distributed ledger is stored in local ledger files 432 in an appropriate location in memory 210, 215 (e.g., a location accessible via the trusted execution environment 420A). In such an embodiment, the requested data may be accessed from the local ledger files 432);
Ventura does not explicitly discloses broadcast the distributed identifier generation to a plurality of nodes in the distributed network upon receiving the command.
However, in analogues art, Saleh discloses broadcast the distributed identifier generation to a plurality of nodes in the distributed network upon receiving the command (see Saleh par. 0151, When the ordering service 710 initializes a new data block 730, the new data block 730 may be broadcast to committing peers (e.g., blockchain nodes 711, 712, and 713). In response, each committing peer validates the transaction within the new data block 730 by checking to make sure that the read set and the write set still match the current world state in the state database 724. Specifically, the committing peer can determine whether the read data that existed when the endorsers simulated the transaction is identical to the current world state in the state database 724. When the committing peer validates the transaction, the transaction is written to the blockchain 722 on the distributed ledger 720, and the state database 724 is updated with the write data from the read-write set).
Therefore it would have been obvious to a person of ordinary skill in the art before the effective filing date of the application to Incorporate the teachings of Saleh into the system of Ventura to include An ordering-service-node or orderer is a node running the communication service for all nodes, and which implements a delivery guarantee, such as a broadcast to each of the peer nodes in the system when committing transactions and modifying a world state of the blockchain (see Saleh par. 0042).
Ventura in view of Saleh does not explicitly discloses generate the distributed identifier, wherein the distributed identifier masks the information entry. However, in analogues art, generate the distributed identifier, wherein the distributed identifier masks the information entry (see Arya pars. 0019-0020, The encryption platform 110 may be further configured to utilize a masking engine 118 to generate mask sequence values 122 for the sensitive personal information 102 extracted from the stored data records 104. The mask sequence value 122 may be arbitrary identifiers unique to respective elements of sensitive personal information 102. Thus, the mask sequence values 122 may be used in database operations in place of the sensitive personal information 102 and without exposing the underlying sensitive personal information 102 values. In some cases, different sequences of mask sequence values 122 may be used for masking different types of sensitive personal information 102 (e.g., a first sequence for social security numbers, a second sequence for tax identifiers, etc.)).
Therefore it would have been obvious to a person of ordinary skill in the art before the effective filing date of the application to Incorporate the teachings of Arya into the system of Ventura and Saleh to include a system may be designed to safeguard sensitive personal information included in data records by replacing the sensitive personal information with generated mask identifiers that cannot be reversed by a receiving party (see Arya par. 0011).
Regarding claims 4, 10, and 16, Ventura in view of Saleh in further view Arya discloses the system of Claim 1, the computer program product of Claim 7, the computer-implemented method of Claim 13,
Ventura further discloses wherein receiving a command to generate a distributed identifier for the information entry, comprises receiving from the domain the command to generate the distributed identifier for the information entry, wherein miner nodes of the distributed network prioritize the command to generate the distributed identifier with a plurality of commands to generate distributed identifiers (see Ventura par. 0082, At 710, a second TA-HOST 428B of the one or more second TA-HOSTS 422B may request the entry (e.g., instance of information/data and/or record, block, and/or the like) comprising the at least a portion of the update from the secure ledger 430 (e.g., via a get or read command issued to the secure ledger 430). For example, the second TA-HOST 422B may request the entry (e.g., instance of information/data and/or record, block, and/or the like) responsive to detecting, identifying, and/or determining that the entry has been added to the secure ledger 430. In an example embodiment, the second TA-HOST 422B may periodically and/or regularly request entries (e.g., instances of information/data and/or records, blocks and/or the like) written to the secure ledger 430 since the previous read and/or get request was submitted to the secure ledger 420 by the TA-HOST 422B. In another example, the first TA-HOST 422A may provide (e.g., transmit) a notification via the TA-NET and/or the like regarding the update of the TA-SEC 428A based on the update).
