DETAILED ACTION
In response to communication filed on 24 June 2026, claims 1-22 are canceled. Claims 23-45 are newly added claims. Claims 23-45 are pending.
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
Applicant’s arguments, see “Remarks”, filed 24 June 2026, have been carefully considered but the arguments are not considered to be persuasive. The arguments are related to newly added limitations and are addressed in the rejection below.
Claim Interpretation
Claim 28 recites “a database-user account used to perform database operations”. The claims do not recite functionality, but instead recites what the database-user accounts are used for. Examiner suggests amending the claim to recite the functionality performed by the claimed method, instead of reciting what the claim elements are used for.
Claim 44 recites “a database-user account used for SQL requests”. The claims do not recite functionality, but instead recites what the database-user accounts are used for. Examiner suggests amending the claim to recite the functionality performed by the claimed method, instead of reciting what the claim elements are used for.
Claim Objections
Claims 23-27, 29, 31-34 and 37-45 are objected to because of the following informalities:
Claims 23-27, 29, 31-34 and 37-45 recite “SQL” that have been introduced in the abbreviated form without clarifying the unabbreviated form of this claim term.
Appropriate corrections are required.
Claim Rejections - 35 USC § 112
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112:
The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention.
Claim 41 is rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention.
Claim 41 recites “determining a count of SQL requests associated with the application-user information and obtained during a time interval; and determining that the count does not exceed a maximum count specified by the data-access policy”. Upon review of the specification, it does mention SQL requests but does not appear to mention a count of SQL requests associated with the application-user information and obtained during a time interval; and determining that the count does not exceed a maximum count specified by the data-access policy. As a result, there appears to be a lack of support for the newly added limitations.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 23-24, 28-29, 31, 33-35, 37-38 and 45 are rejected under 35 U.S.C. 103 as being unpatentable over Kaushik et al. (US 2018/0365290 A1, hereinafter “Kaushik”) in view of Ahmed et al. (US 2015/0379257 A1, hereinafter “Ahmed”).
Regarding claim 23, Kaushik teaches
A computer-implemented method comprising: (see Kaushik, [claim 1] “A method of executing instructions in a database statement”; [0026] “the computing system 100”).
obtaining, with a computer system, an SQL request to access a database, (see Kaushik, [0041] “In response to receiving the request from the untrusted machine 142 to process the database statement 120… In response to receiving the database statement 120 comprising the parameterized contents, the untrusted machine 142 can be configured to request that the trusted machine 152 to process the database statement 120”; [0026] “the computing system 100”) the SQL request comprising an SQL statement and an SQL comment; (see Kaushik, [0024] “"parsing" a database statement generally refers to examining characters in a database statement and recognizing commands, string literals, and comments by detecting keywords and identifiers and matching an overall structure of the database statement to a set of syntax rules applicable to the database”).
obtaining, with the computer system, based on content of the SQL comment, (see Kaushik, [0024] “"parsing" a database statement generally refers to examining characters in a database statement and recognizing commands, string literals, and comments by detecting keywords and identifiers and matching an overall structure of the database statement to a set of syntax rules applicable to the database”; [0026] “the computing system 100”) application-user information identifying an application user on whose behalf the SQL request was submitted; (see Kaushik, [0031]-[0032] “The application server 106 can be configured to execute one or more applications 112 configured to facilitate retrieving or otherwise interacting with records (e.g., patient records 132) in a database 109 provided by the database server 108… the application 112 can include components configured to create a database statement 120 for accessing data in the database 109 based on user input to, for example, locate a patient record 132 in the database 109… include a computing device that facilitates access to the application server 106 via the computer network 104 by users 101… identified as a user 101”; [0054] “upon actuation of the submit button 118 by the user 101, the application 112 can be configured to generate the database statement 120 based on the received user input… the database statement 120 can include instructions for the database server 108 to process for requesting certain patient records 132 associated with the received user input or performing other suitable actions”; [0026] “the computing system 100”).
… with the computer system, (see Kaushik, [0026] “the computing system 100”) based on the application-user information and (see Kaushik, [0031]-[0032] “The application server 106 can be configured to execute one or more applications 112 configured to facilitate retrieving or otherwise interacting with records (e.g., patient records 132) in a database 109 provided by the database server 108… the application 112 can include components configured to create a database statement 120 for accessing data in the database 109 based on user input to, for example, locate a patient record 132 in the database 109… include a computing device that facilitates access to the application server 106 via the computer network 104 by users 101… identified as a user 101”; [0054] “upon actuation of the submit button 118 by the user 101, the application 112 can be configured to generate the database statement 120 based on the received user input… the database statement 120 can include instructions for the database server 108 to process for requesting certain patient records 132 associated with the received user input or performing other suitable actions”) a resource of the database identified by the SQL statement,… (see Kaushik, [0022] “refers to an estimate representing predicted resource usage for executing instructions included in a database statement according to an execution plan”) a database operation specified by the SQL statement (see Kaushik, [0022] “an “execution plan” generally refers to ordered operations for performing instructions related to a database statement”) with respect to the resource; and (see Kaushik, [0022] “refers to an estimate representing predicted resource usage for executing instructions included in a database statement according to an execution plan”).
… with the computer system, (see Kaushik, [0026] “the computing system 100”) causing the database to perform the database operation (see Kaushik, [0019] “a “database statement” generally refers to a structured statement executable in a database for performing certain requested action(s)… a database statement can request retrieval of certain records in a database based on one or more queries… the database statement can comprise a query and a predicate may limit the rows of a column that are returned when the query is executed”).
Kaushik does not explicitly teach determining, that a data-access policy permits a database operation; in response to the determining, causing the database to perform the database operation.
However, Ahmed discloses data access control policy and teaches
determining,… that a data-access policy permits access (see Ahmed, [0059] “implements a data access control policy that provides row-level and/or column-level access control to data stored in database system 120. The data access control policy may be specified using one or more access control lists. Each access control list specifies what privileges (e.g., read or write) can be performed by which principals, where each principal is a user or role in the database system”; [0071] “data access control policies may only allow access to users that are associated with the value of “West” as the “Organization” attribute”) (see Ahmed, [0059] “implements a data access control policy that provides row-level and/or column-level access control to data stored in database system 120. The data access control policy may be specified using one or more access control lists. Each access control list specifies what privileges (e.g., read or write) can be performed by which principals, where each principal is a user or role in the database system”; [0071] “data access control policies may only allow access to users that are associated with the value of “West” as the “Organization” attribute”).
in response to the determining, perform read or write operations (see Ahmed, [0059] “implements a data access control policy that provides row-level and/or column-level access control to data stored in database system 120. The data access control policy may be specified using one or more access control lists. Each access control list specifies what privileges (e.g., read or write) can be performed by which principals, where each principal is a user or role in the database system”; [0071] “data access control policies may only allow access to users that are associated with the value of “West” as the “Organization” attribute”).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to include the functionality of data access policy related permissions/prohibitions, application user identification, rejecting operations, database-user account, database operations, group identification, session identifier, before executing operations, SQL request routed to the database, transmitting, user access designation, resource access designation, named field, SQL comment not being used, relational database and transmitting information to a server as being disclosed and taught by Ahmed, in the system taught by Kaushik to yield the predictable results of effectively allowing a database system to enforce security (see Ahmed, [0042] “Techniques are provided for allowing a database system to enforce application data security policies based on the identity of an application user. The database system natively enforces application-defined policies within the database system based on the application user's identity. A user's security context is securely and transparent propagated from the middle tier (in which the application executes) to the database system”).
Claim 45 incorporates substantively all the limitations of claim 23 in a computer-readable medium form (see Kaushik, [0087]-[0090] “memory controller 318 can also be used with processor 304, or in some implementations memory controller 318 can be an internal part of processor 304… such as computer readable instructions, data structures, program modules, or other data. The term "computer readable storage media" or "computer readable storage device" excludes propagated signals and communication media… The system memory 306, removable storage devices 336, and non-removable storage devices 338 are examples of computer readable storage media”) and is rejected under the same rationale.
Regarding claim 24, the proposed combination of Kaushik and Ahmed teaches
wherein causing the database to perform the database operation comprises providing the SQL request to the database, and wherein the database executes the SQL statement without using the application-user information (see Kaushik, [0019] “a “database statement” generally refers to a structured statement executable in a database for performing certain requested action(s)… a database statement can request retrieval of certain records in a database based on one or more queries… the database statement can comprise a query and a predicate may limit the rows of a column that are returned when the query is executed” – the SQL statement is not using the application-user information).
