DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Priority
Acknowledgement is made of applicant’s claim for priority based on Application No. 18/771,415 filed on 12 July 2024, which is a continuation of and claims priority to Application No. 18/379,926 filed on 13 October 2023, which is a continuation of and claims priority to Application No. 17/550,040 filed on 14 December 2021.
Double Patenting
Claims 1-20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-20 of U.S. Patent No. 12,361,008 B2 (hereinafter referred to as the “’008 patent”).
Although the claims at issue are not identical, they are not patentably distinct from each other because independent claims 1, 8, and 15 represent overlapping and broader limitations than those found in the ’008 patent. More specifically, the ’008 patent includes additional limitations not present in the present application, including that the view definition is a “limited consumer view definition”, that a “table” of certification results is generated (as opposed to the present claims in which simply certification results are generated), and utilizes a data access certification process (i.e., “perform, based on one or more first rules, associated with consumer permissions to access the database via a cloud database platform, a data access certification process on the records stored by the database to generate a first table of certification results” and “perform the data access certification process on the updated at least one record to generate a second table of certification results”).
The rest of the independent claims’ limitations are substantially similar such that the scope is indistinguishable from one another.
Dependent claims 2-7, 9-14, and 16-20 of the present application recite substantially similar limitations to dependent claims 2-7, 9-14, and 16-20 of the ’008 patent, with the exception of the present application’s claims 4, 11, and 18, which recite “view definition” as opposed to the ’008 patent’s claims 4, 11, and 18 that recite “limited consumer view definition”.
Claims 1-20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-20 of U.S. Patent No. 12,067,018 B2 (hereinafter referred to as the “’018 patent”).
Although the claims at issue are not identical, they are not patentably distinct from each other because independent claims 1, 8, and 15 represent overlapping and broader limitations than those found in the ’018 patent. More specifically, the ’018 patent includes additional limitations not present in the present application, including the use of one or more first rules, i.e., “determine one or more first rules that specify criteria, associated with consumer permissions to access the database via a cloud database platform, that limit consumer access to the records stored by the database”, and that the query is executed “in compliance with the criteria of the one or more first rules”; and a “limited consumer view definition” as opposed to the present application’s “view definition”.
The rest of the independent claims’ limitations are substantially similar such that the scope is indistinguishable from one another.
Dependent claims 2-7, 9-14, and 16-20 of the present application recite substantially similar limitations to dependent claims 2-7, 9-14, and 16-20 of the ’018 patent, with the exception of the present application’s claims 4, 11, and 18, which recite “view definition” as opposed to the ’018 patent’s claims 4, 11, and 18 that recite “limited consumer view definition”.
Claims 1-20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-20 of U.S. Patent No. 11,829,367 B2 (hereinafter referred to as the “’367 patent”).
Although the claims at issue are not identical, they are not patentably distinct from each other because independent claims 1, 8, and 15 represent overlapping and broader limitations than those found in the ’367 patent. More specifically, the ’367 patent includes additional limitations not present in the present application, including
a “limited consumer view definition” as opposed to the present claims’ “view definition”;
the use of a shared view definition, i.e., “determine a shared view definition for access to the database stored on the database server, wherein the shared view definition is configured to provide access to all records stored by the database and to enable execution of queries against the database using processing resources of one or more virtual warehouses provided by a cloud database platform”, that the limited consumer view definition is generated based on an intersection of the first table of certification results and the shared view definition, that the detection of the update to at least one of the records stored by the database is via the shared view definition, and that the updated limit consumer view definition is generated also based on the shared view definition;
the use of one or more first rules, i.e., “determine one or more first rules that specify criteria, associated with consumer permissions to access the database via a cloud database platform, that limit consumer access to the records stored by the database”, and that the query is executed “in compliance with the criteria of the one or more first rules”; and
the use of a data access certification process, i.e., “perform, based on one or more first rules, associated with consumer permissions to access the database via a cloud database platform, a data access certification process on the records stored by the database to generate a first table of certification results” and “perform the data access certification process on the updated at least one record to generate a second table of certification results”.
(Essentially, the ’367 patent discloses the same limitations as the ’008 and ’018 patents, as well as additional detail concerning the shared view definition, as explained above).
The rest of the independent claims’ limitations are substantially similar such that the scope is indistinguishable from one another.
Dependent claims 2-7, 9-14, and 16-20 of the present application recite substantially similar limitations to dependent claims 2-7, 9-14, and 16-20 of the ’367 patent, with the exception of the present application’s claims 4, 11, and 18, which recite “view definition” as opposed to the ’367 patent’s claims 4, 11, and 18 that recite “limited consumer view definition”.
