DETAILED ACTION
This action is in response to the application filed on March 28, 2023. Claims 1-20 are pending. Of such, claims 1-5 represent a system, claims 6, 11-14 represent an apparatus, claims 7-9 and 15-16 represent a method and claims 10 and 17-20 represent a non-transient computer readable medium directed to a secure computation system using most significant bit extraction.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Specification
Applicant is reminded of the proper language and format for an abstract of the disclosure.
The language should be clear and concise and should not repeat information given in the title. It should avoid using phrases which can be implied, such as, “The disclosure concerns,” “The disclosure defined by this invention,” “The disclosure describes,” etc. In addition, the form and legal phraseology often used in patent claims, such as “means” and “said,” should be avoided.
The disclosure is objected to because of the following informalities:
¶ 51 discloses “the anomaly 122” should be corrected to “the anomaly measures 122” to match the drawing label of figure 1.
¶ 59 discloses “each iteration may generates a distinct set….can vary across iterations” should be corrected to “may generate”.
¶ 59 discloses “the anomaly detection module 120 maybe assumed” should be corrected to “may be”.
¶ 64 discloses “may further configured” should be corrected to “may be further configured”.
¶ 73 discloses “may then performed” should be corrected to “may then be performed”.
¶ 73 discloses “may thus performed” should be corrected to “may then be performed”.
¶ 85 discloses “may then executes the iterative anomaly analysis method” should be corrected to “may then execute”.
¶ 97 discloses “cloud-based severs” should be corrected to “servers”.
Appropriate correction is required.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-20 are rejected under 35 U.S.C. 101 because the identified claim limitation(s) that recite(s) an abstract idea without significantly more.
Claim 1 recites repeatedly processing the entitlement assignments using an anomaly detection module to determine anomaly measures, determining combined anomaly measures from those measurements, and determining an entitlement recommendation from the combined measurements. These limitations recite mathematical calculations where no formula is expressed. The recited “anomaly measure” is a computed score and combining those measures is performed by summing, averaging, or counting as disclosed in ¶ 11 of the applicant’s specification.
The claim recites the following additional elements: a computing device, a data repository from which the entitlement assignments are received, and an anomaly detection module. The receiving from the data repository is mere data gathering necessary to perform the recited analysis. Other than reciting “the computing device” and “anomaly detection module” nothing in the claim element precludes the step of performing the mathematical calculations using generic computational methods such as using pen, paper, calculators and other generic computer products. The “anomaly detection module” as described by the applicant’s specification, describes it as software instructions executed by a generic processor.
If a claim limitation, under its broadest reasonable interpretation, covers mathematical concepts but for the recitation of generic computer components, then it falls within the “Mathematical Concepts” grouping of abstract ideas. Accordingly, the claim recites an abstract idea.
This judicial exception is not integrated into a practical application. Receiving the entitlement assignments from a data repository is mere data gathering. The method is recited at a high-level of generality such that it amounts no more than mere instructions to apply the exception using a generic computer component. Further, claim 1 recites no additional element that applies or uses the recited determination for any purpose. The claim is directed to an abstract idea.
The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional element of using a system to perform the computation amounts to no more than mere instructions to apply the exception using a generic computer component. Mere instructions to apply an exception using a generic computer component cannot provide an inventive concept. The claim is not patent eligible. Claims 17 and 20 represent a system and non-transitory computer readable medium, respectively, of the limitations presented in Claim 1. These are abstract for the same reasons as Claim 1, and do not integrate the abstract ideas into a practical application or add significantly more to the abstract ideas recited in Claim 1. Claims 1, 17, and 20 represents a method, system, and non-transitory computer readable medium, respectively, are drafted to provide anomaly analysis and detection for user entitlement data of claim 1 and are abstract for the same reasons as Claim 1, and do not integrate the abstract ideas into a practical application or add significantly more to the abstract ideas recited in Claim 1.
Claims 2-16 and 18-19 are dependent on independent claims 1, 17, and 20 and similarly do not present any additional limitations that would integrate the judicial exception into a practical application. Furthermore, no additional elements are added that impose any meaningful limits on practicing the abstract idea other than generic computer components. For this reason, claims 2-16 and 18-19 are also rejected based on their dependency on claims 1, 17, and 20 and not for resolving the deficiencies identified in the rejection of claims 1, 17, and 20 above.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claim(s) 1-2, 4, 7-11, and 13-20 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Smyth et al. (US 20230319055), hereinafter referred to as Smyth.