Regarding claim 28, the proposed combination of Kaushik and Ahmed teaches
wherein the database operation is performed (see Kaushik, [0019] “a “database statement” generally refers to a structured statement executable in a database for performing certain requested action(s)… a database statement can request retrieval of certain records in a database based on one or more queries… the database statement can comprise a query and a predicate may limit the rows of a column that are returned when the query is executed”) under a database-user account used to perform database operations on behalf of the application user and at least one other application user (see Ahmed, [0102] “a single user may be shared by multiple database sessions. A single end-user request (e.g., from client 102) may result in multiple connections between an application in middle tier 110 and database system 120”; [0121] “One or more specific users in database system 120 are granted these privileges”; [0123] “can authenticate session manager 118 to database system 120, then session manager 118 can perform the corresponding task of initiating the creation and management of authenticated sessions for application users in database system 120”; [0117] “application end-users are introduced in the database. Correspondingly, there are users' application sessions (or LWSs) in the database. These application users can be provisioned in the database or in an identity store”). The motivation for the proposed combination is maintained.
Regarding claim 29, the proposed combination of Kaushik and Ahmed teaches
wherein the content of the SQL comment comprises (see Kaushik, [0024] “"parsing" a database statement generally refers to examining characters in a database statement and recognizing commands, string literals, and comments by detecting keywords and identifiers and matching an overall structure of the database statement to a set of syntax rules applicable to the database”) a user identifier identifying the application user and a group identifier identifying a user group that includes the application user (see Ahmed, [0050] “may then determine, based on the user/group identifier, one or more application roles that have been assigned to the end-user. An application role is a logical grouping of application privileges that are required to accomplish a task. An application role may be granted to one or more other application roles. Application roles are used to associate application users with privileges”). The motivation for the proposed combination is maintained.
Regarding claim 31, the proposed combination of Kaushik and Ahmed teaches
wherein the application-user information comprises (see Kaushik, [0031]-[0032] “The application server 106 can be configured to execute one or more applications 112 configured to facilitate retrieving or otherwise interacting with records (e.g., patient records 132) in a database 109 provided by the database server 108… the application 112 can include components configured to create a database statement 120 for accessing data in the database 109 based on user input to, for example, locate a patient record 132 in the database 109… include a computing device that facilitates access to the application server 106 via the computer network 104 by users 101… identified as a user 101”; [0054] “upon actuation of the submit button 118 by the user 101, the application 112 can be configured to generate the database statement 120 based on the received user input… the database statement 120 can include instructions for the database server 108 to process for requesting certain patient records 132 associated with the received user input or performing other suitable actions”) a session identifier associated with an application session through which the application user submitted the SQL request (see Ahmed, [0113] “the application data request is analyzed to identify the LWS identifier within the application data request”; Fig – 3 – 350 – Identify the session identifier within the data request; [0092] “The data request may include a SQL query for database system 120 to process”). The motivation for the proposed combination is maintained.
Regarding claim 33, the proposed combination of Kaushik and Ahmed teaches
wherein obtaining the SQL request, (see Kaushik, [0041] “In response to receiving the request from the untrusted machine 142 to process the database statement 120… In response to receiving the database statement 120 comprising the parameterized contents, the untrusted machine 142 can be configured to request that the trusted machine 152 to process the database statement 120”; [0026] “the computing system 100”) obtaining the application-user information, (see Kaushik, [0031]-[0032] “The application server 106 can be configured to execute one or more applications 112 configured to facilitate retrieving or otherwise interacting with records (e.g., patient records 132) in a database 109 provided by the database server 108… the application 112 can include components configured to create a database statement 120 for accessing data in the database 109 based on user input to, for example, locate a patient record 132 in the database 109… include a computing device that facilitates access to the application server 106 via the computer network 104 by users 101… identified as a user 101”; [0054] “upon actuation of the submit button 118 by the user 101, the application 112 can be configured to generate the database statement 120 based on the received user input… the database statement 120 can include instructions for the database server 108 to process for requesting certain patient records 132 associated with the received user input or performing other suitable actions”; [0026] “the computing system 100”) determining that the data-access policy permits access (see Ahmed, [0059] “implements a data access control policy that provides row-level and/or column-level access control to data stored in database system 120. The data access control policy may be specified using one or more access control lists. Each access control list specifies what privileges (e.g., read or write) can be performed by which principals, where each principal is a user or role in the database system”; [0071] “data access control policies may only allow access to users that are associated with the value of “West” as the “Organization” attribute”) the database operation, (see Kaushik, [0022] “an “execution plan” generally refers to ordered operations for performing instructions related to a database statement”) and causing the database to perform the database operation (see Kaushik, [0019] “a “database statement” generally refers to a structured statement executable in a database for performing certain requested action(s)… a database statement can request retrieval of certain records in a database based on one or more queries… the database statement can comprise a query and a predicate may limit the rows of a column that are returned when the query is executed”) are performed by a proxy computing system (see Kaushik, [0030] “some or all of the techniques disclosed herein may be implemented on a proxy server (not shown) interconnected between the application server 106 and the database server 108 via the computer network 104”) through which the SQL request is routed to the database (see Ahmed, [0046] “receiving a client request, applications 112 and 114 send requests to database system 120 through database connections”). The motivation for the proposed combination is maintained.
Regarding claim 34, the proposed combination of Kaushik and Ahmed teaches
wherein causing the database to perform the database operation comprises (see Kaushik, [0019] “a “database statement” generally refers to a structured statement executable in a database for performing certain requested action(s)… a database statement can request retrieval of certain records in a database based on one or more queries… the database statement can comprise a query and a predicate may limit the rows of a column that are returned when the query is executed”) transmitting the SQL statement from the proxy computing system to the database (see Kaushik, [0041] “to transmit a database statement 120”; [0030] “may be implemented on a proxy server (not shown) interconnected between the application server 106 and the database server 108 via the computer network 104”) according to a database communication protocol, (see Ahmed, [0139] “this protocol, database system 120”) the method further comprising: (see Kaushik, [claim 1] “A method of executing instructions in a database statement”; [0026] “the computing system 100”).
obtaining, by the proxy computing system, a database response generated by the database; and (see Kaushik, [0019] “a “database statement” generally refers to a structured statement executable in a database for performing certain requested action(s)… a database statement can request retrieval of certain records in a database based on one or more queries… the database statement can comprise a query and a predicate may limit the rows of a column that are returned when the query is executed”; [0034] “The statement results 129 are generated based on the patient records 132 in the database 109 in response to the database statement 120”; [0055] “the example SQL statement comprises a database command (i.e., select)”; [0030] “may be implemented on a proxy server… interconnected between the application server 106 and the database server 108 via the computer network 104”).
providing, through the proxy computing system, the database response in response to the SQL request (see Kaushik, [0078] “In response to receiving the statement results 129, the application 112, can display patient information 119 from the patient records 132 to the user 101”; [0030] “may be implemented on a proxy server… interconnected between the application server 106 and the database server 108 via the computer network 104”).
Regarding claim 35, the proposed combination of Kaushik and Ahmed teaches
wherein determining that the data-access policy permits access (see Ahmed, [0059] “implements a data access control policy that provides row-level and/or column-level access control to data stored in database system 120. The data access control policy may be specified using one or more access control lists. Each access control list specifies what privileges (e.g., read or write) can be performed by which principals, where each principal is a user or role in the database system”; [0071] “data access control policies may only allow access to users that are associated with the value of “West” as the “Organization” attribute”) the database operation comprises: (see Kaushik, [0022] “an “execution plan” generally refers to ordered operations for performing instructions related to a database statement”).
transmitting, to (see Ahmed, [0124] “transmits the credential data to database system 120”) a policy server, (see Ahmed, [0063] “a database server, a database server enforcing a data access control policy”) the application-user information and (see Kaushik, [0031]-[0032] “The application server 106 can be configured to execute one or more applications 112 configured to facilitate retrieving or otherwise interacting with records (e.g., patient records 132) in a database 109 provided by the database server 108… the application 112 can include components configured to create a database statement 120 for accessing data in the database 109 based on user input to, for example, locate a patient record 132 in the database 109… include a computing device that facilitates access to the application server 106 via the computer network 104 by users 101… identified as a user 101”; [0054] “upon actuation of the submit button 118 by the user 101, the application 112 can be configured to generate the database statement 120 based on the received user input… the database statement 120 can include instructions for the database server 108 to process for requesting certain patient records 132 associated with the received user input or performing other suitable actions”) information (see Kaushik, [0061] “transmitting the database statement 120 to the database server 108”) identifying the resource and (see Kaushik, [0022] “refers to an estimate representing predicted resource usage for executing instructions included in a database statement according to an execution plan”) the database operation; and (see Kaushik, [0022] “an “execution plan” generally refers to ordered operations for performing instructions related to a database statement”).
obtaining, from (see Kaushik, [0054] “the received user input… the database statement 120 can include instructions for the database server 108”) the policy server, (see Ahmed, [0063] “a database server, a database server enforcing a data access control policy”) an instruction (see Kaushik, [0054] “the received user input… the database statement 120 can include instructions for the database server 108”) permitting the database operation with respect to the resource (see Ahmed, [0057] “A server, such as a database server, is a combination of integrated software components and an allocation of computational resources, such as memory, a node, and processes on the node for executing the integrated software components on a processor”). The motivation for the proposed combination is maintained.
