Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
1. This action is in response to the amendment and argument field on 2 June 2026.
2. Claims 1, 16 and 20 have been amended.
3. Claims 1-20 remain Pending and Rejected.
Responses to the Argument
4. The applicant’s arguments filed on 2 June 2026 are moot in view of new ground of rejection rendered.
Claim Rejections - 35 USC § 103
5. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-20 are rejected under 35 U.S.C §103 as being unpatentable over Sapir et al. (US Publication No. 20250126145), hereinafter Sapir and in view of Applegate-Swanson (US Publication No. 20210281610), hereinafter Applegate-Swanson.
Regarding claim 1:
determining a plurality of permissions associated with a user (Sapir, abstract), wherein IHS to: obtain a plurality of resource risk weights of a respective plurality of resources, and a plurality of access permissions of a user for the respective plurality of resources and generate based, at least in part, on the plurality of resource risk weights and the plurality of access permissions of the user.
determining a corresponding risk associated with each of the plurality of permissions (Sapir, ¶9-10, FIG.2), wherein, IHS to: determine a plurality of access risks for the user with respect to the respective plurality of resources; and generate the risk score for the user based, at least in part, on the mean or median of the plurality of access risks for the user.
determining an aggregate risk associated with the plurality of permissions associated with the user as a whole to generate an identity risk based on the determined corresponding risk associated with each of the plurality of permissions (Sapir, ¶12, ¶71), wherein generating the risk score for the user further includes: generating based, at least in part, on the plurality of access permissions of the user, a plurality of permission factors, where an individual permission factor includes an integer number representing a type of access permission of the user for a respective resource of the plurality of resources; determining a plurality of access risks for the user with respect to the respective plurality of resources, where an individual access risk of the plurality of access risks is determined by multiplying a resource risk weight
determining which of the plurality of permissions are used by the user to generate a determined use (Sapir, ¶62), wherein RBAC is designed to simplify access control administration, improve security, and support least privilege principles. For RBAC, users are typically assigned permissions based on their role or job function within an organization. These permissions determine what actions a user can take within the system, such as reading, writing, or executing certain files.
Sapir explicitly suggest, and configuring one or more roles for the user based on the identity risk generated based on the determined corresponding risk associated with each of the plurality of permissions associated with the user and the determined use; however, in a same field of endeavor Applegate-Swanson discloses this limitation (Applegate-Swanson, ¶53, ¶56, ¶68-72),
updating the plurality of permissions associated with the user based on the one or more roles configured for the user; and storing the one or more roles configured for the user in a memory (Sapir, ¶88)
It would have been obvious to one of ordinary skill in the art at the time the invention was filed to include the method of role-based identity risk determination of Sapir with the combining risk score generation disclosed in Applegate-Swanson to improve security by modifying existing policies, stated by Applegate-Swanson at ¶9.
Regarding claim 2:
wherein determining the plurality of permissions associated with user includes identifying the one or more roles associated with user (Sapir, ¶62).
Regarding claim 3:
wherein determining the corresponding risk associated with each of the plurality of permissions includes determining a corresponding blast impact (Sapir, ¶10).
Regarding claim 4:
wherein determining the corresponding blast impact includes evaluating a set of attributes associated with a permission of the plurality of permissions (Sapir, ¶65).
Regarding claim 5:
wherein the set of attributes includes a type of access granted by the permission, a sensitive of the data or resources accessible through the permission, a potential for privilege escalation, and/or a breadth of resource exposure associated with the permission (Sapir, ¶74-75).
Regarding claim 6:
wherein determining a corresponding risk associated with each of the plurality of permissions includes determining a corresponding scope of access for each of the plurality of permissions (Sapir, ¶12).
Regarding claim 7:
wherein the determined corresponding risk associated with each of the plurality of permissions is a contextualized permission risk (Sapir, ¶78).
Regarding claim 8:
wherein the contextualized permission risk is a value that is normalized with respect to a scale (Sapir, ¶90).
Regarding claim 9:
wherein configuring the one or more roles for the user includes applying a least standing privilege (Sapir, ¶78, ¶62).
Regarding claim 10:
wherein configuring the one or more roles for the user includes configuring at least one permission associated with the one or more roles for just-in-time access (Sapir, ¶66).
Regarding claim 11:
further comprising aggregating corresponding identity risk scores associated with a plurality of users into an account-level risk (Sapir, ¶64).
Regarding claim 12:
further comprising, for a plurality of accounts, aggregating corresponding account-level risk into a provider risk (Sapir, ¶77, ¶91).
Regarding claim 13:
further comprising, for a plurality of providers, aggregating corresponding provider risk into a tenant risk (Sapir, ¶83).
Regarding claim 14:
further comprising generating outputs for prioritization and remediation based on one or more of the identity risk, the account-level risk, the provider risk, and/or the tenant risk (Sapir, ¶67).
Regarding claim 15:
Sapir does not explicitly suggest, wherein determining the aggregate risk associated with the plurality of permissions includes: deduplicating permission that are accessible to the user through multiple roles within a same scope such that a duplicate permission does not increase the aggregate risk; and treating permissions available across different scopes as separate contributions to the aggregate risk; however, in a same field of endeavor Applegate-Swanson teaches this limitation (Applegate-Swanson, ¶67-68).
Same motivation for combining the respective features of Sapir and Applegate-Swanson applies herein, as discussed in the rejection of claim 1.
