DETAILED ACTION
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This office action is in response to the application filed on 05/01/2025.
Claims 1-20 are currently pending in this application.
Information Disclosure Statement
The information disclosure statement (IDS) submitted by applicant dated 05/01/2025 and 12/02/2025 have been considered by the examiner.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claims 1-2, 4, 6, 10-11, 13, 15, and 19 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Sinha et al. US 20230060068 hereinafter referred to as Sinha.
As per claim 1, Sinha discloses a method for enforcing data access to run one or more applications in a cloud computing system, the method comprising (Sinha [FIG. 1], [FIG. 10], [0007], [0047], [0151]: "sharing a consent token associated with a user consent among applications installed or accessible on a user device of a user… one or more application service providers, arranged in a cluster of servers or as a server farm, may host the first application 110… the server system 1000 is embodied as a cloud-based and/or SaaS-based (software as a service) architecture"):
receiving, by one or more processors, a request by an application to access a piece of data in a storage system for use by the application (Sinha [0139-0140]: "storing, by a server system 102, a consent token associated with the user in a database 116… consent token includes the credential data associated with the user 102… receiving, by the server system 102, a request to access the consent token associated with the user 106 from a second application service provider 112 associated with a second application 114");
parsing, by the one or more processors, a token in the storage system associated with the piece of data that indicates which applications a user consented to accessing the piece of data (Sinha [0101], [0104], [0141]: "access rules data associated with the consent token… server system 204 stores the consent token and the access rules data in the consent database 220… second application 110 is able to access the consent token associated with the first application based, at least in part, on access rules data set by the user 106");
determining, by the one or more processors, whether the application has consent to access the piece of data based on the token (Sinha [0141]: "determining, by the server system 102, whether the second application 110 is able to access the consent token associated with the first application based, at least in part, on access rules data set by the user 106 and the first application service provider 108 of the first application 110 for accessing the consent token");
granting or denying, by the one or more processors, access to the piece of data based on the determination (Sinha [0142]: "allowing, by the server system 102, access of the consent token to the second application 114 based, at least in part, on the determining step");
and outputting, by the one or more processors, the grant or denial to access the piece of data (Sinha [0089]: "server system 102 provides the stored consent token to the second application service provider 112 if the second application service provider 112 meets the criteria for the access level permission set by the first application service provider 108").
As per claim 2, Sinha discloses the method of claim 1, wherein the request is a read request or a write request for the piece of data (Sinha [0140]: access request constitutes a read request, see e.g., "a request to access the consent token associated with the user 106 from a second application service provider 112").
As per claim 4, Sinha discloses method of claim 1, wherein the token further comprises which users consented to accessing the piece of data (Sinha [0071], [0080]: "The consent token includes user's enrollment ID, user preferences, first application service provider ID, timestamp provided by the first application service provider 108, and the user consent message").
As per claim 6, Sinha discloses the method of claim 1, further comprising outputting, by the one or more processors, a notification to request access to the piece of data as part of outputting the denial to access the piece of data (Sinha [FIG. 5A], [0111-0113]: "if the second merchant 202b does not have the access permission of the consent token associated with the first merchant 202a, at 512, the server system 204 sends a notification to request the second merchant 202b to initiate consent enrolment process for the user").
As per claims 10-11, 13, and 15, the claims disclose a system corresponding to the method claims 1-2, 4, and 6 above, and they are rejected, at least for the same reasons.
As per claim 19, the claim discloses a non-transitory computer readable medium corresponding to the method claim 1 above, and they are rejected, at least for the same reasons.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 3 and 12 are rejected under 35 U.S.C. 103 as being unpatentable over Sinha et al. US 20230060068 hereinafter referred to as Sinha in view of Fakhraie et al. US 12174992 hereinafter referred to as Fakhraie.
As per claim 3, Sinha teaches the method of claim 1 and application (Sinha [0141]: second application).
Sinha does not explicitly disclose wherein the application comprises at least one of a video streaming application, a map generation application, a search application, or a digital content management application.
Fakhraie teaches wherein the application comprises at least one of a video streaming application, a map generation application, a search application, or a digital content management application (Fakhraie [Col. 11, lines 55-66], [Col. 15, lines 51-60], [Col. 16, lines 12-13]: reads on digital content management application and is a requesting application, see e.g., “third-party systems 106 may be affiliated… cloud storage systems (e.g., document back-up systems, such as Google® Drive, Dropbox®, etc.)… the third party client application 206 may make a request to the financial institution client application 208, which obtains the requested information from the financial institution computing system 110… financial institution computing system 110 (and/or the financial institution client application 208) may allow or deny the third party client application 206 access to the requested information").
Thus it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention of Sinha of consent token associated with user consent among applications with the teachings of Fakhraie to include the application comprising a digital content management application in order to do a simple substitution of one known requesting application type for another yielding the predictable result of enforcing the user’s access decision for that application type.