Regarding claim 37, the proposed combination of Kaushik and Ahmed teaches
wherein the resource is a column of a table identified by the SQL statement (see Kaushik, [0059] “the example SQL statement comprises a database command (i.e., select), identification of a table (i.e., patients), table columns (i.e., sate, illness, and sex)”).
Regarding claim 38, the proposed combination of Kaushik and Ahmed teaches
wherein the resource is a row of a table satisfying a condition specified by a WHERE clause of the SQL statement (see Kaushik, [0056]-[0059] “SELECT * FROM patients WHERE state LIKE 'Washington' AND illness LIKE @x AND sex LIKE 'male”; @x =diabetes…the example SQL statement comprises a database command (i.e., select), identification of a table (i.e., patients), table columns (i.e., sate, illness, and sex), and content "Washington," "male," and "@x", where @x is a parameterized value corresponding to "diabetes.").
Claims 25 and 26 are rejected under 35 U.S.C. 103 as being unpatentable over Kaushik in view of Ahmed further in view of Shulman et al. (US 2007/0136312 A1, hereinafter “Shulman”).
Regarding claim 25, the proposed combination of Kaushik and Ahmed teaches
wherein causing the database to perform the database operation comprises… (see Kaushik, [0019] “a “database statement” generally refers to a structured statement executable in a database for performing certain requested action(s)… a database statement can request retrieval of certain records in a database based on one or more queries… the database statement can comprise a query and a predicate may limit the rows of a column that are returned when the query is executed”) and providing the SQL statement, without the SQL comment, to the database (see Kaushik, [0019] “a “database statement” generally refers to a structured statement executable in a database for performing certain requested action(s)… a database statement can request retrieval of certain records in a database based on one or more queries… the database statement can comprise a query and a predicate may limit the rows of a column that are returned when the query is executed” – the SQL statement is not using the SQL comment).
The proposed combination of Kaushik and Ahmed does not explicitly teach removing the SQL comment from the SQL request.
However, Shulman discloses application level security system and teaches
removing the SQL comment from the SQL request (see Shulman, [0024] “each literal in the SQL query statement is replaced with a place holder (e.g., a question mark) and comments and white-space characters are removed”; [claim 8] “removing comments in the SQL query”).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to include the functionality of removing SQL comment and locating SQL comment as being disclosed and taught by Shulman, in the system taught by the proposed combination of Kaushik and Ahmed to yield the predictable results of effectively analyzing SQL query statements (see Shulman, [0024] “a SQL query statement is captured by the SQL sensor and, at S360, the statement is converted to a SQL template. Namely, each literal in the SQL query statement is replaced with a place holder (e.g., a question mark) and comments and white-space characters are removed. At S370, the SQL template is inserted to the URL-Template matrix to an entry in the first available column and the first row”).
Regarding claim 26, the proposed combination of Kaushik and Ahmed teaches
wherein obtaining the application-user information comprises… (see Kaushik, [0031]-[0032] “The application server 106 can be configured to execute one or more applications 112 configured to facilitate retrieving or otherwise interacting with records (e.g., patient records 132) in a database 109 provided by the database server 108… the application 112 can include components configured to create a database statement 120 for accessing data in the database 109 based on user input to, for example, locate a patient record 132 in the database 109… include a computing device that facilitates access to the application server 106 via the computer network 104 by users 101… identified as a user 101”; [0054] “upon actuation of the submit button 118 by the user 101, the application 112 can be configured to generate the database statement 120 based on the received user input… the database statement 120 can include instructions for the database server 108 to process for requesting certain patient records 132 associated with the received user input or performing other suitable actions”) and obtaining a value associated with a predefined field identifier… (see Kaushik, [0031] “The input fields 116 can be configured to receive a user input containing a numerical, string, or other suitable types of value”) the application-user information (see Kaushik, [0031]-[0032] “The application server 106 can be configured to execute one or more applications 112 configured to facilitate retrieving or otherwise interacting with records (e.g., patient records 132) in a database 109 provided by the database server 108… the application 112 can include components configured to create a database statement 120 for accessing data in the database 109 based on user input to, for example, locate a patient record 132 in the database 109… include a computing device that facilitates access to the application server 106 via the computer network 104 by users 101… identified as a user 101”; [0054] “upon actuation of the submit button 118 by the user 101, the application 112 can be configured to generate the database statement 120 based on the received user input… the database statement 120 can include instructions for the database server 108 to process for requesting certain patient records 132 associated with the received user input or performing other suitable actions”) comprising the value (see Kaushik, [0031] “The input fields 116 can be configured to receive a user input containing a numerical, string, or other suitable types of value”).
The proposed combination of Kaushik and Ahmed does not explicitly teach locating the SQL comment at a predefined position within the SQL request; in the SQL comment.
However, Shulman discloses application level security system and teaches
locating the SQL comment at a predefined position within the SQL request… (see Shulman, [0018] “for the SQL query statement: "select a/* just a comment */ from table_1 where a>6” – the comment is located on a SQL statement at a predefined position) information in the SQL comment, (see Shulman, [0018] “a SQL template is a SQL query statement where at least literals are replaced with, for example, question marks '?' and comments and white-space characters are replaced”).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to include the functionality of removing SQL comment and locating SQL comment as being disclosed and taught by Shulman, in the system taught by the proposed combination of Kaushik and Ahmed to yield the predictable results of effectively analyzing SQL query statements (see Shulman, [0024] “a SQL query statement is captured by the SQL sensor and, at S360, the statement is converted to a SQL template. Namely, each literal in the SQL query statement is replaced with a place holder (e.g., a question mark) and comments and white-space characters are removed. At S370, the SQL template is inserted to the URL-Template matrix to an entry in the first available column and the first row”).
Claims 27 and 32 are rejected under 35 U.S.C. 103 as being unpatentable over Kaushik in view of Ahmed further in view of Lin (US 2015/0317567 A1, hereinafter “Lin”).
Regarding claim 27, the proposed combination of Kaushik and Ahmed teaches
further comprising: obtaining an additional SQL request comprising an additional SQL statement and… (see Kaushik, [0034] “The interface component 144 can be configured to receive database statements 120 from the application 112 at the application server 106” – there are plurality of SQL statements) SQL comment (see Kaushik, [0024] “"parsing" a database statement generally refers to examining characters in a database statement and recognizing commands, string literals, and comments by detecting keywords and identifiers and matching an overall structure of the database statement to a set of syntax rules applicable to the database”) containing information identifying an application user; and (see Ahmed, [0050] “may then determine, based on the user/group identifier, one or more application roles that have been assigned to the end-user. An application role is a logical grouping of application privileges that are required to accomplish a task. An application role may be granted to one or more other application roles. Application roles are used to associate application users with privileges”).
rejecting specific operations (see Ahmed, [0132] “does not explicitly call any session management operations (e.g., create session, attach session, etc.)”) the additional SQL request (see Kaushik, [0034] “The interface component 144 can be configured to receive database statements 120 from the application 112 at the application server 106” – there are plurality of SQL statements) without causing the database to execute specific operations (see Ahmed, [0132] “does not explicitly call any session management operations (e.g., create session, attach session, etc.)”) the additional SQL statement (see Kaushik, [0034] “The interface component 144 can be configured to receive database statements 120 from the application 112 at the application server 106” – there are plurality of SQL statements).
The proposed combination of Kaushik and Ahmed does not explicitly teach lacking an SQL comment.
However, Lin discloses database commands and teaches
lacking an SQL comment (see Lin, [0031] “the identification number "1234" is added to the SQL command, usually as part of a comment, and now the request and the SQL command can be associated to each other”- the comment SQL is not included in the beginning and hence is lacking that information).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to include the functionality of lacking an SQL comment and adding SQL comment as being disclosed and taught by Lin, in the system taught by the proposed combination of Kaushik and Ahmed to yield the predictable results of effectively processing change requests (see Lin, [0020] “a process 200 for auditing changes requests performed by the business change management system of the present invention. Generally, the change requests are implemented and recorded on one or more business databases stored on a server 202. Through an auditing process 204, events 206 that happened during implementation of the change requests are retrieved, filtered and grouped as instances 210”).