Regarding claims 5 and 11, Ventura in view of Saleh in further view of Arya discloses the system of Claim 1, the computer program product of Claim 7,
Ventura further discloses wherein the distributed network and distributed ledger are controlled by an entity, such that only a superuser and the domain are capable of accessing the information entry associated with the distributed identifier (see Ventura par. 0044, a user computing entity 30 may be a computing entity configured for user interaction (e.g., via a user interface thereof) for receiving, generating, and/or providing requests from a user to the distributed system. In various embodiments, a user may be a person interacting with a user computing entity 30 (e.g., via the user interface thereof) or a machine user (e.g., an application, service, and/or the like operating on the user computing entity 30). In various embodiments, the user computing entity may receive, generate, and/or provide requests to create or generate a TA-NET, add a node computing entity 200, 200′ to an existing TA-NET, update a trusted application (e.g., the TA-SEC and/or the supplemental domain of a trusted application (TA-SUP)), execute and/or provide a function of a trusted application of the TA-NET, and/or the like).
Regarding claims 6, 12, and 17, Ventura in view of Saleh in further view of Arya discloses the system of Claim 1, the computer program product of Claim 7, the computer-implemented method of Claim 13,
Saleh further discloses wherein masking the information entry further comprises supplying a hash table to the originating node and a superuser, while not allowing access to the hash table by other nodes in the distributed network (see Saleh par. 0083, In structure 362, valid transactions are formed into a block and sealed with a lock (hash). This process may be performed by mining nodes among the nodes 354. Mining nodes may utilize additional software specifically for mining and creating blocks for the permissionless blockchain 352. Each block may be identified by a hash (e.g., 256 bit number, etc.) created using an algorithm agreed upon by the network. Each block may include a header, a pointer or reference to a hash of a previous block's header in the chain, and a group of valid transactions. The reference to the previous block's hash is associated with the creation of the secure independent chain of blocks).
Therefore it would have been obvious to a person of ordinary skill in the art before the effective filing date of the application to Incorporate the teachings of Saleh into the system of Ventura to include An ordering-service-node or orderer is a node running the communication service for all nodes, and which implements a delivery guarantee, such as a broadcast to each of the peer nodes in the system when committing transactions and modifying a world state of the blockchain (see Saleh par. 0042).
Regarding claim 7, Ventura discloses a computer program product for resource transfer monitoring and authorization, the computer program product comprising at least one non-transitory computer-readable medium having computer-readable program code portions embodied therein (see Ventura par. 0007, the computer program product comprises at least one non-transitory computer-readable storage medium having computer-executable program code instructions stored therein), the computer-readable program code portions comprising:
“receiving an information entry from one or more domains, wherein the one or more domains comprise one or more nodes of a distributed network, and wherein the information entry is provided to an originating node” (see Ventura par. 0044, a user computing entity 30 may be a computing entity configured for user interaction (e.g., via a user interface thereof) for receiving, generating, and/or providing requests from a user to the distributed system. In various embodiments, a user may be a person interacting with a user computing entity 30 (e.g., via the user interface thereof) or a machine user (e.g., an application, service, and/or the like operating on the user computing entity 30). In various embodiments, the user computing entity may receive, generate, and/or provide requests to create or generate a TA-NET, add a node computing entity 200, 200′ to an existing TA-NET, update a trusted application (e.g., the TA-SEC and/or the supplemental domain of a trusted application (TA-SUP)), execute and/or provide a function of a trusted application of the TA-NET, and/or the like);
“storing the information entry on a distributed ledger of the distributed network” (see Ventura par. 0094, if the secure ledger is a distributed ledger, posting the new entry to the secure ledger 430 may comprise storing the new entry in the local ledger files 432 and distributing and/or disseminating the new entry via the distributed ledger in accordance with the validation and/or consensus process of the ledger);
“receiving a command to generate a distributed identifier for the information entry, wherein the distributed identifier is a generated number associated with the information entry based on information contained in the information entry” (see Ventura par. 0092, At 816, the first TA-SEC 428A may request (e.g., provide a get call/command) to the secure ledger 430 (or another secured shared resource) to access the information/data stored in the secure ledger 430 (or other secured shared resource) that is required for executing and/or performing the requested function. The requested data may be received from the secure ledger 430 (or other secured shared resource) at the first TA-SEC 428A. In an example embodiment, the secure ledger 430 is a distributed ledger and a copy of the distributed ledger is stored in local ledger files 432 in an appropriate location in memory 210, 215 (e.g., a location accessible via the trusted execution environment 420A). In such an embodiment, the requested data may be accessed from the local ledger files 432);
Ventura does not explicitly discloses broadcasting the distributed identifier generation to a plurality of nodes in the distributed network upon receiving the command.