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13.
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1-20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Independent claims 1, 8, and 13 recite “generate, based on the first certification results indicating compliance…a view definition configured to provide…access to a first portion of the records in compliance with the one or more first rules and exclude a second portion of the records not in compliance with the one or more first rules”.
There is both a “shared view definition” and “limited consumer view definition”. For example, Specification, [0011] states that a shared view definition for access to the database may be determined, where the shared view definition provides access to all records stored by the database. Although contextually, it appears that this “view definition” refers to the “limited consumer view definition”, as the limited consumer view definition is generated based on the certification results, however, the parent applications claim the use of “limited consumer view definition”. It is unclear, therefore, whether “view definition”, which appears to refer to a broader scope than “limited consumer view definition”, was intended to mean “limited consumer view definition”, as described in the Specification and claimed in the parent applications, or “shared view definition”, and/or the distinction in scope between the claimed “view definition” and “limited consumer view definition”.
For purposes of examination, the interpretation the “view definition” corresponds to the “limited consumer view definition” has been taken.
The dependent claims are rejected for at least by virtue of their dependency on their respective independent claims, and for failing to cure the deficiencies of their respective independent claims.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-5, 8-12, and 15-19 are rejected under 35 U.S.C. 103 as being unpatentable over Vahlis et al. (“Vahlis”) (US 2015/0150075 A1), in view of Fisher et al. (“Fisher”) (US 6,085,191 A).
Regarding claim 1: Vahlis teaches A data sharing platform configured to provide access to records of a database stored on a database server (Vahlis, [0029-0033], where the disclosed system includes database 145 provided by a third-party server and/or network 140 not directly controlled by a data owner 105 who uploaded the secured data to the third party network 140 to create the secured third-party database 145, and data may be requested to be accessed by a requesting entity 110 who may not be trusted by (or otherwise be beyond the control of) the data owner), the data sharing platform comprising:
one or more processors; and memory storing instructions that, when executed by the one or more processors, cause the data sharing platform to (Vahlis, [Claim 10], where the disclosed system includes a processor and memory coupled to the processor that comprises computer readable program code embodied in the memory that, when executed by the processor, causes the processor to perform the disclosed operations):
generate, based on first certification results indicating compliance, by the records stored by the database, with one or more first rules associated with permissions to access the database via a cloud database platform, and without modifying the records stored by the database, a view definition configured to provide, via … the cloud database platform, access to a first portion of the records in compliance with the one or more first rules and exclude a second portion of the records not in compliance with the one or more first rules (Vahlis, [FIG. 1], [FIG. 4] and [0050-0054], where the system generates a secure database DB (i.e., “view definition”) by utilizing access policy representation BF (Bloom Filter), which identifies the records D of the original database DB0 to which access is authorized for the corresponding user or requesting entity. In other words, for each known user that has access rights to the database DB0 (i.e., “one or more first rules associated with permissions to access the database”), a Bloom filter BF is generated to identify all of the data records D in the original database DB0 to which that particular user is allowed to access under the access policy (i.e., “based on first certification results indicating compliance, by the records stored by the database…”). A secure database DB (such as the database 145 of [FIG. 1]), is created to include the plurality of records D and the respective access policy representations BF for each of the known users. Upon receipt of a query q for d(r1, r2) from a particular user, the system determines whether the resulting values are set in the Bloom filter BF to determine whether or not to transmit data to the end user.
See Vahlis, [0037] and [0041-0042], where the query result delivery control module 231 obtains from the data access policy verification module 224, the query result containing indications of which record(s) the requesting entity 110 is permitted to access under the applicable access policy, and which do not correspond to record(s) the requesting entity 110 is permitted to access. The data access policy verification module 224 verifies whether a requesting entity 110 is permitted to access data included in the query result based on the representation of the data access policy, e.g., list of otherwise identifying the particular records in the database 145 to which the requesting entity 110 is authorized to access. The query result delivery control module 231 may then allow transmission of the matching data (which complies with the access policy) while preventing transmission of the other data (which does not comply with the access policy (i.e., “provide…access to a first portion of the records in compliance with the one or more first rules and exclude a second portion of the records not in compliance with the one or more first rules”).
See Vahlis, [0068-0069], where a data owner may store data on a cloud storage solution (e.g., such that the database 145 is a “database via a cloud database platform”, as claimed)) … .
Vahlis does not appear to explicitly teach one or more virtual warehouses of [the cloud database platform]; detect an update to at least one record of the records stored by the database; generate second certification results based on the update; generate, based on the first certification results and the second certification results, an updated view definition different from the view definition; and based on the one or more first rules via the updated view definition, cause a first virtual warehouse, of the one or more virtual warehouses, to execute a query on the records.
