Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Detailed Action
Claims 1-23 are pending
Priority
This application is a continuation of U.S. patent application Ser. No. 17/687,235 filed Mar. 4, 2022, which is a division of U.S. patent application Ser. No. 16/714,318, filed Dec. 13, 2019, now U.S. Pat. No. 11,496,479 issued Nov. 8, 2022. Therefore, the effective filing date of this application is 12/13/2019.
Drawings
Applicants’ drawing filed on 04/22/2025 has been inspected and it is in compliance with MPEP 608.02.
Specification
The specification filed on 04/22/2025 is acceptable for examination proceedings.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 04/22/2025. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement has been considered by the examiner.
Claim Objections
Claims 2-21 are objected to because of the following informalities: independent claim 1 recites of “A data control method …”. However, dependent claims 2-21 recite of just “The method …”. Examiner suggests replacing “The method …” with “The data control method …”. Appropriate correction is required.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION. —The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
Claims 1-23 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claims 1 and 23 recite the limitation “based on the indication of at least one recipient with which to share the data”. However, the claims previously recite “receiving from the particular user an indication of at least one recipient with which to share the data”. It is unclear if the “at least one recipient” recited in this claim is the same as the one recited in the previous limitation. For the purpose of examination Examiner is interpreting them to be the same and interpreting the limitation as “based on the indication of the at least one recipient with which to share the data”. Appropriate correction is required.
Claims 2-21 depend on claim 1. Therefore, they also inherit the rejection.
Claim 8 recites the limitation “an indication of at least one recipient”. However, claim 1 already recites of “an indication of at least one recipient”. It is unclear if the indication and recipient recited in claim 8 is the same as the one recited in claim 1. For the purpose of examination Examiner is interpreting them to be the same and interpreting the limitation as “the indication of the at least one recipient”. Appropriate correction is required.
Claim 17 recites the limitation “the indication of at least one recipient”. However, claim 1 already recites of “an indication of at least one recipient”. It is unclear if the recipient recited in claim 17 is the same as the one recited in claim 1. For the purpose of examination Examiner is interpreting them to be the same and interpreting the limitation as “the indication of the at least one recipient”. Appropriate correction is required.
Claim 22 recites the limitation “based on at least one allowed action”. However, claim 22 recites in a previous limitation “receiving from the user at least one allowed action for the data”. It is unclear if the allowed actions are the same or different. For the purpose of examination Examiner is interpreting them to be the same, and interpreting the limitation as “based on the at least one allowed action”. Appropriate correction is required.
Claim 22 recites the limitation “based on the indication of the combined multidimensional vector”. There is insufficient antecedent basis for “the indication of the combined multidimensional vector”. For the purpose of examination Examiner is interpreting this limitation as “based on the determination of the combined multidimensional vector”. Appropriate correction is required.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13.
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer.
Claims 1-23 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-18 of U.S. Patent No. US 12289312 B2. Although the claims at issue are not identical, they are not patentably distinct from each other because the corresponding claims further recite similar/same limitation of the same subject matter.
Current application 19/186,133
U.S. Patent No. US 12289312 B2
1.) A data control method comprising:
receiving from a particular user an indication of data for sharing;
determining a first multidimensional vector based on the indication of data for sharing;
receiving from the particular user an indication of at least one recipient with which to share the data;
determining a second multidimensional vector based on the indication of at least one recipient with which to share the data;
determining a combined multidimensional vector based on the first multidimensional vector and the second multidimensional vector;
determining a multidimensional zone based on the combined multidimensional vector;
accessing via a network a plurality of application program interfaces (APIs) for a plurality of applications; and
setting data sharing permissions for the particular user for each of the plurality of applications based on the multidimensional zone via the plurality of APIs.
1. A data control method comprising:
receiving from a user an indication of data for sharing;
receiving from the user an indication of at least one recipient with which to share the data;
receiving from the user at least one allowed action for the data;
determining a first multidimensional vector based on the indication of the data for sharing;
determining a second multidimensional vector based on the indication of the at least one recipient with which to share the data;
determining a third multidimensional vector based on the at least one allowed action for the data;
determining a multidimensional zone based on the indication of the data for sharing, the indication of the at least one recipient, and the at least one allowed action for the data, the determining the multidimensional zone comprises determining a combined multidimensional vector based on the first multidimensional vector, the second multidimensional vector, and the third multidimensional vector;
accessing via a network a plurality of application program interfaces (APIs) for a plurality of applications; and
setting data sharing permissions for the user for each of the plurality of applications based on the multidimensional zone via the plurality of APIs.
2. The method of claim 1, the setting of the data sharing permissions comprising selecting predefined permissions via the plurality of APIs.
2. The data control method of claim 1, the setting of the data sharing permissions comprising selecting predefined permissions via the plurality of APIs.
3. The method of claim 1, further comprising:
determining a modification by the particular user of the data sharing permissions for a particular one of the plurality of applications;
re-determining the multidimensional zone based on the modification of the data sharing permissions; and
re-setting the data sharing permissions for the particular user for at least one other of the plurality of applications based on the re-determined multidimensional zone via at least one of the plurality of APIs.
3. The data control method of claim 1, further comprising:
determining a modification by the user of the data sharing permissions for a particular one of the plurality of applications;
re-determining the multidimensional zone based on the modification of the data sharing permissions; and
re-setting the data sharing permissions for the user for at least one other of the plurality of applications based on the re-determined multidimensional zone via at least one of the plurality of APIs.
4. The method of claim 1, the receiving from the particular user of the indication of the data for sharing comprising receiving at least one of an indication of photos for sharing or an indication of contacts for sharing.
4. The data control method of claim 1, the receiving from the user of the indication of the data for sharing comprising receiving at least one of an indication of photos for sharing or an indication of contacts for sharing.
5. The method of claim 1, the receiving from the particular user of the indication of the data for sharing comprising receiving an indication of location of a computing device of the particular user.
5. The data control method of claim 1, the receiving from the user of the indication of the data for sharing comprising receiving an indication of location of a computing device of the user.
6. The method of claim 1, the receiving from the particular user the indication of the at least one recipient with which to share the data comprising receiving an indication of at least one of a particular application with which to share the data or an indication of a network destination with which to share the data.
6. The data control method of claim 1, the receiving from the user of the indication of the at least one recipient with which to share the data comprising receiving an indication of at least one of a particular application with which to share the data or an indication of a network destination with which to share the data.