Regarding Claim 1, Smyth discloses:
A method comprising (In ¶ 12, Smyth discloses “the present disclosure provides a method for generating access entitlements to access-controlled computing resources”): receiving, by a computing device, a plurality of entitlement assignments associated with a plurality of users from a data repository (In ¶ 51, Smyth discloses “In some embodiments, the data storage 114 may be a data store, including a secure data store. In some embodiments, the data storage 114 may store data sets representing access entitlements associated with one or more computing resources for a plurality of users or identities. The access entitlement data sets may be received from at least one of the client device 130 or the networked computing resource 160.”); repeatedly processing, by the computing device, the plurality of entitlement assignments using an anomaly detection module for a plurality of iterations, to determine a plurality of anomaly measures, wherein each respective anomaly measure of the plurality of anomaly measures corresponds to a respective iteration of the anomaly detection module and a respective entitlement assignment of the plurality of entitlement assignments (In ¶ 79, Smyth discloses “For respective levels of hierarchy, an attestation value R.sub.h.sub.i(E) may be generated based on equation (2):” And further in ¶ 82 “an attestation value associated with these entitlements may indicate a relatively low anomaly nature if assessed from the perspective of a user identifier that is part of the sub-group. In contrast, the attestation value may be relatively high if assessed from the perspective of a user that may not be part of the given sub-group.”); determining, by the computing device, a plurality of combined anomaly measures based on the plurality of anomaly measures, wherein each respective combined anomaly measure of the plurality of combined anomaly measures corresponds to a respective entitlement assignment of the plurality of entitlement assignments and is determined based on anomaly measures of the plurality of anomaly measures that correspond to the respective entitlement assignment (In ¶ 77, Smyth discloses “an attestation value associated with an entitlement R(E) may be generated based on a summation of attestation values for the given entitlement at various levels of hierarchy, represented in equation (1):” and further discloses in ¶ 83 “individual score hierarchies can be used to generate identity and entitlement pairings. For example, an entitlement is not attestable conditioned on the user being in a particular team.”); and determining an entitlement recommendation based on at least a subset of the combined anomaly measures (In ¶¶ 152-153, Smyth discloses “At operation 413, the processor may determine whether the total attestation score may meet a threshold value…. At operation 414, the processor may determine that the given entitlement may need to be subject to attestation operations.”).
Regarding Claim 2, Smyth discloses:
The method of claim 1, wherein repeatedly processing the plurality of entitlement assignments for the plurality of iterations comprises: for each respective iteration of the plurality of iterations, applying the anomaly detection module to the plurality of entitlement assignments to determine a corresponding subset of the plurality of anomaly measures, wherein each respective anomaly measure of the corresponding subset is associated with the respective iteration and a respective entitlement assignment of the plurality of entitlement assignments (In ¶ 79, Smyth discloses “For respective levels of hierarchy, an attestation value R.sub.h.sub.i(E) may be generated based on equation (2):” and further in ¶ 70 “attestation values may be generated for a number of different levels, and normalized, for example, to a value between 0 and 1.”).
Regarding Claim 4, Smyth discloses:
The method of claim 2, wherein applying the anomaly detection module for the plurality of iterations comprises: performing a first iteration by applying the anomaly detection module to the plurality of entitlement assignments to determine a first subset of the plurality of anomaly measures, wherein each anomaly measure in the first subset corresponds to the first iteration and a respective entitlement assignment of the plurality of entitlement assignments; and performing a second iteration by applying the anomaly detection module to the plurality of entitlement assignments to determine a second subset of the plurality of anomaly measures, wherein each anomaly measure in the second subset corresponds to the second iteration and a respective entitlement assignment of the plurality of entitlement assignments (In ¶ 70, Smyth discloses “In an example, n is two. Other levels of particularity are also contemplated.” And further in ¶ 78 “Respective hierarchy levels, H, may include teams h.sub.i, and may respectively be associated with a set of sub-team.”).
Regarding Claim 7, Smyth discloses:
The method of claim 1, wherein determining each respective combined anomaly measure comprises combining a corresponding subset of the plurality of anomaly measures, the corresponding subset comprising anomaly measures determined across the plurality of iterations for the respective entitlement assignment (In ¶ 77, Smyth discloses “an attestation value associated with an entitlement R(E) may be generated based on a summation of attestation values for the given entitlement at various levels of hierarchy, represented in equation (1):” and further in ¶ 83 “In some scenarios, individual score hierarchies can be used to generate identity and entitlement pairings.”)
