DETAILED ACTION
Status of Claims
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
This action is in reply to Application 19/267,453 filed on 11 July 2025.
Claims 1-20 are currently pending and have been examined.
Claim Rejections – 35 USC § 103
The following is a quotation of U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office Action:
A patent may not be obtained though the invention is not identically disclosed or described as set forth in section 102 of this title, if the differences between the subject matter sought to be patented and the prior art are such that the subject matter as a whole would have been obvious at the time the invention was made to a person having ordinary skill in the art to which said subject matter pertains. Patentability shall not be negatived by the manner in which the invention was made.
Claims 1-20 are rejected under U.S.C. 103 as being unpatentable over Martinez et al., US 2024/0364745 A1 (“Martinez”), in view of Gutta et al., US 2020/0380161 A1 (“Gutta”), further in view of Chandramouli et al., US 2017/0187693 A1 (“Chandramouli”).
Re Claim 1: Martinez discloses a system for remotely retrieving sensitive data in cloud computing systems featuring shared data repositories accessible from a plurality of application programming interfaces (APIs), the system comprising:
one or more processors; (¶¶ [132, 135-136])
a non-transitory, computer-readable medium comprising instructions recorded thereon that when executed by the one or more processors cause operations comprising: (¶¶ [147, 151])
receiving a first API request, from a first device, for a first encrypted field set, wherein the first encrypted field set is stored on a shared data repository for a cloud computing system; (FIG. 1; ¶¶[3-32, 90-91, 98, 114, 134, 150-152])
Regarding the limitation feature comprising:
in response to the first API request and after a determination is made that a first composite field set of the shared data repository that comprises the first encrypted field set, wherein the first composite field set comprises the first encrypted field set and a second encrypted field set:
Gutta makes this teaching in a related endeavor (¶¶[16-17, 28-29, 32-33]). It would have been obvious to one of ordinary skill in the art at the time of the invention to incorporate the teachings of Gutta to the invention of Martinez as described above for the motivation of facilitating secure compliant data collection.
Martinez further discloses:
selecting a first API request mapping from a plurality of API request mappings based on the first API request, wherein each of the plurality of API request mappings comprises a respective function template for an API parser and API server; (¶¶[11, 74, 80, 82, 113])
Regarding the limitation feature comprising:
reinterpreting the first API request to generate a second API request using the first API request mapping, wherein the second API request modifies the first API request to exclude the second encrypted field set.
Chandramouli makes this teaching in a related endeavor (¶¶[19-22, 24, 28-29]). It would have been obvious to one of ordinary skill in the art at the time of the invention to incorporate the teachings of Chandramouli to the invention of Martinez as described above for the motivation of orchestrating a secure, fraud resilient data transaction involving data associated with multiple parties.
Re Claim 2: : Claim 2, as best understood by the Examiner, encompasses the same or substantially the same scope as claim 1. Accordingly, claim 2 is rejected in the same or substantially the same manner as claim 1.
Martinez further discloses:
generating for display, on a user interface of the first device, the data for the first encrypted field set. (¶[130])
Re Claim 3: Martinez in view of Gutta in view of Chandramouli discloses the method of claim 2. Martinez further discloses:
selecting, based on the first API request, a first API request mapping from a plurality of API request mappings, wherein each of the plurality of API request mappings comprises a respective function template for an API parser and API server; determining a first API corresponding to the first API request; and determining that the first API request mapping corresponds to the first API. (¶¶[11, 18, 26, 74, 80, 82, 113])
Re Claim 4: Martinez in view of Gutta in view of Chandramouli discloses the method of claim 2. Martinez further discloses:
selecting, based on the first API request, a first computer client of a plurality of computer clients; and determining to query the shared data repository for the first encrypted field set using the first computer client as a proxy. (FIG. 1; ¶¶[3-32, 90-91, 98, 114, 134, 150-152])
Re Claim 5: Martinez in view of Gutta in view of Chandramouli discloses the method of claim 2. Martinez further discloses:
determining a first field attribute for the first composite field set, wherein determining the first field attribute for the first composite field set further comprises: determining an encrypted data management platform corresponding to the first composite field set; determining the first field attribute based on the encrypted data management platform; and reinterpreting the first API request to generate a second API request corresponding to the first field attribute. (¶¶[76, 105])
Re Claim 6: Martinez in view of Gutta in view of Chandramouli discloses the method of claim 2. Martinez further discloses:
further comprising: generating for display the data for the first encrypted field set by: determining a first decrypted field set corresponding to the first encrypted field set, wherein the first decrypted field set comprises a decryption key for a second encrypted field set; generating, based on the decryption key, a third API request for the second encrypted field set; querying, using the third API request, the shared data repository for the second encrypted field set; and generating for display, on the user interface of the first device, a second decrypted field set corresponding to the second encrypted field set. (¶¶[17, 21, 84, 90-91, 130])
Re Claim 7: Martinez in view of Gutta in view of Chandramouli discloses the method of claim 2. Martinez further discloses:
wherein determining the first composite field set of the shared data repository that comprises the first encrypted field set further comprises: receiving a first device identifier corresponding to the first device; determining a first user account corresponding to the first device identifier using a database, wherein the database comprises a listing of device identifiers corresponding to user accounts; and selecting the first composite field set based on the first user account. (¶¶[7, 11, 96-98])
Re Claim 8: Martinez in view of Gutta in view of Chandramouli discloses the method of claim 2. Martinez further discloses:
wherein determining the first composite field set of the shared data repository that comprises the first encrypted field set further comprises: receiving, in the first API request, a platform identifier corresponding to the first encrypted field set; determining a first cloud platform corresponding to the first encrypted field set using a database, wherein the database comprises a listing of cloud platforms storing respective field sets; and selecting the first composite field set based on the first cloud platform. (¶¶[113, 118-119, 147])
Re Claim 9: Martinez in view of Gutta in view of Chandramouli discloses the method of claim 2. Martinez further discloses:
selecting, based on the first API request, a first API request mapping from a plurality of API request mappings, wherein each of the plurality of API request mappings comprises a respective function template for an API parser and API server. (¶¶[11, 18, 26, 74, 80, 82, 113])
Re Claim 10: Martinez in view of Gutta in view of Chandramouli discloses the method of claim 9. Martinez further discloses:
wherein selecting, based on the first API request, the first API request mapping from the plurality of API request mappings further comprises: determining a subset of API request mappings of the plurality of API request mappings that correspond to a first field attribute; determining an API of the first device; and filtering the subset of API request mappings based on the API. (¶¶[66, 105, 113, 128])
Re Claim 11: Martinez in view of Gutta in view of Chandramouli discloses the method of claim 9. Martinez further discloses:
wherein selecting, based on the first API request, the first API request mapping from the plurality of API request mappings further comprises: determining a type of content of the first encrypted field set; determining a subset of API request mappings of the plurality of API request mappings that correspond to the type of content; and selecting the first API request mapping from the subset of API request mappings. (FIG. 2A; ¶¶[11, 61, 79, 80, 113, 158-159, 161,])
Re Claim 12: Martinez in view of Gutta in view of Chandramouli discloses the method of claim 9. Martinez further discloses:
wherein selecting, based on the first API request, the first API request mapping from the plurality of API request mappings further comprises: determining a device type of the first device; determining a subset of API request mappings of the plurality of API request mappings that correspond to the device type; and selecting the first API request mapping from the subset of API request mappings. (¶¶[64, 105, 112])
Re Claim 13: Martinez in view of Gutta in view of Chandramouli discloses the method of claim 9. Martinez further discloses:
wherein selecting, based on the first API request, the first API request mapping from the plurality of API request mappings further comprises: determining a processing speed requirement of the first API request; determining a subset of API request mappings of the plurality of API request mappings that correspond to the processing speed requirement; and selecting the first API request mapping from the subset of API request mappings. (¶¶[64, 105, 112])
Re Claim 14: Martinez in view of Gutta in view of Chandramouli discloses the method of claim 9. Martinez further discloses:
wherein selecting, based on the first API request, the first API request mapping from the plurality of API request mappings further comprises: determining a security protocol of the first API request; determining a subset of API request mappings of the plurality of API request mappings that correspond to the security protocol; and selecting the first API request mapping from the subset of API request mappings. (¶¶[58, 60, 64])
Re Claim 15: Martinez in view of Gutta in view of Chandramouli discloses the method of claim 2. Martinez further discloses:
further comprising: receiving a data refreshment schedule for the first encrypted field set; determining that the first encrypted field set has been refreshed based on the data refreshment schedule; and transmitting a fourth API request to retrieve the first encrypted field set. (¶¶[FIG. 3:[286]; 28, 67, 105, 120])
Re Claim 16: Claim 16, as best understood by the Examiner, encompasses the same or substantially the same scope as claim 2. Accordingly, claim 16 is rejected in the same or substantially the same manner as claim 2.