Regarding claim 32, the proposed combination of Kaushik and Ahmed teaches
further comprising, before (see Ahmed, [0143] “When an attach session operation is invoked before executing the data request”) obtaining the SQL request: (see Kaushik, [0041] “In response to receiving the request from the untrusted machine 142 to process the database statement 120… In response to receiving the database statement 120 comprising the parameterized contents, the untrusted machine 142 can be configured to request that the trusted machine 152 to process the database statement 120”; [0026] “the computing system 100”).
obtaining, from an application session, user-identifying information identifying the application user; and (see Kaushik, [0031]-[0032] “The application server 106 can be configured to execute one or more applications 112 configured to facilitate retrieving or otherwise interacting with records (e.g., patient records 132) in a database 109 provided by the database server 108… the application 112 can include components configured to create a database statement 120 for accessing data in the database 109 based on user input to, for example, locate a patient record 132 in the database 109… include a computing device that facilitates access to the application server 106 via the computer network 104 by users 101… identified as a user 101”; [0054] “upon actuation of the submit button 118 by the user 101, the application 112 can be configured to generate the database statement 120 based on the received user input… the database statement 120 can include instructions for the database server 108 to process for requesting certain patient records 132 associated with the received user input or performing other suitable actions”; [0026] “the computing system 100”).
… containing the user-identifying information… (see Kaushik, [0031]-[0032] “The application server 106 can be configured to execute one or more applications 112 configured to facilitate retrieving or otherwise interacting with records (e.g., patient records 132) in a database 109 provided by the database server 108… the application 112 can include components configured to create a database statement 120 for accessing data in the database 109 based on user input to, for example, locate a patient record 132 in the database 109… include a computing device that facilitates access to the application server 106 via the computer network 104 by users 101… identified as a user 101”; [0054] “upon actuation of the submit button 118 by the user 101, the application 112 can be configured to generate the database statement 120 based on the received user input… the database statement 120 can include instructions for the database server 108 to process for requesting certain patient records 132 associated with the received user input or performing other suitable actions”; [0026] “the computing system 100”).
The proposed combination of Kaushik and Ahmed does not explicitly teach adding the SQL comment containing the user-identifying information to the SQL statement to form the SQL request.
However, Lin discloses database commands and teaches
adding the SQL comment with identification number to the SQL statement to form the SQL request (see Lin, [0031] “the identification number "1234" is added to the SQL command, usually as part of a comment, and now the request and the SQL command can be associated to each other”).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to include the functionality of lacking an SQL comment and adding SQL comment as being disclosed and taught by Lin, in the system taught by the proposed combination of Kaushik and Ahmed to yield the predictable results of effectively processing change requests (see Lin, [0020] “a process 200 for auditing changes requests performed by the business change management system of the present invention. Generally, the change requests are implemented and recorded on one or more business databases stored on a server 202. Through an auditing process 204, events 206 that happened during implementation of the change requests are retrieved, filtered and grouped as instances 210”).
Claims 30, 36, 39 and 42-44 are rejected under 35 U.S.C. 103 as being unpatentable over Kaushik in view of Ahmed further in view of Khanduja et al. (US 2021/0097194 A1, hereinafter “Khanduja”).
Regarding claim 44, Kaushik teaches
A computer-implemented method performed by a proxy computing system in a communication path between an application and a… database, the method comprising: (see Kaushik, [0030] “may be implemented on a proxy server… interconnected between the application server 106 and the database server 108 via the computer network 104”).
obtaining, by the proxy computing system, an SQL request submitted… (see Kaushik, [0041] “In response to receiving the request from the untrusted machine 142 to process the database statement 120… In response to receiving the database statement 120 comprising the parameterized contents, the untrusted machine 142 can be configured to request that the trusted machine 152 to process the database statement 120”; [0030] “may be implemented on a proxy server… interconnected between the application server 106 and the database server 108 via the computer network 104” [0026] “the computing system 100”) a plurality of application users of the application, (see Kaushik, [0032] “The client devices 102 can individually include a computing device that facilitates access to the application server 106 via the computer network 104 by users 101” – there are plurality of users) the SQL request comprising a SELECT statement and (see Kaushik, [0055] “the example SQL statement comprises a database command (i.e., select)”) an SQL comment having a predefined format (see Kaushik, [0024] “"parsing" a database statement generally refers to examining characters in a database statement and recognizing commands, string literals, and comments by detecting keywords and identifiers and matching an overall structure of the database statement to a set of syntax rules applicable to the database”) that includes a user identifier identifying an application user among the plurality of application users… (see Kaushik, [0031]-[0032] “The application server 106 can be configured to execute one or more applications 112 configured to facilitate retrieving or otherwise interacting with records (e.g., patient records 132) in a database 109 provided by the database server 108… the application 112 can include components configured to create a database statement 120 for accessing data in the database 109 based on user input to, for example, locate a patient record 132 in the database 109… include a computing device that facilitates access to the application server 106 via the computer network 104 by users 101… identified as a user 101”; [0054] “upon actuation of the submit button 118 by the user 101, the application 112 can be configured to generate the database statement 120 based on the received user input… the database statement 120 can include instructions for the database server 108 to process for requesting certain patient records 132 associated with the received user input or performing other suitable actions”; [0026] “the computing system 100”).
parsing, by the proxy computing system, the SQL comment according to the predefined format (see Kaushik, [0024] “"parsing" a database statement generally refers to examining characters in a database statement and recognizing commands, string literals, and comments by detecting keywords and identifiers and matching an overall structure of the database statement to a set of syntax rules applicable to the database”; [0030] “may be implemented on a proxy server… interconnected between the application server 106 and the database server 108 via the computer network 104”) to obtain the user identifier… (see Kaushik, [0031]-[0032] “The application server 106 can be configured to execute one or more applications 112 configured to facilitate retrieving or otherwise interacting with records (e.g., patient records 132) in a database 109 provided by the database server 108… the application 112 can include components configured to create a database statement 120 for accessing data in the database 109 based on user input to, for example, locate a patient record 132 in the database 109… include a computing device that facilitates access to the application server 106 via the computer network 104 by users 101… identified as a user 101”; [0054] “upon actuation of the submit button 118 by the user 101, the application 112 can be configured to generate the database statement 120 based on the received user input… the database statement 120 can include instructions for the database server 108 to process for requesting certain patient records 132 associated with the received user input or performing other suitable actions”; [0026] “the computing system 100”).
identifying, by the proxy computing system from the SELECT statement, a resource of the… database accessed by the SELECT statement; (see Kaushik, [0022] “refers to an estimate representing predicted resource usage for executing instructions included in a database statement according to an execution plan”; [0055] “the example SQL statement comprises a database command (i.e., select)”; [0030] “may be implemented on a proxy server… interconnected between the application server 106 and the database server 108 via the computer network 104”).
by the proxy computing system… (see Kaushik, [0030] “may be implemented on a proxy server… interconnected between the application server 106 and the database server 108 via the computer network 104”) a database operation specified by the SELECT statement (see Kaushik, [0022] “an “execution plan” generally refers to ordered operations for performing instructions related to a database statement”; [0055] “the example SQL statement comprises a database command (i.e., select)”) with respect to the resource; (see Kaushik, [0022] “refers to an estimate representing predicted resource usage for executing instructions included in a database statement according to an execution plan”).
transmitting, by the proxy computing system, the SELECT statement to the… database for execution… to execute the SELECT statement; (see Kaushik, [0019] “a “database statement” generally refers to a structured statement executable in a database for performing certain requested action(s)… a database statement can request retrieval of certain records in a database based on one or more queries… the database statement can comprise a query and a predicate may limit the rows of a column that are returned when the query is executed”; [0055] “the example SQL statement comprises a database command (i.e., select)”; [0030] “may be implemented on a proxy server… interconnected between the application server 106 and the database server 108 via the computer network 104” – the SQL statement is not using the application-user information).
obtaining, by the proxy computing system, a database response generated by execution of the SELECT statement; (see Kaushik, [0019] “a “database statement” generally refers to a structured statement executable in a database for performing certain requested action(s)… a database statement can request retrieval of certain records in a database based on one or more queries… the database statement can comprise a query and a predicate may limit the rows of a column that are returned when the query is executed”; [0034] “The statement results 129 are generated based on the patient records 132 in the database 109 in response to the database statement 120”; [0055] “the example SQL statement comprises a database command (i.e., select)”; [0030] “may be implemented on a proxy server… interconnected between the application server 106 and the database server 108 via the computer network 104”).
providing, by the proxy computing system, the database response to the application; (see Kaushik, [0078] “In response to receiving the statement results 129, the application 112, can display patient information 119 from the patient records 132 to the user 101”; [0030] “may be implemented on a proxy server… interconnected between the application server 106 and the database server 108 via the computer network 104”).