7. The method of claim 1, the receiving from the particular user of the indication of the data for sharing comprising receiving an indication of data not for sharing, the data not for sharing comprising at least one of a name of the particular user, an address of the particular user, a telephone number of the particular user, an email address of the particular user, photos, or an identification number of the particular user.
7. The data control method of claim 1, the receiving from the user of the indication of the data for sharing comprising receiving an indication of data not for sharing, the data not for sharing comprising at least one of a name of the user, an address of the user, a telephone number of the user, an email address of the user, photos, or an identification number of the user.
8. The method of claim 1, the receiving from the particular user an indication of at least one recipient with which to share the data comprising receiving from the particular user an indication to share the data via the network.
8. The data control method of claim 1, the receiving from the user of the indication of the at least one recipient with which to share the data comprising receiving from the user an indication to share the data via the network.
9. The method of claim 1, wherein the setting of the data sharing permissions for the particular user for each of the plurality of applications comprises:
setting rules indicating information to be shared; and
setting rules indicating targets of the information to be shared;
wherein the setting of the rules indicating the information to be shared and the setting of the rules indicating the targets of the information to be shared comprises establishing a multidimensional coordinate based on the information to be shared and the targets of the information to be shared to be within the multidimensional zone.
9. The data control method of claim 1, wherein the setting of the data sharing permissions for the user for each of the plurality of applications comprises:
setting rules indicating information to be shared; and
setting rules indicating targets of the information to be shared;
wherein the setting of the rules indicating the information to be shared and the setting of the rules indicating the targets of the information to be shared comprises establishing a multidimensional coordinate based on the information to be shared and the targets of the information to be shared to be within the multidimensional zone.
10. The method of claim 1, wherein the setting of the data sharing permissions for the particular user for each of the plurality of applications comprises:
setting rules indicating information to be shared;
setting rules indicating targets of the information to be shared;
determining a first position vector based on the information to be shared; and
determining a second position vector based on the targets of the information to be shared;
wherein the setting of the rules indicating the information to be shared and the setting of the rules indicating the targets of the information to be shared comprises establishing a multidimensional coordinate based on the first position vector and the second position vector.
10. The data control method of claim 1, wherein the setting of the data sharing permissions for the user for each of the plurality of applications comprises:
setting rules indicating information to be shared;
setting rules indicating targets of the information to be shared;
determining a first position vector based on the information to be shared; and
determining a second position vector based on the targets of the information to be shared;
wherein the setting of the rules indicating the information to be shared and the setting of the rules indicating the targets of the information to be shared comprises establishing a multidimensional coordinate based on the first position vector and the second position vector.
11. The method of claim 1, further comprising:
receiving from the particular user at least one allowed action for the data; and
determining the multidimensional zone further based on the at least one allowed action for the data, the determining the multidimensional zone comprising determining the combined multidimensional vector based on the indication of the data for sharing, the indication of the at least one recipient, and the at least one allowed action for the data.
1. … determining a multidimensional zone based on the indication of the data for sharing, the indication of the at least one recipient, and the at least one allowed action for the data, the determining the multidimensional zone comprises determining a combined multidimensional vector based on the first multidimensional vector, the second multidimensional vector, and the third multidimensional vector; …
12. The method of claim 11, the receiving from the particular user the at least one allowed action for the data comprising receiving an indication that the data can be shared by the at least one recipient with other recipients.
11. The data control method of claim 1, the receiving from the user the at least one allowed action for the data comprising receiving an indication that the data can be shared by the at least one recipient with other recipients.
13. The method of claim 11, the receiving from the particular user the at least one allowed action for the data comprising receiving an indication that the data can be used by the at least one recipient in building at least one of an application or a service.
12. The data control method of claim 1, the receiving from the user the at least one allowed action for the data comprising receiving an indication that the data can be used by the at least one recipient in building at least one of an application or a service.
14. The method of claim 11, the receiving from the particular user the at least one allowed action for the data comprising receiving an indication that the data can be used to enable transmission of at least one of advertisements, offers, or coupons to the particular user.
13. The data control method of claim 1, the receiving from the user the at least one allowed action for the data comprising receiving an indication that the data can be used to enable transmission of at least one of advertisements, offers, or coupons to the user.
15. The method of claim 11, the receiving from the particular user the at least one allowed action for the data comprising receiving an indication that the data can be sold.
14. The data control method of claim 1, the receiving from the user the at least one allowed action for the data comprising receiving an indication that the data can be sold.
16. The method of claim 11, the receiving from the particular user the at least one allowed action for the data comprising receiving an indication that the data can be sold by the at least one recipient.
15. The data control method of claim 1, the receiving from the user the at least one allowed action for the data comprising receiving an indication that the data can be sold by the at least one recipient.
17. The method of claim 1, wherein:
determining the first multidimensional vector comprises determining a first value on a first axis based on the indication of data for sharing; and
determining the second multidimensional vector comprises determining a second value on a second axis based on the indication of at least one recipient with which to share the data.
17. … determining a first value on a first axis based on the indication of the data for sharing;
determining a second value on a second axis based on the indication of the at least one recipient with which to share the data;
…
18. The method of claim 1, further comprising:
receiving identifying information of the particular user;
receiving identifying information of a plurality of other users;
comparing the identifying information of the particular user and the identifying information of the plurality of other users;
receiving from the other users a plurality of indications of information for sharing;
receiving from the other users a plurality of indications of recipients with which to share the information; and
determining the multidimensional zone further based on the plurality of indications of information for sharing, the plurality of indications of recipients with which to share the information, and the comparing of the identifying information of the particular user and the identifying information of the plurality of other users.
18. … receiving from the particular user at least one allowed action for the data;
receiving identifying information of the particular user;
receiving identifying information of a plurality of other users;
comparing the identifying information of the particular user and the identifying information of the plurality of other users;
receiving from the plurality of other users a plurality of indications of information for sharing;
receiving from the plurality of other users a plurality of indications of recipients with which to share the information for sharing;
receiving from the plurality of other users a plurality of allowed actions for the information for sharing; and
determining a multidimensional zone based on the indication of the data for sharing, the indication of the at least one recipient, the at least one allowed action for the data, the plurality of indications of the information for sharing, the plurality of indications of the recipients with which to share the information for sharing, the plurality of allowed actions for the information for sharing, and the comparing of the identifying information of the particular user and the identifying information of the plurality of other users;
….
19. The method of claim 1, further comprising:
accessing for each of the plurality of applications at least one of a manifest, an end-user license agreement (“EULA”), or privacy settings; and
setting the data sharing permissions for the particular user further based on the at least one of the manifest, the EULA, or the privacy settings of each of the plurality of applications.