However, in analogues art, Saleh discloses broadcasting the distributed identifier generation to a plurality of nodes in the distributed network upon receiving the command (see Saleh par. 0151, When the ordering service 710 initializes a new data block 730, the new data block 730 may be broadcast to committing peers (e.g., blockchain nodes 711, 712, and 713). In response, each committing peer validates the transaction within the new data block 730 by checking to make sure that the read set and the write set still match the current world state in the state database 724. Specifically, the committing peer can determine whether the read data that existed when the endorsers simulated the transaction is identical to the current world state in the state database 724. When the committing peer validates the transaction, the transaction is written to the blockchain 722 on the distributed ledger 720, and the state database 724 is updated with the write data from the read-write set).
Therefore it would have been obvious to a person of ordinary skill in the art before the effective filing date of the application to Incorporate the teachings of Saleh into the system of Ventura to include An ordering-service-node or orderer is a node running the communication service for all nodes, and which implements a delivery guarantee, such as a broadcast to each of the peer nodes in the system when committing transactions and modifying a world state of the blockchain (see Saleh par. 0042).
Ventura in view of Saleh does not explicitly discloses generating the distributed identifier, wherein the distributed identifier masks the information entry. However, in analogues art, generating the distributed identifier, wherein the distributed identifier masks the information entry (see Arya pars. 0019-0020, The encryption platform 110 may be further configured to utilize a masking engine 118 to generate mask sequence values 122 for the sensitive personal information 102 extracted from the stored data records 104. The mask sequence value 122 may be arbitrary identifiers unique to respective elements of sensitive personal information 102. Thus, the mask sequence values 122 may be used in database operations in place of the sensitive personal information 102 and without exposing the underlying sensitive personal information 102 values. In some cases, different sequences of mask sequence values 122 may be used for masking different types of sensitive personal information 102 (e.g., a first sequence for social security numbers, a second sequence for tax identifiers, etc.)).
Therefore it would have been obvious to a person of ordinary skill in the art before the effective filing date of the application to Incorporate the teachings of Arya into the system of Ventura and Saleh to include a system may be designed to safeguard sensitive personal information included in data records by replacing the sensitive personal information with generated mask identifiers that cannot be reversed by a receiving party (see Arya par. 0011).
Regarding claim 13, Ventura discloses a computer-implemented method for resource transfer monitoring and authorization, the method comprising:
“providing a computing system comprising a computer processing device and a non- transitory computer readable medium, where the non-transitory computer readable medium comprises configured computer program instruction code, such that when said computer program instruction code is operated by said computer processing device (see Ventura par. 0007, the computer program product comprises at least one non-transitory computer-readable storage medium having computer-executable program code instructions stored therein), said computer processing device performs the following operations:
“receiving an information entry from one or more domains, wherein the one or more domains comprise one or more nodes of a distributed network, and wherein the information entry is provided to an originating node” (see Ventura par. 0044, a user computing entity 30 may be a computing entity configured for user interaction (e.g., via a user interface thereof) for receiving, generating, and/or providing requests from a user to the distributed system. In various embodiments, a user may be a person interacting with a user computing entity 30 (e.g., via the user interface thereof) or a machine user (e.g., an application, service, and/or the like operating on the user computing entity 30). In various embodiments, the user computing entity may receive, generate, and/or provide requests to create or generate a TA-NET, add a node computing entity 200, 200′ to an existing TA-NET, update a trusted application (e.g., the TA-SEC and/or the supplemental domain of a trusted application (TA-SUP)), execute and/or provide a function of a trusted application of the TA-NET, and/or the like);