… by the proxy computing system,… (see Kaushik, [0030] “may be implemented on a proxy server… interconnected between the application server 106 and the database server 108 via the computer network 104”) the SELECT statement,… (see Kaushik, [0055] “the example SQL statement comprises a database command (i.e., select)”) a computing device from which the SQL request was obtained; and (see Kaushik, [0041] “In response to receiving the request from the untrusted machine 142 to process the database statement 120… In response to receiving the database statement 120 comprising the parameterized contents, the untrusted machine 142 can be configured to request that the trusted machine 152 to process the database statement 120”; [0026] “the computing system 100”).
… by the proxy computing system, (see Kaushik, [0030] “may be implemented on a proxy server… interconnected between the application server 106 and the database server 108 via the computer network 104”).
Kaushik does not explicitly teach a relational database; under a database-user account used for SQL requests; associated with a plurality of application users of the application and a group identifier identifying a user group that includes the application user; and the group identifier; relational database; determining applying a policy rule associated with the group identifier to the resource, that a data-access policy permits a database; relational database under the database-user account, without the relational database using the SQL comment; storing a log record associating the user identifier, the group identifier, an identifier of the database-user account, a timestamp, and an Internet Protocol address of a computing device; transmitting, the log record to a monitoring server.
However, Ahmed discloses data access control policy and teaches
relational database (see Ahmed, [0054] “Database data may be stored in one or more data containers. Each container contains records. The data within each record is organized into one or more fields… relational database management systems”).
under a database-user account used for SQL requests; associated with application (see Ahmed, [0102] “a single user may be shared by multiple database sessions. A single end-user request (e.g., from client 102) may result in multiple connections between an application in middle tier 110 and database system 120”; [0121] “One or more specific users in database system 120 are granted these privileges”; [0123] “can authenticate session manager 118 to database system 120, then session manager 118 can perform the corresponding task of initiating the creation and management of authenticated sessions for application users in database system 120”) and a group identifier identifying a user group that includes the application user; (see Ahmed, [0050] “based on the user/group identifier, one or more application roles that have been assigned to the end-user. An application role is a logical grouping of application privileges that are required to accomplish a task. An application role may be granted to one or more other application roles. Application roles are used to associate application users with privileges”).
and the group identifier; (see Ahmed, [0050] “based on the user/group identifier, one or more application roles that have been assigned to the end-user. An application role is a logical grouping of application privileges that are required to accomplish a task. An application role may be granted to one or more other application roles. Application roles are used to associate application users with privileges”).
relational database (see Ahmed, [0054] “Database data may be stored in one or more data containers. Each container contains records. The data within each record is organized into one or more fields… relational database management systems”).
determining,… applying a policy rule associated with the group identifier to the resource, that a data-access policy permits access (see Ahmed, [0066] “The database system 120 may use the user/group identifier for auditing purposes and/or for security purposes to enforce security policies in light of the specific user. For example, a security policy on a table may include a user-specific or group-specific policy”).
relational database (see Ahmed, [0054] “Database data may be stored in one or more data containers. Each container contains records. The data within each record is organized into one or more fields… relational database management systems”) under the database-user account, (see Ahmed, [0102] “a single user may be shared by multiple database sessions. A single end-user request (e.g., from client 102) may result in multiple connections between an application in middle tier 110 and database system 120”; [0121] “One or more specific users in database system 120 are granted these privileges”; [0123] “can authenticate session manager 118 to database system 120, then session manager 118 can perform the corresponding task of initiating the creation and management of authenticated sessions for application users in database system 120”) without the relational database using the SQL comment (see Ahmed, [0054] “Database data may be stored in one or more data containers. Each container contains records. The data within each record is organized into one or more fields… relational database management systems”; [0143] “When an application data request (e.g., a SQL query) is executed on a connection”– SQL comment is not being used).
… the user identifier, (see Ahmed, [0049] “The authentication data may include a user identifier”) the group identifier, (see Ahmed, [0049] “The authentication data may include… a group identifier”) an identifier of the database-user account, (see Ahmed, [0066] “The database system 120 may use the user/group identifier for auditing purposes and/or for security purposes to enforce security policies in light of the specific user”) and an Internet Protocol address of a device (see Ahmed, [0071] “example attribute is IP address, where only a specific set of one or more IP addresses is used as a data access control policy”).
transmitting, information to the server to a monitoring server (see Ahmed, [0049] “send the user credentials to an external authentication server”).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to include the functionality of data access policy related permissions/prohibitions, application user identification, rejecting operations, database-user account, database operations, group identification, session identifier, before executing operations, SQL request routed to the database, transmitting, user access designation, resource access designation, named field, SQL comment not being used, relational database and transmitting information to a server as being disclosed and taught by Ahmed, in the system taught by Kaushik to yield the predictable results of effectively allowing a database system to enforce security (see Ahmed, [0042] “Techniques are provided for allowing a database system to enforce application data security policies based on the identity of an application user. The database system natively enforces application-defined policies within the database system based on the application user's identity. A user's security context is securely and transparent propagated from the middle tier (in which the application executes) to the database system”).
The proposed combination of Kaushik and Ahmed does not explicitly teach storing, a log record associating a timestamp, transmitting, the log record to a monitoring server.
However, Khanduja discloses restricted portion of data element based on access control policy and teaches
storing, a log record associating… a timestamp, (See Khanduja, [0046] “a history of accessed data elements based on PL/SQL code blocks (e.g., a reconstructed procedure) and/or stored procedures previously defined may be stored in a log by data access system 114a. The log may identify, for instance, the identity of the user accessing the data elements, identity of the data elements that a user accessed and/or was permitted to access, the time of access”)
monitor the log record (see Khanduja, [0046] “The log of historical accesses may be available… to identify any vulnerabilities and/or access control issues that may exist, enabling the generation or modification of the access control policies in the policy engine 116 and/or the access patterns 230”).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to include the functionality of log records and timestamps, as being disclosed and taught by Khanduja, in the system taught by the proposed combination of Kaushik and Ahmed to yield the predictable results of improving data security (see Khanduja, [0009] “The example data access system improves data security by ensuring fine-grained security rules and policies when provisioning data through PL/SQL procedures. The benefits of using stored procedures rather than application code stored locally on client computers include allowing for modular programming, faster execution, reduce network traffic, and can be used as a security mechanism”).
Regarding claim 30, the proposed combination of Kaushik and Ahmed teaches
wherein determining that the data-access policy permits access (see Ahmed, [0059] “implements a data access control policy that provides row-level and/or column-level access control to data stored in database system 120. The data access control policy may be specified using one or more access control lists. Each access control list specifies what privileges (e.g., read or write) can be performed by which principals, where each principal is a user or role in the database system”; [0071] “data access control policies may only allow access to users that are associated with the value of “West” as the “Organization” attribute”) the database operation comprises… (see Kaushik, [0022] “an “execution plan” generally refers to ordered operations for performing instructions related to a database statement”) the data-access policy based on the group identifier and… (see Ahmed, [0066] “The database system 120 may use the user/group identifier for auditing purposes and/or for security purposes to enforce security policies in light of the specific user”) the resource, (see Kaushik, [0022] “an estimate representing predicted resource usage for executing instructions included in a database statement according to an execution plan”) that the database operation is permitted (see Ahmed, [0059] “implements a data access control policy that provides row-level and/or column-level access control to data stored in database system 120. The data access control policy may be specified using one or more access control lists. Each access control list specifies what privileges (e.g., read or write) can be performed by which principals, where each principal is a user or role in the database system”; [0071] “data access control policies may only allow access to users that are associated with the value of “West” as the “Organization” attribute”).
The proposed combination of Kaushik and Ahmed does not explicitly teach selecting a rule of the data-access policy based on the group identifier and determining, by the applying the rule to the resource.
However, Khanduja discloses restricted portion of data element based on access control policy and teaches
selecting a rule of control policy determining, by applying the rule to the data elements (see Khanduja, [0009] “ensuring fine-grained security rules and policies when provisioning data through PL/SQL procedures”; [0057] “The computer system determines whether the access control policy restricts user access to a restricted portion of the requested data elements”).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to include the functionality of rules related to data access policy, prohibits access, modifying SQL statements, log records and timestamps, as being disclosed and taught by Khanduja, in the system taught by the proposed combination of Kaushik and Ahmed to yield the predictable results of improving data security (see Khanduja, [0009] “The example data access system improves data security by ensuring fine-grained security rules and policies when provisioning data through PL/SQL procedures. The benefits of using stored procedures rather than application code stored locally on client computers include allowing for modular programming, faster execution, reduce network traffic, and can be used as a security mechanism”).