As per claim 12, the claim discloses a system corresponding to the method claim 3 above, and they are rejected, at least for the same reasons.
Claims 5 and 14 are rejected under 35 U.S.C. 103 as being unpatentable over Sinha et al. US 20230060068 hereinafter referred to as Sinha in view of Cotner et al. US 9514328 hereinafter referred to as Cotner.
As per claim 5, Sinha teaches the method of claim 1 and the token (Sinha [0104]: “server system 204 stores the consent token and the access rules data in the consent database 220”).
Sinha does not explicitly disclose wherein the token is included as a column in table data.
Cotner teaches column-level implementation of the access control system (Cotner [Col. 9, lines 34-42]: “the administrator includes a SECURITY_LABEL column in the table… row-level security mechanism is driven by the presence of the SECURITY_LABEL column and the content of the data row”).
Thus it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention of Sinha of database token storage with the teachings of Cotner to include column-level enforcement in order to prevent unauthorized access to sensitive data by providing a targeted, column-level access control mechanism.
As per claim 14, the claim discloses a system corresponding to the method claim 5 above, and they are rejected, at least for the same reasons.
Claims 7, 16, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Sinha et al. US 20230060068 hereinafter referred to as Sinha in view of Price et al. US 20130246470 hereinafter referred to as Price.
As per claim 7, Sinha teaches the method of claim 1, further comprising, by the one or more processors, the token and which applications a user consented to access the piece of data (Sinha [0104], [0140-0141]: consent token and access rules).
Sinha does not explicitly disclose periodically updating the token to update which applications a user consented to access the piece of data.
Price teaches periodically updating ACL permissions (Price [0031]: periodically updating the access-permission record of which entities are permitted, see e.g., "The ACL permissions may also be proactively pruned, for example by routinely or periodically… thereby identifying and invalidating ACL permissions at 106 when the dtime data indicates that the user ACL permissions no longer meet the duration rule").
Thus it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention of Sinha of the consent token and access rules with the teachings of Price to include periodically updating ACL permissions in order to prevent unauthorized data access and improve security when certain access no longer meets current authorization requirements.
As per claim 16, the claim discloses a system corresponding to the method claim 7 above, and they are rejected, at least for the same reasons.
As per claim 20, the claim discloses a non-transitory computer readable medium corresponding to the method claim 7 above, and they are rejected, at least for the same reasons.
Claims 8-9 and 17-18 are rejected under 35 U.S.C. 103 as being unpatentable over Sinha et al. US 20230060068 hereinafter referred to as Sinha in view of Welton et al. US 10963426 hereinafter referred to as Welton.
As per claim 8, Sinha teaches the method of claim 1.
Sinha does not explicitly disclose, wherein the storage system is a hierarchy of databases and the parsing, determining, and granting or denying are performed by one of the databases of the hierarchy.
Welton teaches wherein the storage system is a hierarchy of databases and the parsing, determining, and granting or denying are performed by one of the databases of the hierarchy (Welton [FIG. 5], [FIG. 7], [Col. 5, lines 27-29], [Col. 7, lines 8-15], [Clm. 1]: Worker nodes 504, 505, 506, 508, and 510 may be configured in a tree structure, and master node 502 may be a root node… Storing database metadata on a master node may allow permissions, such as user or group permissions, to be checked at a central location… Once the objects are validated against the permissions, the plans and accompanying metadata may be pushed to the worker nodes… validating, at the master node, at least one of the permissions against at least one of the database objects… worker node stores unstructured data”).
Thus it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention of Sinha of a single consent database server with the teachings of Welton to include hierarchical database and tree-structured metadata in order to reduce redundancies and improve scalability and security by establishing a central location for validating permissions.
As per claim 9, Sinha in view of Welton teach the method of claim 8, wherein the other databases of the hierarchy honor the grant or denial without performing their own determination (Welton [Col. 7, lines 5-15]: worker nodes execute the already-validated query plan handed down by the master node, see e.g., “Once the objects are validated against the permissions, the plans and accompanying metadata may be pushed to the worker nodes… Validating permissions on the master node may be particularly beneficial if the data in the database is unstructured and/or stored on a distributed file system. The permissions may be applied on a master node to database objects defined by the metadata, and the data itself may reside on individual worker nodes in the cluster. This may allow the permissions to be validated against structured metadata prior to distributing the query plans to the workers… executing the query plan on the worker node, wherein the worker node stores unstructured data”).
As per claims 17-18, the claims disclose a system corresponding to the method claims 7-8 above, and they are rejected, at least for the same reasons.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to CAROLINE HOANG-ANH NGUYEN whose telephone number is (571)272-8309. The examiner can normally be reached Monday-Thursday 7am-5pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Farid Homayounmehr can be reached at (571) 272-3739. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/C.H.N./Examiner, Art Unit 2495
/HENRY TSANG/Primary Examiner, Art Unit 2495