16. The data control method of claim 1, further comprising:
accessing for each of the plurality of applications at least one of a manifest, an end-user license agreement (“EULA”), or privacy settings; and
setting the data sharing permissions for the user further based on the at least one of the manifest, the EULA, or the privacy settings of each of the plurality of applications.
20. The method of claim 1, wherein the setting of the data sharing permissions for the particular user for each of the plurality of applications comprises:
setting rules indicating information to be shared; and
setting rules indicating targets of the information to be shared;
wherein the setting of the rules indicating the information to be shared and the setting of the rules indicating the targets of the information to be shared comprises establishing a multidimensional coordinate based on the information to be shared and the targets of the information to be shared.
9. The data control method of claim 1, wherein the setting of the data sharing permissions for the user for each of the plurality of applications comprises:
setting rules indicating information to be shared; and
setting rules indicating targets of the information to be shared;
wherein the setting of the rules indicating the information to be shared and the setting of the rules indicating the targets of the information to be shared comprises establishing a multidimensional coordinate based on the information to be shared and the targets of the information to be shared to be within the multidimensional zone.
21. The method of claim 1, wherein the setting of the data sharing permissions for the particular user for each of the plurality of applications comprises:
setting rules indicating information to be shared;
setting rules indicating targets of the information to be shared;
determining a first position vector based on the information to be shared; and
determining a second position vector based on the targets of the information to be shared;
wherein the setting of the rules indicating the information to be shared and the setting of the rules indicating the targets of the information to be shared comprises establishing a multidimensional coordinate based on the first position vector and the second position vector to be within the multidimensional zone.
10. The data control method of claim 1, wherein the setting of the data sharing permissions for the user for each of the plurality of applications comprises:
setting rules indicating information to be shared;
setting rules indicating targets of the information to be shared;
determining a first position vector based on the information to be shared; and
determining a second position vector based on the targets of the information to be shared;
wherein the setting of the rules indicating the information to be shared and the setting of the rules indicating the targets of the information to be shared comprises establishing a multidimensional coordinate based on the first position vector and the second position vector.
Claims 22 and 23 recite of features similar to that of claim 1. Therefore, claims 22 and 23 are rejected in a similar manner.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-14, and 17-23 are rejected under 35 U.S.C. 103 as being unpatentable over MURDOCH (US-20200351271-A1), in view of VESTERINEN (US-20100280965-A1), and further in view of SADEH (US-20190108353-A1), hereinafter MURDOCH-VESTERINEN-SADEH.
Regarding claim 1, MURDOCH teaches “A data control method comprising: receiving from a particular user an indication of data for sharing; ([MURDOCH, abstract] “Receiving a request from an entity for using data stored in a data storage that is associated with a DID as one or more inputs of an application associated with the entity to generate one or more results.”) ([MURDOCH, para. 0019] “A request for using data stored in a data storage that is associated with an owner of a DID is received. Specifically, the request for using the data is a request for using the data as one or more input(s) of an application”) ([MURDOCH, para. 0092] “process allows the identity hub 411 and the third party 401 to communicate and to share the data”) … receiving from the particular user an indication of at least one recipient with which to share the data; ([MURDOCH, para. 0152] “The method 900 includes generating a notification to the DID owner (e.g., Alice 640) in response to the receiving of the request (901). The method 900 may also include receiving a user indication (e.g., Alice 640's input) that indicates a scope of permission that is to be granted (902). The method 900 may then determine the scope of permission that is consistent with the user indication (e.g., Alice's input) (903). In some embodiments, the DID owner's input (e.g., Alice 640's input) may be entered when the request from the application (e.g., application 620) was received”) ([MURDOCH, abstract] “the scope of permission is granted to a container where the application is stored or is to be stored. The application is then executed in the container using the data”)
However, MURDOCH does not teach “determining a first multidimensional vector based on the indication of data for sharing; … determining a second multidimensional vector based on the indication of at least one recipient with which to share the data; determining a combined multidimensional vector based on the first multidimensional vector and the second multidimensional vector; determining a multidimensional zone based on the combined multidimensional vector; … accessing via a network a plurality of application program interfaces (APIs) for a plurality of applications; and setting data sharing permissions for the particular user for each of the plurality of applications based on the multidimensional zone via the plurality of APIs.”
In analogous teaching VESTERINEN teaches “… determining a first multidimensional vector based on the indication of data for sharing; ([VESTERINEN, para. 0050] “For example, contact icon 413 (Partner) and contact icon 415 (Close Friend) with contact radii 0.1 and 0.5, respectively (both less than 1.0), are in the innermost circle with information radius 1, representing access to the UserA's physical location. These contacts also have access to the information represented by the outer circles 403, 405 and 407. Similarly, contact 425 (Colleague C), with contact radius 1.5, lies outside the innermost circle 401 with information radius 1 and inside the second circle 403, with radius 2, which represents access to UserA's phone number. This contact is denied access to UserA's physical location in the circle with a smaller radius, but is granted access to UserA's phone number and information represented by the outer circles 405 and 407.”) … determining a second multidimensional vector based on the indication of at least one recipient with which to share the data; ([VESTERINEN, para. 0050] “For example, contact icon 413 (Partner) and contact icon 415 (Close Friend) with contact radii 0.1 and 0.5, respectively (both less than 1.0), are in the innermost circle with information radius 1, representing access to the UserA's physical location. These contacts also have access to the information represented by the outer circles 403, 405 and 407. Similarly, contact 425 (Colleague C), with contact radius 1.5, lies outside the innermost circle 401 with information radius 1 and inside the second circle 403, with radius 2, which represents access to UserA's phone number. This contact is denied access to UserA's physical location in the circle with a smaller radius, but is granted access to UserA's phone number and information represented by the outer circles 405 and 407.”) determining a combined multidimensional vector based on the first multidimensional vector and the second multidimensional vector; determining a multidimensional zone based on the combined multidimensional vector; ([VESTERINEN, para. 0048] “Circles are nested when the circle with the smaller radius lies entirely within a circle with a larger radius. In some embodiments, the nested circles are concentric. For example, in FIG. 4, the four radii 1, 2, 3 and 4 for the four pieces of user information in the example: (physical location, phone number, email address and service name, respectively), are shown by the four nested circles, circle 401, circle 403, circle 405 and circle 407, respectively”) ([VESTERINEN, para. 0028] “the numerical values used for information radius is on a different scale than the numerical values used for contact radius; and, a scale factor or transform algorithm is used to convert values in one scale to corresponding values in the other scale”).