Regarding Claim 8, Smyth discloses:
The method of claim 7, wherein determining the plurality of combined anomaly measures comprises: determining a first combined anomaly measure for a first entitlement assignment of the plurality of entitlement assignments based on a first subset of the plurality of anomaly measures, wherein the first subset comprises anomaly measures associated with the first entitlement assignment determined across the plurality of iterations; and determining a second combined anomaly measure for a second entitlement assignment of the plurality of entitlement assignments based on a second subset of the plurality of anomaly measures, wherein the second subset comprises anomaly measures associated with the second entitlement assignment determined across the plurality of iterations (In ¶ 77, Smyth discloses “In some embodiments, an attestation value associated with an entitlement R(E) may be generated based on a summation of attestation values for the given entitlement at various levels of hierarchy, represented in equation (1):” and further in ¶ 89 “In some embodiments, an attestation value may be a basis for generating a ranked or ordered list of entitlements for identifying potential anomalous entitlements.”).
Regarding Claim 9, Smyth discloses:
The method of claim 7, wherein combining the corresponding subset of the plurality of anomaly measures comprises: determining a sum of the anomaly measures in the corresponding subset; determining an average of the anomaly measures in the corresponding subset; determining a count of anomaly measures within the corresponding subset that indicate the respective entitlement assignment was identified as anomalous; or a combination thereof (In ¶ 77, Smyth discloses “an attestation value associated with an entitlement R(E) may be generated based on a summation of attestation values for the given entitlement at various levels of hierarchy, represented in equation (1):”).
Regarding Claim 10, Smyth discloses:
The method of claim 1, further comprising: receiving, by the computing device, user profile data associated with the plurality of users from the data repository, the user profile data comprising a plurality of user features (In ¶ 234, Smyth discloses “The entitlement request may include particulars about the new user, such as requested resource access requirements, user role within the organization, team on which the new user is a part of, among other details.”); and wherein repeatedly processing the plurality of entitlement assignments further comprises processing the plurality of entitlement assignments and the plurality of user features using the anomaly detection module to determine the plurality of anomaly measures (In ¶ 61, Smyth discloses “an attestation value may be based on the pervasiveness of an entitlement at the global level (organizational), or at a local level, such as line of business and BUFUGU (Business Unit, Functional Unit, Group Unit).”).
Regarding Claim 11, Smyth discloses:
The method of claim 10, wherein the plurality of user features comprises one or more of: a user role, a user team membership, a user manager identity, a user business unit affiliation, or a user location (In ¶ 234, Smyth discloses “The entitlement request may include particulars about the new user, such as requested resource access requirements, user role within the organization, team on which the new user is a part of, among other details.” And further discloses in ¶ 61, “an attestation value may be based on the pervasiveness of an entitlement at the global level (organizational), or at a local level, such as line of business and BUFUGU (Business Unit, Functional Unit, Group Unit).”).
Regarding Claim 13, Smyth discloses:
The method of claim 1, wherein the plurality of iterations comprises a predetermined number of iterations, N, where N is greater than one. (In ¶ 70, Smyth discloses “attestation values may be generated or calculated based on n levels of hierarchy, where n may be determined based on a pre-identified quantity of granularity. Greater values of n may represent a desired greater level of granularity. In an example, n is two.”)
Regarding Claim 14, Smyth discloses:
The method of claim 1, further comprising: determining, based on the combined anomaly measures, one or more inlier entitlement assignments that are identified as non-anomalous across the plurality of iterations (In ¶ 63, Smyth discloses “operations of the entitlement application 112 may include identifying entitlements that may not reach the prior-determined threshold (e.g., identified as most likely acceptable).”); and determining a suggestion for a missing entitlement for a target user based on comparing entitlement assignments of the target user to the one or more inlier entitlement assignments associated with peer users (In ¶¶ 169-170, Smyth discloses “At operation 442, the processor may determine similar identities. At operation 443, the processor may determine recommended entitlements for the given identity, based on the entitlement of the similar identities.”).
Regarding Claim 15, Smyth discloses:
The method of claim 1, further comprising: generating an alert notification based on the entitlement recommendation; triggering enhanced monitoring for user activity associated with an entitlement assignment identified in the entitlement recommendation; requiring step-up authentication for access related to an entitlement assignment identified in the entitlement recommendation; initiating an automated remediation action based on the entitlement recommendation, the automated remediation action comprising at least one of provisioning or de-provisioning an entitlement assignment identified in the entitlement recommendation; generating a report detailing entitlement assignments identified based on the combined anomaly measures; or a combination thereof (In ¶ 89, Smyth discloses “By ranking entitlements based on an ordered list of associated attestation values, the entitlement application 112 may include operations for transmitting signals to an administrative user conducting entitlement audits to scrutinize entitlements to computing resources that have a greater chance of being identified as anomalous.”).
Regarding Claim 16, Smyth discloses:
The method of claim 1, wherein determining the entitlement recommendation is performed in response to receiving an access request for a new entitlement assignment, the method further comprising: providing an indication of whether the requested new entitlement assignment is anomalous based on the entitlement recommendation (In ¶ 233, Smyth discloses “At operation 902, the processor may receive an input data set representing an entitlement request associated with a user identifier.” And further in ¶ 235 “the entitlement request may be associated with a query on whether a given entitlement data set for a user identifier may include unintended or outdated entitlement assignments.”).