“storing the information entry on a distributed ledger of the distributed network” (see Ventura par. 0094, if the secure ledger is a distributed ledger, posting the new entry to the secure ledger 430 may comprise storing the new entry in the local ledger files 432 and distributing and/or disseminating the new entry via the distributed ledger in accordance with the validation and/or consensus process of the ledger);
“receiving a command to generate a distributed identifier for the information entry, wherein the distributed identifier is a generated number associated with the information entry based on information contained in the information entry” (see Ventura par. 0092, At 816, the first TA-SEC 428A may request (e.g., provide a get call/command) to the secure ledger 430 (or another secured shared resource) to access the information/data stored in the secure ledger 430 (or other secured shared resource) that is required for executing and/or performing the requested function. The requested data may be received from the secure ledger 430 (or other secured shared resource) at the first TA-SEC 428A. In an example embodiment, the secure ledger 430 is a distributed ledger and a copy of the distributed ledger is stored in local ledger files 432 in an appropriate location in memory 210, 215 (e.g., a location accessible via the trusted execution environment 420A). In such an embodiment, the requested data may be accessed from the local ledger files 432);
Ventura does not explicitly discloses broadcasting the distributed identifier generation to a plurality of nodes in the distributed network upon receiving the command.
However, in analogues art, Saleh discloses broadcasting the distributed identifier generation to a plurality of nodes in the distributed network upon receiving the command (see Saleh par. 0151, When the ordering service 710 initializes a new data block 730, the new data block 730 may be broadcast to committing peers (e.g., blockchain nodes 711, 712, and 713). In response, each committing peer validates the transaction within the new data block 730 by checking to make sure that the read set and the write set still match the current world state in the state database 724. Specifically, the committing peer can determine whether the read data that existed when the endorsers simulated the transaction is identical to the current world state in the state database 724. When the committing peer validates the transaction, the transaction is written to the blockchain 722 on the distributed ledger 720, and the state database 724 is updated with the write data from the read-write set).
Therefore it would have been obvious to a person of ordinary skill in the art before the effective filing date of the application to Incorporate the teachings of Saleh into the system of Ventura to include An ordering-service-node or orderer is a node running the communication service for all nodes, and which implements a delivery guarantee, such as a broadcast to each of the peer nodes in the system when committing transactions and modifying a world state of the blockchain (see Saleh par. 0042).
Ventura in view of Saleh does not explicitly discloses generating the distributed identifier, wherein the distributed identifier masks the information entry. However, in analogues art, generating the distributed identifier, wherein the distributed identifier masks the information entry (see Arya pars. 0019-0020, The encryption platform 110 may be further configured to utilize a masking engine 118 to generate mask sequence values 122 for the sensitive personal information 102 extracted from the stored data records 104. The mask sequence value 122 may be arbitrary identifiers unique to respective elements of sensitive personal information 102. Thus, the mask sequence values 122 may be used in database operations in place of the sensitive personal information 102 and without exposing the underlying sensitive personal information 102 values. In some cases, different sequences of mask sequence values 122 may be used for masking different types of sensitive personal information 102 (e.g., a first sequence for social security numbers, a second sequence for tax identifiers, etc.)).
Therefore it would have been obvious to a person of ordinary skill in the art before the effective filing date of the application to Incorporate the teachings of Arya into the system of Ventura and Saleh to include a system may be designed to safeguard sensitive personal information included in data records by replacing the sensitive personal information with generated mask identifiers that cannot be reversed by a receiving party (see Arya par. 0011).
Allowable Subject Matter 9. Claims 2-3, 8-9, and 14-15 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims.
Conclusion
10. Any inquiry concerning this communication or earlier communications from the examiner should be directed to SAMUEL AMBAYE whose telephone number is (571)270-7635. The examiner can normally be reached M-F 9:00 AM - 6:00 PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey Pwu can be reached on (571) 272-6798. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/SAMUEL AMBAYE/Examiner, Art Unit 2433
/JEFFREY C PWU/Supervisory Patent Examiner, Art Unit 2433