Thus, given the teaching of VESTERINEN, it would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to combine the teaching of withholding data relating to a user by VESTERINEN into the teaching of a data control method as taught by MURDOCH. One of ordinary skill in the art would have been motivated to do so because VESTERINEN recognizes the need to improve sharing of private information ([VESTERINEN, para. 0002] “there is a need for a less tedious, more intuitive way to manage the private information shared among other subscribers than is currently available in social networks”).
Ina analogous teaching SADEH teaches “… accessing via a network a plurality of application program interfaces (APIs) for a plurality of applications; and ([SADEH, para. 0037] “decisions about granting access to sensitive functionality or data may be the responsibility of Policy Enforcement Points (PEPs) capable of enforcing user-specific permission settings configured by users and/or their Privacy Assistants via APIs that the Privacy Assistants can discover in IoT Resource Registries”) ([SADEH, para. 0040] “The user-specific settings are advertised along with APIs that can be used by Personalized Privacy Assistants to communicate directly with these IoT resources or with policy enforcement functionality associated with these IoT resources to configure these user-specific settings”) ([SADEH, para. 0083] “These descriptions of user-specific privacy settings associated with an IoT resource's entry in the registry can include a description of interfaces (or APIs) available for the personal privacy assistant to read and configure these settings”) ([SADEH, para. 0040] “help users configure user-specific privacy settings associated with different external IoT resources such as IoT apps, IoT devices or IoT services”) setting data sharing permissions for the particular user for each of the plurality of applications based on the multidimensional zone via the plurality of APIs. ([SADEH, para. 0082] “Privacy preference models can also be used to help the user configure any user-specific privacy settings exposed by a given resource … PPA is also able to query the resource's individual entry in the registry. Such entry typically includes a description … what data it collects, how long it retains data and in what form (e.g. anonymized or not), how the data is used, who it is shared with, and whether the resource offers any specific APIs that enable individual users (via their PPA) to configure any available user-specific settings (e.g. each user having access to opt-in, opt-out privacy settings pertaining to one or more data collection and/or use practices) … As the PPA helps its user configure user-specific privacy settings … it accesses user-specific privacy setting … These APIs typically support functionality to check the current configuration of a setting for a given user as well as functionality to modify configuration of that setting (e.g. accessing a camera system's API and finding that the user is currently opted into facial recognition for that particular camera system, and then accessing the camera system's API to configure that setting and requesting that the user be opted out instead).”).
Thus, given the teaching of SADEH, it would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to combine the teaching of accessing API of applications by SADEH into the teaching of a data control method as taught by MURDOCH-VESTERINEN. One of ordinary skill in the art would have been motivated to do so because SADEH recognizes the need to improve user privacy ([SADEH, para. 0005] “technologies can access sensitive data and functionality and the need for users to be able to control settings that determine which technology can access which element of functionality and which data under which conditions.”) ([SADEH, para. 0006] “The present invention revolves around, in one general aspect, personalized privacy assistant functionality that can help users configure privacy settings”).
Regarding claim 2, MURDOCH-VESTERINEN-SADEH teaches all limitations of claim 1. SADEH further teaches “the setting of the data sharing permissions comprising selecting predefined permissions via the plurality of APIs. ([SADEH, abstract] “The personal privacy assistant app receives the at least one model from the one or more servers of the data center; collects information about the user; identifies at least one recommended permission setting for the first app based on the at least one model and such that the recommended permission setting is user-specific; and configures the computing device to implement the received at least one user-specific recommended permission setting”) ([SADEH, para. 0040] “The user-specific settings are advertised along with APIs that can be used by Personalized Privacy Assistants to communicate directly with these IoT resources or with policy enforcement functionality associated with these IoT resources to configure these user-specific settings”) [Examiner’s note: examiner is interpreting recommended permissions as the predefined permissions.]
The same motivation to modify MURDOCH-VESTERINEN with SADEH as in the rejection of claim 1 applies.
Regarding claim 3, MURDOCH-VESTERINEN-SADEH teaches all limitations of claim 1. SADEH further teaches “further comprising: determining a modification by the particular user of the data sharing permissions for a particular one of the plurality of applications; ([SADEH, para. 0057] “situations where a user modifies a permission setting he or she had selected earlier.”) ([SADEH, para. 0082] “APIs typically support functionality to check the current configuration of a setting for a given user as well as functionality to modify configuration of that setting”) re-determining the multidimensional zone based on the modification of the data sharing permissions; and ([SADEH, para. 0042] “The PPA can also be responsible for further refining that user's individual privacy preference model based on additional information collected from the user such as the particular permission recommendations the user accepts, rejects or modifies as well as additional permissions the user configures over time and possibly answers to additional personalized questions asked over time to the user.”) re-setting the data sharing permissions for the particular user for at least one other of the plurality of applications based on the re-determined multidimensional zone via at least one of the plurality of APIs. ([SADEH, para. 0082] “accesses user-specific privacy setting APIs advertised in the IoT resource registries for the corresponding IoT resource. These APIs typically support functionality to check the current configuration of a setting for a given user as well as functionality to modify configuration of that setting (e.g. accessing a camera system's API and finding that the user is currently opted into facial recognition for that particular camera system, and then accessing the camera system's API to configure that setting and requesting that the user be opted out instead).”).
The same motivation to modify MURDOCH-VESTERINEN with SADEH as in the rejection of claim 1 applies.
Regarding claim 4, MURDOCH-VESTERINEN-SADEH teaches all limitations of claim 1. SADEH further teaches “the receiving from the particular user of the indication of the data for sharing comprising receiving at least one of an indication of photos for sharing or an indication of contacts for sharing. ([SADEH, para. 0024] “An example is a set of permissions that enable a mobile operating system to control access to sensitive functionality or data by apps running on a smartphone … access to contacts list information”) ([SADEH, para. 0053] “First, as shown in FIG. 8A, the user could be presented with a screen where permissions are organized by types of permissions (e.g., location, contacts, messages, etc.) with an identification of the number of apps that request each type of permission. The user could then select one type of permission … (apps requesting contacts), decide whether to accept or ignore different recommended settings, modify settings for which the PPA does not provide any recommendations”).
The same motivation to modify MURDOCH-VESTERINEN with SADEH as in the rejection of claim 1 applies.