Regarding claim 36, the proposed combination of Kaushik and Ahmed teaches
wherein determining that the data-access policy permits access (see Ahmed, [0059] “implements a data access control policy that provides row-level and/or column-level access control to data stored in database system 120. The data access control policy may be specified using one or more access control lists. Each access control list specifies what privileges (e.g., read or write) can be performed by which principals, where each principal is a user or role in the database system”; [0071] “data access control policies may only allow access to users that are associated with the value of “West” as the “Organization” attribute”) the database operation comprises… (see Kaushik, [0022] “an “execution plan” generally refers to ordered operations for performing instructions related to a database statement”)
obtaining, from the data-access policy, (see Ahmed, [0063] “a data access control policy determines”) a user-access designation associated with (see Ahmed, [0059] “Each access control list specifies what privileges (e.g., read or write) can be performed by which principals, where each principal is a user or role in the database system”) the application-user information; (see Kaushik, [0031]-[0032] “The application server 106 can be configured to execute one or more applications 112 configured to facilitate retrieving or otherwise interacting with records (e.g., patient records 132) in a database 109 provided by the database server 108… the application 112 can include components configured to create a database statement 120 for accessing data in the database 109 based on user input to, for example, locate a patient record 132 in the database 109… include a computing device that facilitates access to the application server 106 via the computer network 104 by users 101… identified as a user 101”; [0054] “upon actuation of the submit button 118 by the user 101, the application 112 can be configured to generate the database statement 120 based on the received user input… the database statement 120 can include instructions for the database server 108 to process for requesting certain patient records 132 associated with the received user input or performing other suitable actions”; [0026] “the computing system 100”).
obtaining, from the data-access policy, (see Ahmed, [0063] “a data access control policy determines”) a resource-access designation associated with the resource; and (see Ahmed, [0059] “implements a data access control policy that provides row-level and/or column-level access control to data stored in database system 120”).
.. to the user-access designation and (see Ahmed, [0059] “Each access control list specifies what privileges (e.g., read or write) can be performed by which principals, where each principal is a user or role in the database system”) the resource- access designation, (see Ahmed, [0059] “implements a data access control policy that provides row-level and/or column-level access control to data stored in database system 120”) that the database operation (see Kaushik, [0022] “an “execution plan” generally refers to ordered operations for performing instructions related to a database statement”) is permitted (see Ahmed, [0059] “implements a data access control policy that provides row-level and/or column-level access control to data stored in database system 120. The data access control policy may be specified using one or more access control lists. Each access control list specifies what privileges (e.g., read or write) can be performed by which principals, where each principal is a user or role in the database system”; [0071] “data access control policies may only allow access to users that are associated with the value of “West” as the “Organization” attribute”).
The proposed combination of Kaushik and Ahmed does not explicitly teach determining, by the applying a rule to the user-access designation.
However, Khanduja discloses restricted portion of data element based on access control policy and teaches
determining, by applying a rule for user access control (see Khanduja, [0009] “ensuring fine-grained security rules and policies when provisioning data through PL/SQL procedures”; [0057] “The computer system determines whether the access control policy restricts user access to a restricted portion of the requested data elements”).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to include the functionality of rules related to data access policy, prohibits access, modifying SQL statements, log records and timestamps, as being disclosed and taught by Khanduja, in the system taught by the proposed combination of Kaushik and Ahmed to yield the predictable results of improving data security (see Khanduja, [0009] “The example data access system improves data security by ensuring fine-grained security rules and policies when provisioning data through PL/SQL procedures. The benefits of using stored procedures rather than application code stored locally on client computers include allowing for modular programming, faster execution, reduce network traffic, and can be used as a security mechanism”).
Regarding claim 39, the proposed combination of Kaushik and Ahmed teaches
wherein: the SQL statement identifies an additional resource of the database; (see Kaushik, [0071] “for the costing request 122, the statement optimizer 146 can include, for example, a request for a cardinality estimation and a selectivity estimation associated with the restricted column illness of the table”).
the method further comprises determining, based on the application-user information and (see Kaushik, [0031]-[0032] “The application server 106 can be configured to execute one or more applications 112 configured to facilitate retrieving or otherwise interacting with records (e.g., patient records 132) in a database 109 provided by the database server 108… the application 112 can include components configured to create a database statement 120 for accessing data in the database 109 based on user input to, for example, locate a patient record 132 in the database 109… include a computing device that facilitates access to the application server 106 via the computer network 104 by users 101… identified as a user 101”; [0054] “upon actuation of the submit button 118 by the user 101, the application 112 can be configured to generate the database statement 120 based on the received user input… the database statement 120 can include instructions for the database server 108 to process for requesting certain patient records 132 associated with the received user input or performing other suitable actions”) the additional resource, (see Kaushik, [0071] “for the costing request 122, the statement optimizer 146 can include, for example, a request for a cardinality estimation and a selectivity estimation associated with the restricted column illness of the table”) that the data-access policy access… (see Ahmed, [0059] “implements a data access control policy that provides row-level and/or column-level access control to data stored in database system 120. The data access control policy may be specified using one or more access control lists. Each access control list specifies what privileges (e.g., read or write) can be performed by which principals, where each principal is a user or role in the database system”; [0071] “data access control policies may only allow access to users that are associated with the value of “West” as the “Organization” attribute”) the database operation (see Kaushik, [0022] “an “execution plan” generally refers to ordered operations for performing instructions related to a database statement”) with respect to the additional resource; and (see Kaushik, [0071] “for the costing request 122, the statement optimizer 146 can include, for example, a request for a cardinality estimation and a selectivity estimation associated with the restricted column illness of the table”).
causing the database to perform the database operation comprises… (see Kaushik, [0019] “a “database statement” generally refers to a structured statement executable in a database for performing certain requested action(s)… a database statement can request retrieval of certain records in a database based on one or more queries… the database statement can comprise a query and a predicate may limit the rows of a column that are returned when the query is executed”) to the additional resource and (see Kaushik, [0071] “for the costing request 122, the statement optimizer 146 can include, for example, a request for a cardinality estimation and a selectivity estimation associated with the restricted column illness of the table”).
The proposed combination of Kaushik and Ahmed does not explicitly teach prohibits the database operation; modifying the SQL statement to the additional resource and causing the database to execute the modified SQL statement.
However, Khanduja discloses restricted portion of data element based on access control policy and teaches
prohibits access (see Khanduja, [0009] “ensuring fine-grained security rules and policies when provisioning data through PL/SQL procedures”; [0057] “The computer system determines whether the access control policy restricts user access to a restricted portion of the requested data elements”).
modifying the SQL statement… causing the database to execute the modified SQL statement (see Khanduja, [0044] “the reconstruction system 222 receives the P-DSTC 214 and SQL statements from P-statement list 212 as input and generates a modified or reconstructed procedural code block referred to as a modified procedure 224”; [0050] “The reconstruction system 308 can rewrite the database statements 304 using a variety of methods… may thereafter provide the reconstructed procedure to the distributed database to receive data elements to which the user is permitted to access (e.g., as defined by the modified procedure)”).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to include the functionality of rules related to data access policy, prohibits access, modifying SQL statements, log records and timestamps, as being disclosed and taught by Khanduja, in the system taught by the proposed combination of Kaushik and Ahmed to yield the predictable results of improving data security (see Khanduja, [0009] “The example data access system improves data security by ensuring fine-grained security rules and policies when provisioning data through PL/SQL procedures. The benefits of using stored procedures rather than application code stored locally on client computers include allowing for modular programming, faster execution, reduce network traffic, and can be used as a security mechanism”).
Regarding claim 42, the proposed combination of Kaushik and Ahmed teaches
…. the application-user information, (see Kaushik, [0031]-[0032] “The application server 106 can be configured to execute one or more applications 112 configured to facilitate retrieving or otherwise interacting with records (e.g., patient records 132) in a database 109 provided by the database server 108… the application 112 can include components configured to create a database statement 120 for accessing data in the database 109 based on user input to, for example, locate a patient record 132 in the database 109… include a computing device that facilitates access to the application server 106 via the computer network 104 by users 101… identified as a user 101”; [0054] “upon actuation of the submit button 118 by the user 101, the application 112 can be configured to generate the database statement 120 based on the received user input… the database statement 120 can include instructions for the database server 108 to process for requesting certain patient records 132 associated with the received user input or performing other suitable actions”) an identifier of the database-user account, (see Ahmed, [0102] “a single user may be shared by multiple database sessions. A single end-user request (e.g., from client 102) may result in multiple connections between an application in middle tier 110 and database system 120”; [0121] “One or more specific users in database system 120 are granted these privileges”; [0123] “can authenticate session manager 118 to database system 120, then session manager 118 can perform the corresponding task of initiating the creation and management of authenticated sessions for application users in database system 120”) the SQL statement, and… (see Kaushik, [0055] “the example SQL statement comprises a database command (i.e., select)”).