Fisher teaches detect an update to at least one record of the records stored by the database (Fisher, [23:46-54], where whenever a new managed object has been added to the managed object tree (step 1330), the Update View procedure is called (1332) so as to update the set of views defined in the DBMS);
generate second certification results based on the update (Fisher, [24:32-52], where there are database tables XTable, YTable, and ZTable representing classes of managed objects called X-MOC, Y-MOC, and Z-MOC, respectively. XTable has three rows X1-MOI, X2-MOI, and X3-MOI, with two users U1 and U2, and two views for XTable: view_XTable_U1 and view_XTable_U2. New managed object instance X4-MOI is created (i.e., “based on the update”), resulting in the Update_View procedure 372 checking the access control database to determine if X4-MOI should be added to either of the two views corresponding to user U1 and user U2 (i.e., “generate second certification results”));
generate, based on the first certification results and the second certification results, an updated view definition different from the view definition (Fisher, [24:32-52], where after checking the access control database, Update_View determines that X4_MOI belongs only to the X-MOC class, and so the views affecting XTable will need to be updated. Since other tables, YTable and ZTable, are not affected, then their views are not affected. The creation of the X4-MOI object requires only the view_XTable_U1 and view_XTable_U2 views (the results of the generated “first certification results”) to be updated. However, the only views that will actually need to be modified are for those users who have read access to the newly added object (i.e., “based on the second certification results”), e.g., by adding the FDNs for newly created objects to the applicable ones of the previously created views, i.e., the previously created views being the result of “first certification results” (i.e., “generate, based on the first certification results and the second certification results, an updated view definition different from the view definition”).
In other words, recall that XTable had two users, U1 and U2 associated with it. Thus, in the original set of view data specific to the users, view_XTable_U1 and view_XTable_U2 are the views as a result of the “first certification results” (see also, e.g., Vahlis above with respect to the secure database DB 145). When XTable has an extra row, X4_MOI, added to it, not all users will have access to it, i.e., the result of checking the access control database against the newly added row, which implicitly results in generating “second certification results”). For purposes of example, the system checks the access control database, e.g., implicitly resulting in a generation of “second certification results” that indicated user U1 did not have access; however, the access control database returns (i.e., via implicit generation of “second certification results”) that user U2 has access. Thus, only view_XTable_U2 is updated); and
based on the one or more first rules via the updated view definition, cause a first [database] to execute a query on the records (Vahlis, [0042], where an data access policy verification module 224 indicates that some of the data included in the query result matches database record(s) to which the requesting entity 110 is permitted to access, while others do not correspond to database record(s) to which the requesting entity 110 is permitted to access, against the secure database DB 145 (see, e.g., Vahlis, [0050-0054]) (i.e., “cause a first [database] to execute a query on the records”). The query result delivery control module 231 may then allow transmission of the matching data (which complies with the access policy) while preventing transmission of the other data (which does not comply with the access policy).
See Fisher above with respect to the “updated” view definition).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have combined the teachings of Vahlis and Fisher (hereinafter “Vahlis as modified”) with the motivation of ensuring that the Vahlis’ secure database, e.g., a type of filtered subset of data that is possibly accessible by the user, is up-to-date, thereby maintaining data accuracy, and updating only those view definitions that need to be updated, thereby conserving processing resources (e.g., avoiding unnecessarily regenerating views that did not need to be regenerated).
Although Vahlis as modified does not appear to explicitly state that the database corresponds to “one or more virtual warehouses of [the cloud database platform]”, and that “a first virtual warehouse, of the one or more virtual warehouses” is what executes the query on the records, Vahlis discloses in [0068] that “a cloud storage solution…can ensure that the requesting entity doesn’t receive data beyond that which it is entitled to under the corresponding access policy”. Therefore, one of ordinary skill in the art would have been suggested by Vahlis’ disclosure to modify Vahlis such that a first virtual warehouse is provided on top of Vahlis’ disclosed cloud database platform, with the motivation of scalability, high reliability, and high availability, and an ability to support multiple disparate/independent workloads1,2,3, thereby supporting high parallel operations, i.e., an increased ability to handle large workloads, and completing operations faster.
Regarding claim 2: Vahlis as modified teaches The data sharing platform of claim 1, wherein the instructions, when executed by the one or more processors, cause the data sharing platform to detect the update by causing the data sharing platform to: receive, via a cloud database platform, an indication of the update (Fisher, [23:46-54], where whenever a new managed object has been added to the managed object tree (step 1330), the Update View procedure is called (1332) so as to update the set of views defined in the DBMS (i.e., “receive…an indication of the update”). See Vahlis, [0068-0069] in claim 1 above with respect to the “cloud database platform”).