Regarding claim 5, MURDOCH-VESTERINEN-SADEH teaches all limitations of claim 1. SADEH further teaches “the receiving from the particular user of the indication of the data for sharing comprising receiving an indication of location of a computing device of the particular user. ([SADEH, para. 0024] “An example is a set of permissions that enable a mobile operating system to control access to sensitive functionality or data by apps running on a smartphone (e.g., access to location tracking functionality … permissions may be used to capture and enforce user-specific settings associated with Internet of Things (IoT) devices or services such as opt-in or opt-out privacy settings associated with location tracking functionality”).
The same motivation to modify MURDOCH-VESTERINEN with SADEH as in the rejection of claim 1 applies.
Regarding claim 6, MURDOCH-VESTERINEN-SADEH teaches all limitations of claim 1. SADEH further teaches “the receiving from the particular user the indication of the at least one recipient with which to share the data comprising receiving an indication of at least one of a particular application with which to share the data or an indication of a network destination with which to share the data. ([SADEH, para. 0036] “The memory stores the code of one or more apps (software applications) 212 that the processor can execute to provide extended functionality to the computing device. Some, and indeed probably most, of the apps 212 request permissions to on-device functionality or data 140, 141 and/or external functionality or data 150, 151.”) ([SADEH, para. 0037] “the operating system 210 may determine, based on the device's permissions settings, whether the app should be granted access to the functionality/data or not. If access should be granted, the operating system 210 can provide access to the functionality/data”).
The same motivation to modify MURDOCH-VESTERINEN with SADEH as in the rejection of claim 1 applies.
Regarding claim 7, MURDOCH-VESTERINEN-SADEH teaches all limitations of claim 1. VESTERINEN further teaches “the receiving from the particular user of the indication of the data for sharing comprising receiving an indication of data not for sharing, the data not for sharing comprising at least one of a name of the particular user, an address of the particular user, a telephone number of the particular user, an email address of the particular user, photos, or an identification number of the particular user. ([VESTERINEN, para. 0043] “According to the default values in Table 1, no contact is given access to the user's physical location (e.g., home address or current GPS position) or given access to the user's phone number. The default values allow contacts in a friends group to access the user's email and service name”).
The same motivation to modify MURDOCH with VESTERINEN as in the rejection of claim 1 applies.
Regarding claim 8, MURDOCH-VESTERINEN-SADEH teaches all limitations of claim 1. SADEH further teaches “the receiving from the particular user an indication of at least one recipient with which to share the data comprising receiving from the particular user an indication to share the data via the network. ([SADEH, para. 0009] “The personal privacy assistant running on the user's computing device receives from the first IoT resource registry data about the one or more IoT resources … The personal privacy assistant may communicate directly with the one or more IoT resources or with policy enforcement points associated with one or more IoT resources to configure the user-specific privacy settings for these one or more IoT resources.”) ([SADEH, para. 0032] “shown in FIG. 2, a data center 106 is in communication with a computing device 114 via a communications network 112 (e.g., the Internet). The computing device 114 may run or execute the personalized privacy assistant (PPA) as shown in FIG. 1”).
The same motivation to modify MURDOCH-VESTERINEN with SADEH as in the rejection of claim 1 applies.
Regarding claim 9, MURDOCH-VESTERINEN-SADEH teaches all limitations of claim 1. SADEH further teaches “wherein the setting of the data sharing permissions for the particular user for each of the plurality of applications comprises: setting rules indicating information to be shared; and ([SADEH, para. 0082] “Privacy preference models can also be used to help the user configure any user-specific privacy settings exposed by a given resource (e.g. automatically opting out of some practices on behalf of the user, or recommending to the user that they opt in or opt out of various data collection and/or use practices).”) setting rules indicating targets of the information to be shared; ([SADEH, para. 0040] “help users configure user-specific privacy settings associated with different external IoT resources such as IoT apps, IoT devices or IoT services.”).
The same motivation to modify MURDOCH-VESTERINEN with SADEH as in the rejection of claim 1 applies.
VESTERINEN further teaches “wherein the setting of the rules indicating the information to be shared and the setting of the rules indicating the targets of the information to be shared comprises establishing a multidimensional coordinate based on the information to be shared and the targets of the information to be shared to be within the multidimensional zone. ([VESTERINEN, para. 0050] “For example, contact icon 413 (Partner) and contact icon 415 (Close Friend) with contact radii 0.1 and 0.5, respectively (both less than 1.0), are in the innermost circle with information radius 1, representing access to the UserA's physical location. These contacts also have access to the information represented by the outer circles 403, 405 and 407. Similarly, contact 425 (Colleague C), with contact radius 1.5, lies outside the innermost circle 401 with information radius 1 and inside the second circle 403, with radius 2, which represents access to UserA's phone number. This contact is denied access to UserA's physical location in the circle with a smaller radius, but is granted access to UserA's phone number and information represented by the outer circles 405 and 407.”).
The same motivation to modify MURDOCH with VESTERINEN as in the rejection of claim 1 applies.
Regarding claim 10, MURDOCH-VESTERINEN-SADEH teaches all limitations of claim 1. SADEH further teaches “wherein the setting of the data sharing permissions for the particular user for each of the plurality of applications comprises: setting rules indicating information to be shared; ([SADEH, para. 0082] “Privacy preference models can also be used to help the user configure any user-specific privacy settings exposed by a given resource (e.g. automatically opting out of some practices on behalf of the user, or recommending to the user that they opt in or opt out of various data collection and/or use practices).”) setting rules indicating targets of the information to be shared; ([SADEH, para. 0040] “help users configure user-specific privacy settings associated with different external IoT resources such as IoT apps, IoT devices or IoT services.”).
The same motivation to modify MURDOCH-VESTERINEN with SADEH as in the rejection of claim 1 applies.
VESTERINEN further teaches “determining a first position vector based on the information to be shared; and determining a second position vector based on the targets of the information to be shared; wherein the setting of the rules indicating the information to be shared and the setting of the rules indicating the targets of the information to be shared comprises establishing a multidimensional coordinate based on the first position vector and the second position vector. ([VESTERINEN, para. 0050] “For example, contact icon 413 (Partner) and contact icon 415 (Close Friend) with contact radii 0.1 and 0.5, respectively (both less than 1.0), are in the innermost circle with information radius 1, representing access to the UserA's physical location. These contacts also have access to the information represented by the outer circles 403, 405 and 407. Similarly, contact 425 (Colleague C), with contact radius 1.5, lies outside the innermost circle 401 with information radius 1 and inside the second circle 403, with radius 2, which represents access to UserA's phone number. This contact is denied access to UserA's physical location in the circle with a smaller radius, but is granted access to UserA's phone number and information represented by the outer circles 405 and 407.”).