One or more non-transitory, computer-readable mediums comprising instructions recorded thereon that when executed by one or more processors cause operations comprising:
receiving, at an abstraction layer, a first API request, from a first device, for a first encrypted field set, wherein the first encrypted field set is stored on a shared data repository for a cloud computing system, wherein the abstraction layer comprises an API layer that performs one or more functions related to storing or monitoring security credentials or other secured data;
in response to the first API request, determining, by the abstraction layer, a first composite field set of the shared data repository that comprises the first encrypted field set;
selecting, based on the first API request, a first API request mapping from a plurality of API request mappings, wherein each of the plurality of API request mappings comprises a respective function template for an API parser and API server;
querying, using a second API request, the shared data repository for the first encrypted field set;
receiving, by the abstraction layer, data for the first encrypted field set in response to the second API request; and
generating for display, on a user interface of the first device, the data for the first encrypted field set.
Re Claim 17: Claim 17, as best understood by the Examiner, encompasses the same or substantially the same scope as claim 3. Accordingly, claim 17 is rejected in the same or substantially the same manner as claim 3.
Re Claim 18: Claim 18, as best understood by the Examiner, encompasses the same or substantially the same scope as claim 4. Accordingly, claim 18 is rejected in the same or substantially the same manner as claim 4.
Re Claim 19: Martinez in view of Gutta in view of Chandramouli discloses the one or more non-transitory, computer-readable mediums of claim 16. Martinez further discloses:
determining an encrypted data management platform corresponding to the first composite field set; and determining a first field attribute based on the encrypted data management platform. (¶¶[76, 105])
Re Claim 20: Martinez in view of Gutta in view of Chandramouli discloses the one or more non-transitory, computer-readable mediums of claim 16. Martinez further discloses:
wherein generating for display the data for the first encrypted field set further comprises: determining a first decrypted field set corresponding to the first encrypted field set, wherein the first decrypted field set comprises a decryption key for a second encrypted field set; generating, based on the decryption key, a third API request for the second encrypted field set; querying, using the third API request, the shared data repository for the second encrypted field set; and generating for display, on the user interface of the first device, a second decrypted field set corresponding to the second encrypted field set. (¶¶[17, 21, 84, 90-91, 130])
Conclusion
The prior art(s) made of record and not relied upon is/are considered pertinent to applicant's disclosure.
Kirsch (US 2012/0324242 A1) discloses a method and system for fully encrypted repository. According to an embodiment of the present invention, a method for using information in conjunction with a data
repository includes encrypting data associated with the information with an encryption key, sending at least the encrypted data to the data repository, and possibly deleting the information. The method also includes receiving a request for the information from a remote device, and sending a request for
the encrypted data to the data repository. The method further includes receiving the encrypted data from the data repository, decrypting the encrypted data using the encryption key, and sending the information to the remote device.
Kludy et al. (US 2019/0034643 A1) discloses a secure information storage. Embodiments of the disclosure include systems and methods for secure storage and/or retrieval of customer secrets
by, e.g., a cloud services provider. According to methods, secret data that is to be securely stored may be transmitted, along with an initialization vector, to an encryption service for encryption using a private key stored on in a remote key vault. The encrypted data can be returned and stored, in its
encrypted form, in a secure storage along with the initialization vector data. To retrieve the securely stored data, embodiments disclose retrieving the encrypted form of the data and transmitting it, along with its related initialization vector data, to the encryption service for decryption using the private key stored in the remote key vault. The decrypted data can then be made available to a requesting product service.
Velummylum et al. (US 2019/0026732 A1) discloses an aggregated storage file service. Disclosed are various embodiments of a file service. In some embodiments, a plurality of files are stored. Each of the files includes a corresponding file object identifier and a corresponding storage object identifier. A user interface comprises a single view that shows the plurality of files. A file object identifier of a particular file is mapped to a storage object identifier for the particular file. The storage object
identifier specifies a network address where a storage object of the particular file is stored. Access is provided to the particular file based at least in part on the storage object identifier.
Claims 1-20 are rejected.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Clifford Madamba whose telephone number is 571-270-1239. The examiner can normally be reached on Mon-Thu 7:30-5:00 EST Alternate Fridays.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Ryan Donlon, can be reached at 571-272-3602. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/CLIFFORD B MADAMBA/Primary Examiner, Art Unit 3692