Regarding claim 3: Vahlis as modified teaches The data sharing platform of claim 1, wherein the update comprises removal of a first record of the records stored by the database (Fisher, [22:1-10] and [23:46-67]-[24:1-2], where the Update_View procedure 372 is called when a managed object is deleted, which results in updating the set of views defined in the DBMS, e.g., existing view is deleted, and then re-recreated using procedure 362).
Regarding claim 4: Vahlis as modified teaches The data sharing platform of claim 3, wherein the instructions, when executed by the one or more processors, cause the data sharing platform to generate the updated view definition based on a comparison of the first certification results and the second certification results (see Fisher, [24:32-52] in claim 1 above with respect to the generation of the updated view definition based on the first certification results and second certification results. See Fisher, [24:53-67], where views can be modified instead of being regenerated, e.g., when new managed objects are created, the definitions of previously created Views (i.e., based on “the first certification results”) can be modified by adding the fully distinguished names (FDNs) for the newly created objects (i.e., based on the “second certification results”) to the applicable ones of the previously created views).
Although Fisher does not appear to explicitly state that the first and second certification results (i.e., implied existence via their corresponding “views”) are compared as claimed (i.e., based on “a comparison of” the first certification results and the second certification results), Fisher discloses that the data resulting from the second certification result may be added to the view corresponding to the claimed first certification result. Therefore, one of ordinary skill in the art would have found it obvious to have modified Fisher such that the two certification results are compared with the motivation of identifying only the differences between the resulting views such that only the modified/changed data is added, thus conserving resources on having to regenerate the entire view.
Regarding claim 5: The data sharing platform of claim 1, wherein at least one of the one or more first rules prevent one or more of: output of invalid values; output of values outside of a predefined range; or output of values that do not match a regular expression pattern (Vahlis, [0037], where the access policy representation identifies particular records stored in the database to which the requesting entity 110 is authorized to access).
Although Vahlis does not appear to explicitly state that the type of information prevented from being outputted pertain to “one or more of: output of invalid values; output of values outside of a predefined range; or output of values that do not match a regular expression pattern”, the claimed invention does not distinguish over the prior art because the differences in the claim limitations and the prior art’s disclosure are only found in the nonfunctional descriptive material and are not functionally involved in the steps recited. The prevention of data transmission would have been performed the same regardless of the specific data involved (i.e., the claimed data, Vahlis’ access authorization, or some other data). Thus, this descriptive material will not distinguish the claimed invention from the prior art in terms of patentability. See In re Gulack, 703 F.2d 1381, 1385, 217 USPQ2d 401, 404 (Fed. Cir. 1983); In re Lowry, 32 F.3d 1579, 32 USPQ2d 1031 (Fed. Cir. 1994).
Therefore, it would have been obvious to a person of ordinary skill in the art to have referred to Vahlis’ teachings in making the claimed invention, because such data does not functionally relate to the steps in the method claimed and because the subjective interpretation of the data does not patentably distinguish the claimed invention over the prior art.
Regarding claim 8: Claim 8 recites substantially the same limitations as claim 1, and is rejected for the same reasons.
Regarding claim 9: Claim 9 recites substantially the same claim limitations as claim 2, and is rejected for the same reasons.
Regarding claim 10: Claim 10 recites substantially the same claim limitations as claim 3, and is rejected for the same reasons.
Regarding claim 11: Claim 11 recites substantially the same claim limitations as claim 4, and is rejected for the same reasons.
Regarding claim 12: Claim 12 recites substantially the same claim limitations as claim 5, and is rejected for the same reasons.
Regarding claim 15: Claim 15 recites substantially the same claim limitations as claim 1, and is rejected for the same reasons.
Note that Vahlis teaches One or more non-transitory computer-readable media comprising instructions that, when executed by one or more processors of a data sharing platform, cause the data sharing platform to provide access to records of a database stored on a database server by causing the data sharing platform to [implement the claimed steps] (Vahlis, [0026] and [Claim 10], where the disclosed system may be embodied as a computer-readable storage medium having computer-readable program code embodied in the medium. The medium may be, for example, magnetic, optical, a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), and CD-ROM (all examples of “non-transitory” media), where the memory (e.g., medium) may be executed by a processor to implement the disclosed steps).
Regarding claim 16: Claim 16 recites substantially the same claim limitations as claim 2, and is rejected for the same reasons.
Regarding claim 17: Claim 17 recites substantially the same claim limitations as claim 3, and is rejected for the same reasons.