The same motivation to modify MURDOCH with VESTERINEN as in the rejection of claim 1 applies.
Regarding claim 11, MURDOCH-VESTERINEN-SADEH teaches all limitations of claim 1. MURDOCH further teaches “further comprising: receiving from the particular user at least one allowed action for the data; and ([MURDOCH, para. 0113] “the application 620″ may be an insurance quoting application for the entity 610. Many existing or potential customers of the entity 610 may have allowed the application 620″ to use their driving history data (e.g., Alice's driving history data 661) to generate one or more insurance quotes. After the quotes are generated, the quotes may be stored together with the application 620″.”).
VESTERINEN further teaches “… determining the multidimensional zone further based on the at least one allowed action for the data, the determining the multidimensional zone comprising determining the combined multidimensional vector based on the indication of the data for sharing, the indication of the at least one recipient, and the at least one allowed action for the data. ([VESTERINEN, para. 0032] “In some embodiments, information radii and contact radii for a user of mobile terminal 120 are derived based, at least in part, on user activity on the mobile terminal 120. As used herein, activity on the mobile terminal includes one or more network communications with each of one or more contacts, or proximity of mobile terminal 120 to the address or mobile location of each of one or more contacts, or some combination. In such embodiments, the mobile terminal 120 includes a mobile terminal activity tracker module 121 that detects those communications and proximity events and reports those activities, or statistical data or radii derived from them, to the network privacy service module 133 over network 105”) ([VESTERINEN, para. 0050] “For example, contact icon 413 (Partner) and contact icon 415 (Close Friend) with contact radii 0.1 and 0.5, respectively (both less than 1.0), are in the innermost circle with information radius 1, representing access to the UserA's physical location. These contacts also have access to the information represented by the outer circles 403, 405 and 407. Similarly, contact 425 (Colleague C), with contact radius 1.5, lies outside the innermost circle 401 with information radius 1 and inside the second circle 403, with radius 2, which represents access to UserA's phone number. This contact is denied access to UserA's physical location in the circle with a smaller radius, but is granted access to UserA's phone number and information represented by the outer circles 405 and 407.”).
The same motivation to modify MURDOCH with VESTERINEN as in the rejection of claim 1 applies.
Regarding claim 12, MURDOCH-VESTERINEN-SADEH teaches all limitations of claim 11. SADEH further teaches “the receiving from the particular user the at least one allowed action for the data comprising receiving an indication that the data can be shared by the at least one recipient with other recipients. ([SADEH, para. 0030] “some sensitive functionality or data has been accessed, the particular apps responsible for such access, the purpose for accessing this sensitive functionality or data, including who the data might be shared with, what information might be inferred from the sensitive data”) ([SADEH, para. 0040] “describing the IoT resource's data collection and use practices (e.g., what data is being collected, how long it is retained, whether it is aggregated or anonymized, for what purpose it is collected, which third parties it might be shared with”) ([SADEH, para. 0044] “generally comfortable granting access to his fine location gaming apps category for the purpose of the apps being able to operate, for the apps to share the resulting information with advertising networks that may in turn use this information to better target the user”).
The same motivation to modify MURDOCH-VESTERINEN with SADEH as in the rejection of claim 1 applies.
Regarding claim 13, MURDOCH-VESTERINEN-SADEH teaches all limitations of claim 11. SADEH further teaches “the receiving from the particular user the at least one allowed action for the data comprising receiving an indication that the data can be used by the at least one recipient in building at least one of an application or a service. ([SADEH, para. 0073] “When privacy preference models are extended to include notification preferences and models of people's expectations (e.g. whether a user expects facial recognition to be used in conjunction with footage captured by a camera monitoring system”) ([SADEH, para. 0040] “(e.g., discovering in an IoT Registry an entry corresponding to a camera monitoring system in a building with a description of user-specific opt-in setting that authorizes the system to apply facial recognition and scene recognition functionality to the video streams it captures).”).
The same motivation to modify MURDOCH-VESTERINEN with SADEH as in the rejection of claim 1 applies.
Regarding claim 14, MURDOCH-VESTERINEN-SADEH teaches all limitations of claim 11. SADEH further teaches “the receiving from the particular user the at least one allowed action for the data comprising receiving an indication that the data can be used to enable transmission of at least one of advertisements, offers, or coupons to the particular user. ([SADEH, para. 0044] “generally comfortable granting access to his fine location gaming apps category for the purpose of the apps being able to operate, for the apps to share the resulting information with advertising networks that may in turn use this information to better target the user”).
The same motivation to modify MURDOCH-VESTERINEN with SADEH as in the rejection of claim 1 applies.
Regarding claim 17, MURDOCH-VESTERINEN-SADEH teaches all limitations of claim 1. VESTERINEN further teaches “wherein: determining the first multidimensional vector comprises determining a first value on a first axis based on the indication of data for sharing; and determining the second multidimensional vector comprises determining a second value on a second axis based on the indication of at least one recipient with which to share the data. ([VESTERINEN, para. 0050] “For example, contact icon 413 (Partner) and contact icon 415 (Close Friend) with contact radii 0.1 and 0.5, respectively (both less than 1.0), are in the innermost circle with information radius 1, representing access to the UserA's physical location. These contacts also have access to the information represented by the outer circles 403, 405 and 407. Similarly, contact 425 (Colleague C), with contact radius 1.5, lies outside the innermost circle 401 with information radius 1 and inside the second circle 403, with radius 2, which represents access to UserA's phone number. This contact is denied access to UserA's physical location in the circle with a smaller radius, but is granted access to UserA's phone number and information represented by the outer circles 405 and 407.”) ([VESTERINEN, para. 0048] “Circles are nested when the circle with the smaller radius lies entirely within a circle with a larger radius. In some embodiments, the nested circles are concentric. For example, in FIG. 4, the four radii 1, 2, 3 and 4 for the four pieces of user information in the example: (physical location, phone number, email address and service name, respectively), are shown by the four nested circles, circle 401, circle 403, circle 405 and circle 407, respectively”) ([VESTERINEN, para. 0028] “the numerical values used for information radius is on a different scale than the numerical values used for contact radius; and, a scale factor or transform algorithm is used to convert values in one scale to corresponding values in the other scale”).
The same motivation to modify MURDOCH with VESTERINEN as in the rejection of claim 1 applies.