Claims 17-19 are directed to a system having functionality corresponding to the method of Claims 1, 2, and 7 respectively, and are rejected by similar rationale, mutatis mutandis.
Claim 20 is directed to a non-transitory, computer readable medium having functionality corresponding to the method of Claim 1, and is rejected by similar rationale, mutatis mutandis.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 3, 5-6 are rejected under 35 U.S.C. 103 as being unpatentable over Smyth et al. (US 20230319055), hereinafter referred to as Smyth, in view of Gaddam et al. (US 20210328969 ), hereinafter referred to as Gaddam.
Regarding Claim 3, Smyth discloses the limitations of claim 2.
However, Smyth does not disclose a machine learning model or specifically isolation forest model.
Gaddam discloses:
The method of claim 2, wherein the anomaly detection module comprises one or more machine learning models, and wherein applying the anomaly detection module to the plurality of entitlement assignments during each respective iteration comprises providing the plurality of entitlement assignments as input to the one or more machine learning models (In ¶ 104, Gaddam discloses “As stated above, the identified machine learning model may be a classifier model uniquely associated with the requesting entity, requesting entity profile, or requesting entity credential. For example, the machine learning model may be a support vector machine (SVM), isolation forest, etc.”).
One in ordinary skill in the art of cryptography would have been motivated, before the effective filing date of the claimed invention to modify Smyth’s approach by utilizing Gaddam’s approach of using machine learning models as the motivation would be combining the outputs of multiple anomaly detection models increases accuracy while reducing false positive rates (See Gaddam, ¶ 125).
Regarding Claim 5, the combination of Smyth and Gaddam disclose:
The method of claim 3, wherein the one or more machine learning models comprise an unsupervised anomaly detection model (In ¶ 60, Smyth discloses “In some embodiments, the processor 102 may generate attestation values based on unsupervised, machine-learning model operations, and may be based on at least one of operations associated with statistical analysis, classification operations, or recommendation operations.”).
Regarding Claim 6, the combination of Smyth and Gaddam disclose the limitations of claim 5.
However, Smyth does not disclose a machine learning model or specifically isolation forest model.
Gaddam discloses:
The method of claim 5, wherein the unsupervised anomaly detection model comprises an Isolation Forest model. (In ¶ 104, Gaddam discloses “As stated above, the identified machine learning model may be a classifier model uniquely associated with the requesting entity, requesting entity profile, or requesting entity credential. For example, the machine learning model may be a support vector machine (SVM), isolation forest, etc.”).
One in ordinary skill in the art of cryptography would have been motivated, before the effective filing date of the claimed invention to modify Smyth’s approach by utilizing Gaddam’s approach of using machine learning models as the motivation would be combining the outputs of multiple anomaly detection models increases accuracy while reducing false positive rates (See Gaddam, ¶ 125).
Claim(s) 12 is rejected under 35 U.S.C. 103 as being unpatentable over Smyth et al. (US 20230319055), hereinafter referred to as Smyth, in view of Patil et al. (US 20210142209), hereinafter referred to as Patil.
Regarding Claim 12, Smyth discloses the limitations of claim 10.
However, Smyth does not disclose the use of weights.
Patil discloses:
The method of claim 10, further comprising: determining feature weights for different user features of the plurality of user features; and wherein repeatedly processing the plurality of entitlement assignments using the anomaly detection module comprises applying the feature weights during the processing. (In ¶ 66, Patil discloses “a weighted function of the risk scores of the user attribute peer groups may be utilized to represent the different levels of confidence in the risk scores for the various peer groups.” And further in ¶ 67 “Weight=e(−q/Q), where, q is the number of persons in the peer group and for Q is a value selected to represent an importance attached to the user attribute(s) associated with the peer group.” )
One in ordinary skill in the art of cryptography would have been motivated, before the effective filing date of the claimed invention to modify Smyth’s approach by utilizing Patil’s approach of using weights as the motivation would be to provide a reliable and confident risk score for various peer groups based on size (See Patil, ¶ 66).
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Baikalov et al. (US 20120047575 ) discloses a method for performing access risk assessments on entitlement data.
Badawy et al. (US 20230016859) discloses using artificial intelligence for identity management and entitlement access.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SHADI H KOBROSLI whose telephone number is (571)272-1952. The examiner can normally be reached M-F 9am-5pm ET.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Saleh Najjar can be reached on 571-272-4006. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/SHADI H KOBROSLI/Examiner, Art Unit 2492 /RUPAL DHARIA/Supervisory Patent Examiner, Art Unit 2492