Regarding claim 18: Claim 18 recites substantially the same claim limitations as claim 4, and is rejected for the same reasons.
Regarding claim 19: Claim 19 recites substantially the same claim limitations as claim 5, and is rejected for the same reasons.
Claims 6, 13, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Vahlis et al. (“Vahlis”) (US 2015/0150075 A1), in view of Fisher et al. (“Fisher”) (US 6,085,191 A), in further view of McGovern et al. (“McGovern”) (US 2016/0352739 A1).
Regarding claim 6: Vahlis as modified teaches The data sharing platform of claim 1, but does not appear to explicitly teach wherein at least one of the one or more first rules prevent output of data outside a time period specified by the at least one of the one or more first rules.
McGovern teaches wherein at least one of the one or more first rules prevent output of data outside a time period specified by the at least one of the one or more first rules (McGovern, [0037], where an access policy may define time based conditions such as a time range when the policy is enforced, e.g., developing a policy based on time to control access at certain times. See, e.g., McGovern, [0052], where a rule set based policy restricts data access by a Device A between 10:00PM and 4:00AM EST, where a broker determines that the data request from Device A at 11:00PM EST violates the logic provided in the rule set and accordingly denies the data request, preventing the endpoint device 430 from receiving the requested data).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have combined the teachings of Vahlis as modified and McGovern with the motivation of enhancing security, e.g., preventing malicious activity that is likely to occur within certain time frames/windows.
Regarding claim 13: Claim 13 recites substantially the same claim limitations as claim 6, and is rejected for the same reasons.
Regarding claim 20: Claim 20 recites substantially the same claim limitations as claim 6, and is rejected for the same reasons.
Claims 7 and 14 are rejected under 35 U.S.C. 103 as being unpatentable over Vahlis et al. (“Vahlis”) (US 2015/0150075 A1), in view of Fisher et al. (“Fisher”) (US 6,085,191 A), in further view of Brannon et al. (“Brannon”) (US 2022/0043935 A1).
Regarding claim 7: Vahlis as modified teaches The data sharing platform of claim 1, but does not appear to explicitly teach wherein at least one of the one or more first rules is configured to cause output of an alert based on a determination that more than a predetermined percentage of the records is not output based on the one or more first rules.
Brannon teaches wherein at least one of the one or more first rules is configured to cause output of an alert based on a determination that more than a predetermined percentage of the records is not output based on the one or more first rules (Brannon, [0004] and [0064], where the system generates notifications when a particular outlier or unusual events occur in analyzing a request, e.g., the system determines the redacted portion of data in a request exceeds a certain threshold percentage of the total amount of data or total amount of request content, the system may not process that request at all. The system may inform the user submitting the request that the redacted data represents a portion of the data greater than a threshold, and that the request was not processed. See Vahlis in claim 1 above with respect to the “one or more first rules”).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have combined the teachings of Vahlis as modified and Brannon with the motivation of avoiding devoting resources to processing extraneous data, which can degrade system performance through the wasteful expenditure of resources, the provision of an inaccurate or incomplete request to the response, or both (Brannon, [0002]).
Regarding claim 14: Claim 14 recites substantially the same claim limitations as claim 7, and is rejected for the same reasons.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure. See the enclosed 892 form. Vittal (“Top 10 Reasons Why You Should Consider Snowflake for Data Warehousing”), Parker (“Introducing Snowflake: Cloud-Based Data Warehousing”), and Stitch (“5 steps for choosing a cloud data warehouse”) are cited to show why one of ordinary skill in the art would have found it obvious to have incorporated a virtual data warehouse into the primary reference’s disclosure (see Vital, [bullet points 2 and 3]; Parker, [“Snowflake Explained”], [“Such Scalability. Wow”], and [“Testing the Waters”]; and Stitch, [“Cloud data warehouses: What they have in common”]).
The prior art should be considered to define the claims over the art of record.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to IRENE BAKER whose telephone number is (408)918-7601. The examiner can normally be reached M-F 8-5PM PT.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Boris Gorney can be reached at (571) 270-5626. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/IRENE BAKER/Primary Examiner, Art Unit 2154
18 July 2026
1 Vittal. “Top 10 Reasons Why You Should Consider Snowflake for Data Warehousing”, at [bullet points 2 and 3].
2 Parker. “Introducing Snowflake: Cloud-Based Data Warehousing”, at [“Snowflake Explained”], [“Such Scalability. Wow”], and [“Testing the Waters”].
3 Stitch. “5 steps for choosing a cloud data warehouse”, at [“Cloud data warehouses: What they have in common”].