The proposed combination of Kaushik and Ahmed does not explicitly teach further comprising storing a log record that associates a timestamp.
However, Khanduja discloses restricted portion of data element based on access control policy and teaches
further comprising storing a log record that associates… a timestamp (See Khanduja, [0046] “a history of accessed data elements based on PL/SQL code blocks (e.g., a reconstructed procedure) and/or stored procedures previously defined may be stored in a log by data access system 114a. The log may identify, for instance, the identity of the user accessing the data elements, identity of the data elements that a user accessed and/or was permitted to access, the time of access”).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to include the functionality of rules related to data access policy, prohibits access, modifying SQL statements, log records and timestamps, as being disclosed and taught by Khanduja, in the system taught by the proposed combination of Kaushik and Ahmed to yield the predictable results of improving data security (see Khanduja, [0009] “The example data access system improves data security by ensuring fine-grained security rules and policies when provisioning data through PL/SQL procedures. The benefits of using stored procedures rather than application code stored locally on client computers include allowing for modular programming, faster execution, reduce network traffic, and can be used as a security mechanism”).
Regarding claim 43, the proposed combination of Kaushik and Ahmed teaches
wherein the SQL request is conveyed over a database session (see Kaushik, [0046] “receiving a client request, applications 112 and 114 send requests to database system 120 through database connections”) authenticated with a database-user account (see Ahmed, [0102] “a single user may be shared by multiple database sessions. A single end-user request (e.g., from client 102) may result in multiple connections between an application in middle tier 110 and database system 120”; [0121] “One or more specific users in database system 120 are granted these privileges”; [0123] “can authenticate session manager 118 to database system 120, then session manager 118 can perform the corresponding task of initiating the creation and management of authenticated sessions for application users in database system 120”) different from an application account of the application user, (see Ahmed, [0132]-[0134] “Another scenario is referred to as the “non-transparent scenario” where an application explicitly calls session management operations. When acting as a privileged application user, session manager 118 may operate differently depending on which scenario session manager 118 is operating… In the non-transparent scenario, an application (e.g., application 114) explicitly calls one or more session management operations, such as create session or attach session. Session manager 118 intercepts the calls and inserts trust data into the calls before forwarding the calls to database system 120”) the SQL comment is a syntactic SQL comment embedded in the SQL request and (see Kaushik, [0024] “"parsing" a database statement generally refers to examining characters in a database statement and recognizing commands, string literals, and comments by detecting keywords and identifiers and matching an overall structure of the database statement to a set of syntax rules applicable to the database”) comprising a named field containing (see Ahmed, [0054] “the fields are referred to as columns”) the application-user information, (see Kaushik, [0031]-[0032] “The application server 106 can be configured to execute one or more applications 112 configured to facilitate retrieving or otherwise interacting with records (e.g., patient records 132) in a database 109 provided by the database server 108… the application 112 can include components configured to create a database statement 120 for accessing data in the database 109 based on user input to, for example, locate a patient record 132 in the database 109… include a computing device that facilitates access to the application server 106 via the computer network 104 by users 101… identified as a user 101”; [0054] “upon actuation of the submit button 118 by the user 101, the application 112 can be configured to generate the database statement 120 based on the received user input… the database statement 120 can include instructions for the database server 108 to process for requesting certain patient records 132 associated with the received user input or performing other suitable actions”; [0026] “the computing system 100”) the SQL comment is not used by the database to determine the database operation, (see Ahmed, [0143] “When an application data request (e.g., a SQL query) is executed on a connection”– SQL comment is not being used and the claim limitations are in an alternative form and one of the alternate limitation is addressed) obtaining the application-user information comprises (see Kaushik, [0031]-[0032] “The application server 106 can be configured to execute one or more applications 112 configured to facilitate retrieving or otherwise interacting with records (e.g., patient records 132) in a database 109 provided by the database server 108… the application 112 can include components configured to create a database statement 120 for accessing data in the database 109 based on user input to, for example, locate a patient record 132 in the database 109… include a computing device that facilitates access to the application server 106 via the computer network 104 by users 101… identified as a user 101”; [0054] “upon actuation of the submit button 118 by the user 101, the application 112 can be configured to generate the database statement 120 based on the received user input… the database statement 120 can include instructions for the database server 108 to process for requesting certain patient records 132 associated with the received user input or performing other suitable actions”) parsing the named field (see Kaushik, [0075] “table access scan… the total cost for the execution plan may be estimated to be 39 by adding component costs associated with each operation of the execution plan… the operation on encrypted column illness is greater than if the column were not encrypted, because the cost for executing the predicate on the illness column can comprise encrypted data processing costs associated with that operation”) before (see Ahmed, [0143] “When an attach session operation is invoked before executing the data request”) the database performs the database operation, (see Kaushik, [0022] “an “execution plan” generally refers to ordered operations for performing instructions related to a database statement”) the resource comprises a table (see Kaushik, [0059] “the example SQL statement comprises a database command (i.e., select), identification of a table (i.e., patients), table columns (i.e., sate, illness, and sex)” - the claim limitations are in an alternative form and one of the alternate limitation is addressed) identified by parsing the SQL statement, (see Kaushik, [0024] “"parsing" a database statement generally refers to examining characters in a database statement and recognizing commands, string literals, and comments by detecting keywords and identifiers and matching an overall structure of the database statement to a set of syntax rules applicable to the database”; [0064] “can parse the database statement 120 to identify one or more instructions in the database statement 120… the database statement 120 that includes a full table scan for accessing data described by the database statement 120”) the data-access policy comprises… (see Ahmed, [0059] “implements a data access control policy that provides row-level and/or column-level access control to data stored in database system 120. The data access control policy may be specified using one or more access control lists. Each access control list specifies what privileges (e.g., read or write) can be performed by which principals, where each principal is a user or role in the database system”; [0071] “data access control policies may only allow access to users that are associated with the value of “West” as the “Organization” attribute”) the application-user information and (see Kaushik, [0031]-[0032] “The application server 106 can be configured to execute one or more applications 112 configured to facilitate retrieving or otherwise interacting with records (e.g., patient records 132) in a database 109 provided by the database server 108… the application 112 can include components configured to create a database statement 120 for accessing data in the database 109 based on user input to, for example, locate a patient record 132 in the database 109… include a computing device that facilitates access to the application server 106 via the computer network 104 by users 101… identified as a user 101”; [0054] “upon actuation of the submit button 118 by the user 101, the application 112 can be configured to generate the database statement 120 based on the received user input… the database statement 120 can include instructions for the database server 108 to process for requesting certain patient records 132 associated with the received user input or performing other suitable actions”) specifying permission for the database operation with respect to the resource, (see Ahmed, [0062] “that define the access privileges to particular principals to particular rows of one or more database tables”) and causing the database to perform the database operation comprises (see Kaushik, [0019] “a “database statement” generally refers to a structured statement executable in a database for performing certain requested action(s)… a database statement can request retrieval of certain records in a database based on one or more queries… the database statement can comprise a query and a predicate may limit the rows of a column that are returned when the query is executed”) submitting the SQL statement for execution (see Kaushik, [0054] “upon actuation of the submit button 118 by the user 101, the application 112 can be configured to generate the database statement 120 based on the received user input… the database statement 120 can include instructions for the database server 108 to process for requesting certain patient records 132 associated with the received user input or performing other suitable actions”) under the database-user account (see Ahmed, [0102] “a single user may be shared by multiple database sessions. A single end-user request (e.g., from client 102) may result in multiple connections between an application in middle tier 110 and database system 120”; [0121] “One or more specific users in database system 120 are granted these privileges”; [0123] “can authenticate session manager 118 to database system 120, then session manager 118 can perform the corresponding task of initiating the creation and management of authenticated sessions for application users in database system 120”).
The proposed combination of Kaushik and Ahmed does not explicitly teach a rule associated with the application-user information.
However, Khanduja discloses restricted portion of data element based on access control policy and teaches
a rule associated with user access (see Khanduja, [0009] “ensuring fine-grained security rules and policies when provisioning data through PL/SQL procedures”; [0057] “The computer system determines whether the access control policy restricts user access to a restricted portion of the requested data elements”).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to include the functionality of rules related to data access policy, prohibits access, modifying SQL statements, log records and timestamps, as being disclosed and taught by Khanduja, in the system taught by the proposed combination of Kaushik and Ahmed to yield the predictable results of improving data security (see Khanduja, [0009] “The example data access system improves data security by ensuring fine-grained security rules and policies when provisioning data through PL/SQL procedures. The benefits of using stored procedures rather than application code stored locally on client computers include allowing for modular programming, faster execution, reduce network traffic, and can be used as a security mechanism”).