Regarding claim 16:
determine a plurality of permissions associated with a user (Sapir, abstract), wherein IHS to: obtain a plurality of resource risk weights of a respective plurality of resources, and a plurality of access permissions of a user for the respective plurality of resources and generate based, at least in part, on the plurality of resource risk weights and the plurality of access permissions of the user.
determine a corresponding risk associated with each of the plurality of permissions (Sapir, ¶9-10, FIG.2), wherein, IHS to: determine a plurality of access risks for the user with respect to the respective plurality of resources; and generate the risk score for the user based, at least in part, on the mean or median of the plurality of access risks for the user.
determine an aggregate risk associated with the plurality of permissions associated with the user as a whole to generate an identity risk based on the determined corresponding risk associated with each of the plurality of permissions (Sapir, ¶12, ¶71), wherein generating the risk score for the user further includes: generating based, at least in part, on the plurality of access permissions of the user, a plurality of permission factors, where an individual permission factor includes an integer number representing a type of access permission of the user for a respective resource of the plurality of resources; determining a plurality of access risks for the user with respect to the respective plurality of resources, where an individual access risk of the plurality of access risks is determined by multiplying a resource risk weight
determining which of the plurality of permissions are used by the user to generate a determined use (Sapir, ¶62), wherein RBAC is designed to simplify access control administration, improve security, and support least privilege principles. For RBAC, users are typically assigned permissions based on their role or job function within an organization. These permissions determine what actions a user can take within the system, such as reading, writing, or executing certain files.
Sapir explicitly suggest, and configuring one or more roles for the user based on the identity risk generated based on the determined corresponding risk associated with each of the plurality of permissions associated with the user and the determined use; however, in a same field of endeavor Applegate-Swanson discloses this limitation (Applegate-Swanson, ¶53, ¶56, ¶68-72),
updating the plurality of permissions associated with the user based on the one or more roles configured for the user; and storing the one or more roles configured for the user in a memory (Sapir, ¶88).
and a memory coupled to the processor and configured to provide the processor with instructions (Sapir, ¶6).
It would have been obvious to one of ordinary skill in the art at the time the invention was filed to include the method of role-based identity risk determination of Sapir with the combining risk score generation disclosed in Applegate-Swanson to improve security by modifying existing policies, stated by Applegate-Swanson at ¶9.
Regarding claim 17:
wherein to determine the plurality of permissions associated with user, the processor is further configured to identify the one or more roles associated with user (Sapir, ¶62).
Regarding claim 18:
wherein to determine the corresponding risk associated with each of the plurality of permissions, the processor is further configured to determine a corresponding blast impact (Sapir, ¶10).
Regarding claim 19:
wherein to determine the corresponding blast impact, the processor is further configured to evaluate a set of attributes associated with a permission of the plurality of permissions (Sapir, ¶65).
Regarding claim 20:
determining a plurality of permissions associated with a user (Sapir, abstract), wherein IHS to: obtain a plurality of resource risk weights of a respective plurality of resources, and a plurality of access permissions of a user for the respective plurality of resources and generate based, at least in part, on the plurality of resource risk weights and the plurality of access permissions of the user.
determining a corresponding risk associated with each of the plurality of permissions (Sapir, ¶9-10, FIG.2), wherein, IHS to: determine a plurality of access risks for the user with respect to the respective plurality of resources; and generate the risk score for the user based, at least in part, on the mean or median of the plurality of access risks for the user.
determining an aggregate risk associated with the plurality of permissions associated with the user as a whole to generate an identity risk based on the determined corresponding risk associated with each of the plurality of permissions (Sapir, ¶12, ¶71), wherein generating the risk score for the user further includes: generating based, at least in part, on the plurality of access permissions of the user, a plurality of permission factors, where an individual permission factor includes an integer number representing a type of access permission of the user for a respective resource of the plurality of resources; determining a plurality of access risks for the user with respect to the respective plurality of resources, where an individual access risk of the plurality of access risks is determined by multiplying a resource risk weight
determining which of the plurality of permissions are used by the user to generate a determined use (Sapir, ¶62), wherein RBAC is designed to simplify access control administration, improve security, and support least privilege principles. For RBAC, users are typically assigned permissions based on their role or job function within an organization. These permissions determine what actions a user can take within the system, such as reading, writing, or executing certain files.
Sapir explicitly suggest, and configuring one or more roles for the user based on the identity risk generated based on the determined corresponding risk associated with each of the plurality of permissions associated with the user and the determined use; however, in a same field of endeavor Applegate-Swanson discloses this limitation (Applegate-Swanson, ¶53, ¶56, ¶68-72),
updating the plurality of permissions associated with the user based on the one or more roles configured for the user; and storing the one or more roles configured for the user in a memory (Sapir, ¶88)
It would have been obvious to one of ordinary skill in the art at the time the invention was filed to include the method of role-based identity risk determination of Sapir with the combining risk score generation disclosed in Applegate-Swanson to improve security by modifying existing policies, stated by Applegate-Swanson at ¶9.
Conclusion
6. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action.
The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure (See form “PTO-892 Notice of reference cited).
Any inquiry concerning this communication or earlier communications from the examiner should be directed to MONJUR RAHIM whose telephone number is (571)270-3890.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Shewye Gelagay can be reached on 571-272-4219. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/Monjur Rahim/
Patent Examiner
United States Patent and Trademark Office
Art Unit: 2436; Phone: 571.270.3890
E-mail: monjur.rahim@uspto.gov
Fax: 571.270.4890