Regarding claim 18, MURDOCH-VESTERINEN-SADEH teaches all limitations of claim 1. VESTERINEN further teaches “further comprising: receiving identifying information of the particular user; ([VESTERINEN, para. 0005] “The information radius is related to how private the information about the user is. The apparatus includes a means for providing information about the user, in response to a request from the contact for information about the user. The provided information has an information radius value in a range that is based on a value of the contact radius associated with the contact.”) receiving identifying information of a plurality of other users; ([VESTERINEN, para. 0003] “The contact radius is related to how socially close a contact is to a user who is registered with a network service. “) comparing the identifying information of the particular user and the identifying information of the plurality of other users; ([VESTERINEN, para. 0004] “In response to a request from the contact for information about the user, the processor and memory are also configured to provide information about the user, which has an information radius value in a range that is based on a value of the contact radius associated with the contact.”) receiving from the other users a plurality of indications of information for sharing; ([VESTERINEN, para. 0029] “A contact is provided with user information which has an information radius value in a range that is based on a value of a contact radius associated with the contact. For example, in some embodiments, a contact has access to all user information with an information radius greater than or equal to the contact's contact radius, but not to any information with an information radius less than the contact's contact radius.”) receiving from the other users a plurality of indications of recipients with which to share the information; and (VESTERINEN, para. 0049] “Thus, the user can readily and intuitively determine what information is granted to which contacts. In embodiments with concentric circles, each icon is simply plotted at a distance equal to that icon's corresponding contact radius from the shared center of the circles. “) determining the multidimensional zone further based on the plurality of indications of information for sharing, the plurality of indications of recipients with which to share the information, and the comparing of the identifying information of the particular user and the identifying information of the plurality of other users. (VESTERINEN, para. 0048] “FIG. 4, the four radii 1, 2, 3 and 4 for the four pieces of user information in the example: (physical location, phone number, email address and service name, respectively), are shown by the four nested circles, circle 401, circle 403, circle 405 and circle 407, respectively. In some embodiments, the information associated with each circle is indicated by a label giving the name of the parameter shared in that circle, e.g., label 431, label 433, label 435 and label 437 for circle 401, circle 403, circle 405, and circle 407, respectively.”)
The same motivation to modify MURDOCH with VESTERINEN as in the rejection of claim 1 applies.
Regarding claim 19, MURDOCH-VESTERINEN-SADEH teaches all limitations of claim 1. MURDOCH further teaches “further comprising: accessing for each of the plurality of applications at least one of a manifest, an end-user license agreement (“EULA”), or privacy settings; and ([MURDOCH, para. 0139] “The method 700 also includes identifying one or more characteristics of the application (702). The one or more characteristics may be the characteristics 625-626 illustrated in FIG. 6. The one or more characteristics 621 of the application 620 may include (but not limited to) the identity of the entity 610, the nature of the application 620, what type of information is requested by the application 620, and what type of results will be generated by the application 620”).
SADEH further teaches “… setting the data sharing permissions for the particular user further based on the at least one of the manifest, the EULA, or the privacy settings of each of the plurality of applications. ([SADEH, para. 0009] “The data about the one or more IoT resources received by the personal privacy assistant may comprise privacy opt-in or privacy opt-out settings (or other privacy settings) available for the one or more IoT resources. The personal privacy assistant may communicate directly with the one or more IoT resources or with policy enforcement points associated with one or more IoT resources to configure the user-specific privacy settings for these one or more IoT resources”).
The same motivation to modify MURDOCH-VESTERINEN with SADEH as in the rejection of claim 1 applies.
Regarding claim 20, MURDOCH-VESTERINEN-SADEH teaches all limitations of claim 1. SADEH further teaches “wherein the setting of the data sharing permissions for the particular user for each of the plurality of applications comprises: setting rules indicating information to be shared; and ([SADEH, para. 0082] “Privacy preference models can also be used to help the user configure any user-specific privacy settings exposed by a given resource (e.g. automatically opting out of some practices on behalf of the user, or recommending to the user that they opt in or opt out of various data collection and/or use practices).”) setting rules indicating targets of the information to be shared; ([SADEH, para. 0040] “help users configure user-specific privacy settings associated with different external IoT resources such as IoT apps, IoT devices or IoT services.”).
The same motivation to modify MURDOCH-VESTERINEN with SADEH as in the rejection of claim 1 applies.
VESTERINEN further teaches “… wherein the setting of the rules indicating the information to be shared and the setting of the rules indicating the targets of the information to be shared comprises establishing a multidimensional coordinate based on the information to be shared and the targets of the information to be shared. ([VESTERINEN, para. 0050] “For example, contact icon 413 (Partner) and contact icon 415 (Close Friend) with contact radii 0.1 and 0.5, respectively (both less than 1.0), are in the innermost circle with information radius 1, representing access to the UserA's physical location. These contacts also have access to the information represented by the outer circles 403, 405 and 407. Similarly, contact 425 (Colleague C), with contact radius 1.5, lies outside the innermost circle 401 with information radius 1 and inside the second circle 403, with radius 2, which represents access to UserA's phone number. This contact is denied access to UserA's physical location in the circle with a smaller radius, but is granted access to UserA's phone number and information represented by the outer circles 405 and 407.”).
The same motivation to modify MURDOCH with VESTERINEN as in the rejection of claim 1 applies.
Regarding claim 21, MURDOCH-VESTERINEN-SADEH teaches all limitations of claim 1. SADEH further teaches “wherein the setting of the data sharing permissions for the particular user for each of the plurality of applications comprises: setting rules indicating information to be shared; ([SADEH, para. 0082] “Privacy preference models can also be used to help the user configure any user-specific privacy settings exposed by a given resource (e.g. automatically opting out of some practices on behalf of the user, or recommending to the user that they opt in or opt out of various data collection and/or use practices).”) setting rules indicating targets of the information to be shared; ([SADEH, para. 0040] “help users configure user-specific privacy settings associated with different external IoT resources such as IoT apps, IoT devices or IoT services.”).
The same motivation to modify MURDOCH-VESTERINEN with SADEH as in the rejection of claim 1 applies.