Claim 40 is rejected under 35 U.S.C. 103 as being unpatentable over Kaushik in view of Ahmed further in view of Oliner et al. (US 2018/0314853 A1, hereinafter “Oliner”).
Regarding claim 40, the proposed combination of Kaushik and Ahmed teaches
further comprising: obtaining a database response comprising (see Kaushik, [0019] “a “database statement” generally refers to a structured statement executable in a database for performing certain requested action(s)… a database statement can request retrieval of certain records in a database based on one or more queries… the database statement can comprise a query and a predicate may limit the rows of a column that are returned when the query is executed”; [0034] “The statement results 129 are generated based on the patient records 132 in the database 109 in response to the database statement 120”) a value from the resource and an additional value from an additional resource identified by the SQL statement; (see Kaushik, [0050] “the statement processor 148 is configured to transfer all columns to the trusted machine 152 that need processing, including unencrypted columns, and receive all columns back after processing by the TM statement processor 158” – there are plurality of columns; [0078] “comprising values from column illness that is contained in the result 129 received from the trusted machine 152”).
determining, based on the application-user information and (see Kaushik, [0031]-[0032] “The application server 106 can be configured to execute one or more applications 112 configured to facilitate retrieving or otherwise interacting with records (e.g., patient records 132) in a database 109 provided by the database server 108… the application 112 can include components configured to create a database statement 120 for accessing data in the database 109 based on user input to, for example, locate a patient record 132 in the database 109… include a computing device that facilitates access to the application server 106 via the computer network 104 by users 101… identified as a user 101”; [0054] “upon actuation of the submit button 118 by the user 101, the application 112 can be configured to generate the database statement 120 based on the received user input… the database statement 120 can include instructions for the database server 108 to process for requesting certain patient records 132 associated with the received user input or performing other suitable actions”) the additional resource, (see Kaushik, [0050] “the statement processor 148 is configured to transfer all columns to the trusted machine 152 that need processing, including unencrypted columns, and receive all columns back after processing by the TM statement processor 158” – there are plurality of columns) that the data-access policy (see Ahmed, [0059] “implements a data access control policy that provides row-level and/or column-level access control to data stored in database system 120. The data access control policy may be specified using one or more access control lists. Each access control list specifies what privileges (e.g., read or write) can be performed by which principals, where each principal is a user or role in the database system”; [0071] “data access control policies may only allow access to users that are associated with the value of “West” as the “Organization” attribute”) prohibits providing (see Ahmed, [0061] “Thus, each access control entry may specify at least a particular privilege, a value indicating whether the privilege is granted or denied”) the additional value (see Kaushik, [0050] “the statement processor 148 is configured to transfer all columns to the trusted machine 152 that need processing, including unencrypted columns, and receive all columns back after processing by the TM statement processor 158” – there are plurality of columns; [0078] “comprising values from column illness that is contained in the result 129 received from the trusted machine 152”) to the application user; (see Ahmed, [0050] “An application role is a logical grouping of application privileges that are required to accomplish a task. An application role may be granted to one or more other application roles. Application roles are used to associate application users with privileges”).
… the additional value (see Kaushik, [0050] “the statement processor 148 is configured to transfer all columns to the trusted machine 152 that need processing, including unencrypted columns, and receive all columns back after processing by the TM statement processor 158” – there are plurality of columns; [0078] “comprising values from column illness that is contained in the result 129 received from the trusted machine 152”).
… in response to the SQL request (see Kaushik, [0041] “In response to receiving the request from the untrusted machine 142 to process the database statement 120… In response to receiving the database statement 120 comprising the parameterized contents, the untrusted machine 142 can be configured to request that the trusted machine 152 to process the database statement 120”; [0026] “the computing system 100”).
The proposed combination of Kaushik and Ahmed does not explicitly teach modifying the database response by replacing the additional value with a mask value while retaining the value from the resource, thereby forming a modified database response; and providing the modified database response.
However, Oliner discloses masking information and teaches
modifying the database response by replacing values with a mask value while retaining the value from the resource, thereby forming a modified database response; and (see Oliner, [0264] “a query (e.g., search query 2012) could reference the field in one or more query commands of the query language. This can allow the system to automatically mask (e.g., delete or replace) the PII values from the query results by referencing the field”; [0064] “many reasons to retain more of the data”).
providing the modified database response (see Oliner, [0264] “a query (e.g., search query 2012) could reference the field in one or more query commands of the query language. This can allow the system to automatically mask (e.g., delete or replace) the PII values from the query results by referencing the field”; [0260]-[0262] “displaying PII values identified using extraction rules generated based on the example values, and/or masking or otherwise taking action based on identified PII values using user interface 1900 or another user interface… the PII value is masked from machine data. Masking a PII value can generally refer to preventing the PII value from being displayed or otherwise provided to a user”).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to include the functionality modifying database response to replace values as being disclosed and taught by Oliner, in the system taught by the proposed combination of Kaushik and Ahmed to yield the predictable results of effectively identifying and masking unauthorized information (see Oliner, [0211] “It would be desirable for a computing system to have the capability to effectively identify this type information so that appropriate actions can be taken. Appropriate actions may include removing, replacing, obscuring, or otherwise masking this type of information from being accessed by or displayed to unauthorized users, and/or to generate alerts and/or records of the access or display”).
Claim 41 is rejected under 35 U.S.C. 103 as being unpatentable over Kaushik in view of Ahmed further in view of Foley et al. (US 2014/0165189 A1, hereinafter “Foley”).
Regarding claim 41, the proposed combination of Kaushik and Ahmed teaches
wherein determining that the data-access policy permits access (see Ahmed, [0059] “implements a data access control policy that provides row-level and/or column-level access control to data stored in database system 120. The data access control policy may be specified using one or more access control lists. Each access control list specifies what privileges (e.g., read or write) can be performed by which principals, where each principal is a user or role in the database system”; [0071] “data access control policies may only allow access to users that are associated with the value of “West” as the “Organization” attribute”) the database operation comprises: (see Kaushik, [0022] “an “execution plan” generally refers to ordered operations for performing instructions related to a database statement”).
… the application-user information and (see Kaushik, [0031]-[0032] “The application server 106 can be configured to execute one or more applications 112 configured to facilitate retrieving or otherwise interacting with records (e.g., patient records 132) in a database 109 provided by the database server 108… the application 112 can include components configured to create a database statement 120 for accessing data in the database 109 based on user input to, for example, locate a patient record 132 in the database 109… include a computing device that facilitates access to the application server 106 via the computer network 104 by users 101… identified as a user 101”; [0054] “upon actuation of the submit button 118 by the user 101, the application 112 can be configured to generate the database statement 120 based on the received user input… the database statement 120 can include instructions for the database server 108 to process for requesting certain patient records 132 associated with the received user input or performing other suitable actions”)
… specified by the data-access policy (see Ahmed, [0059] “implements a data access control policy that provides row-level and/or column-level access control to data stored in database system 120. The data access control policy may be specified using one or more access control lists. Each access control list specifies what privileges (e.g., read or write) can be performed by which principals, where each principal is a user or role in the database system”; [0071] “data access control policies may only allow access to users that are associated with the value of “West” as the “Organization” attribute”).
The proposed combination of Kaushik and Ahmed does not explicitly teach determining a count of SQL requests associated with the application-user information and obtained during a time interval; and determining that the count does not exceed a maximum count.
However, Foley discloses SQL requests and teaches
determining a count of SQL requests associated with a specific SQL construct… obtained during a time interval; and (see Foley, [0136] “Contains the count of executions for a specific SQL construct (Select, drop, etc.) during a specific period of time for a specific session).
determining that the count (see Foley, [0136] “Contains the count of executions for a specific SQL construct (Select, drop, etc.) during a specific period of time for a specific session”) does not exceed a maximum count (see Foley, [0069] “Once all accumulated records affected reach the threshold”).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to include the functionality modifying database response to replace values as being disclosed and taught by Foley, in the system taught by the proposed combination of Kaushik and Ahmed to yield the predictable results of effectively analyzing client requests (see Foley, [0074] “Specifically, audit program 405 has collector, analyzer and parser modules. Collector module 450 collects each client request 420 and passes it to analyzer module 455, which is configured with various protocol structures in use for data transmission by numerous applications and databases”).
Citation Of Relevant Prior Art
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
US Patent No. US 7,558,738 B1 (Flatt) teaches comments concerning requests, however it does not clarify determining comments, adding comments and other claim limitations.
Conclusion
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to VAISHALI SHAH whose telephone number is (571)272-8532. The examiner can normally be reached Monday - Friday (7:30 AM to 4:00 PM).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, AJAY BHATIA can be reached at (571)272-3906. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/VAISHALI SHAH/Primary Examiner, Art Unit 2156