VESTERINEN further teaches “… determining a first position vector based on the information to be shared; and determining a second position vector based on the targets of the information to be shared; wherein the setting of the rules indicating the information to be shared and the setting of the rules indicating the targets of the information to be shared comprises establishing a multidimensional coordinate based on the first position vector and the second position vector to be within the multidimensional zone. ([VESTERINEN, para. 0050] “For example, contact icon 413 (Partner) and contact icon 415 (Close Friend) with contact radii 0.1 and 0.5, respectively (both less than 1.0), are in the innermost circle with information radius 1, representing access to the UserA's physical location. These contacts also have access to the information represented by the outer circles 403, 405 and 407. Similarly, contact 425 (Colleague C), with contact radius 1.5, lies outside the innermost circle 401 with information radius 1 and inside the second circle 403, with radius 2, which represents access to UserA's phone number. This contact is denied access to UserA's physical location in the circle with a smaller radius, but is granted access to UserA's phone number and information represented by the outer circles 405 and 407.”).
The same motivation to modify MURDOCH with VESTERINEN as in the rejection of claim 1 applies.
Regarding claim 22, this claim recites a data control method that performs similar steps of method claim 1. Therefore, claim 22 is rejected in a similar manner as in the rejection of claim 1. MURDOCH further teaches “… receiving from the user at least one allowed action for the data; …” ([MURDOCH, para. 0113] “For instance, the application 620″ may be an insurance quoting application for the entity 610. Many existing or potential customers of the entity 610 may have allowed the application 620″ to use their driving history data (e.g., Alice's driving history data 661) to generate one or more insurance quotes. After the quotes are generated, the quotes may be stored together with the application 620″.”).
Regarding claim 23, this claim recites a data control method that performs similar steps of method claim 1. Therefore, claim 23 is rejected in a similar manner as in the rejection of claim 1. SADEH further teaches of “… accessing via a network a plurality of application program interfaces (APIs) for a plurality of websites comprising a plurality of webpages; and setting data sharing permissions for the particular user for each of the plurality of websites …” ([SADEH, para. 0082] “the PPA is also able to query the resource's individual entry in the registry. Such entry typically includes a description of the resource such as who its owner is, what data it collects, how long it retains data and in what form (e.g. anonymized or not), how the data is used, who it is shared with, and whether the resource offers any specific APIs that enable individual users (via their PPA) to configure any available user-specific settings (e.g. each user having access to opt-in, opt-out privacy settings pertaining to one or more data collection and/or use practices)”) ([SADEH, para. 0024] “permissions control privacy and/or security settings associated with a browser or control which sensitive functionality or data websites can access.”) ([SADEH, para. 0005] “examples include security and privacy settings found in browsers, privacy settings associated with social network sites and applications”) ([SADEH, para. 0023] “personalized privacy assistant (PPA) that helps a user configure permission settings associated with technologies with which the user interacts. … these permission settings are associated with services with which the user interacts such as cloud-based services (e.g., social networking site)”).
The same motivation to modify MURDOCH-VESTERINEN with SADEH as in the rejection of claim 1 applies.
Claims 15 and 16 are rejected under 35 U.S.C. 103 as being unpatentable over MURDOCH- VESTERINEN-SADEH in view of RANGACHARI (US-20120323741-A1).
Regarding claim 15, MURDOCH-VESTERINEN-SADEH teaches all limitations of claim 11. However, MURDOCH-VESTERINEN-SADEH does not teach “the receiving from the particular user the at least one allowed action for the data comprising receiving an indication that the data can be sold.”
In analogous teaching RANGACHARI teaches “the receiving from the particular user the at least one allowed action for the data comprising receiving an indication that the data can be sold.” ([RANGACHARI, para. 0032] “At 310, the seller is enabled to start publishing the data offered. At 312, the seller is enabled to approve subscription requests. The seller's data becomes available in SDM. When a subscription request is received from a buyer, the data can be exported to the buyer with the seller's approval.”).
Thus, given the teaching of RANGACHARI, it would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to combine the teaching of selling data by RANGACHARI into the teaching of a data control method as taught by MURDOCH-VESTERINEN-SADEH. One of ordinary skill in the art would have been motivated to do so because RANGACHARI recognizes the benefits of a data marketplace ([RANGACHARI, para. 0002] “In many entities still, in-house IT applications are poorly integrated, for example, with disparate applications running on their own, even when there are commonalities in the data those applications use. In such cases, data updated by one application is usually imported to another application manually.”) ([RANGACHARI, para. 0006] “A method and system for open data marketplace may be provided. The method, in one aspect, may include identifying one or more data attributes from a plurality of applications registered with a shared data management system”).
Regarding claim 16, MURDOCH-VESTERINEN-SADEH teaches all limitations of claim 11. However, MURDOCH-VESTERINEN-SADEH does not teach “the receiving from the particular user the at least one allowed action for the data comprising receiving an indication that the data can be sold by the at least one recipient”
In analogous teaching RANGACHARI teaches “the receiving from the particular user the at least one allowed action for the data comprising receiving an indication that the data can be sold by the at least one recipient.” ([RANGACHARI, para. 0032] “At 310, the seller is enabled to start publishing the data offered. At 312, the seller is enabled to approve subscription requests. The seller's data becomes available in SDM. When a subscription request is received from a buyer, the data can be exported to the buyer with the seller's approval.”).
The same motivation to modify MURDOCH-VESTERINEN-SADEH with RANGACHARI as in the rejection of claim 15 applies.
Pertinent Art
The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure.
KANG (US-9232396-B2): This prior art teaches of an apparatus and method that enable data sharing to be performed between short-range/middle-range/long-range mobile terminals by minimizing specific intervention of a user. The apparatus includes a social relationship management unit for managing social network group information formed by a user while the user utilizes a social network service. A device recognition and authentication unit identifies a mobile terminal of another party attempting to make a connection and allocates a data communication channel for data exchange, based on device information received from the mobile terminal of the other party attempting to make a connection and the social network group information. A shared data setting unit sets data to be shared with the mobile terminal of the other party between which the data communication channel has been established. A shared data transmission unit transmits the data to be shared to the mobile terminal of the other party.
MACHANI (US-8782424-B2): This prior art teaches of system and method for sharing data is provided. A request is received from a mobile device to transfer a set of data to a recipient. The set of data is stored by a server and controlled by a user of the mobile device. The request is authenticated, and the data is encrypted. The set of data is transmitted to a recipient specified by the user via the mobile device.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to AFAQ ALI whose telephone number is (571)272-1571. The examiner can normally be reached Mon - Fri 7:30am - 5:30pm EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, ALI SHAYANFAR can be reached at (571) 270-1050. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/A.A./
09/15/2026
/AFAQ ALI/Examiner, Art Unit 2434
/NOURA ZOUBAIR/Primary Examiner, Art Unit 2434