Prosecution Insights
Last updated: August 16, 2026
Application No. 17/452,144

MALICIOUS ACTIVITY DETECTION AND REMEDIATION IN VIRTUALIZED FILE SERVERS

Non-Final OA §103
Filed
Oct 25, 2021
Priority
Oct 26, 2020 — provisional 63/105,787 +3 more
Examiner
SKHOUN, HICHAM
Art Unit
2164
Tech Center
2100 — Computer Architecture & Software
Assignee
Nutanix Inc.
OA Round
5 (Non-Final)
77%
Grant Probability
Favorable
5-6
OA Rounds
0m
Est. Remaining
82%
With Interview

Examiner Intelligence

Grants 77% — above average
77%
Career Allowance Rate
272 granted / 352 resolved
+22.3% vs TC avg
Minimal +5% lift
Without
With
+4.9%
Interview Lift
resolved cases with interview
Typical timeline
3y 2m
Avg Prosecution
24 currently pending
Career history
380
Total Applications
across all art units

Statute-Specific Performance

§101
15.5%
-24.5% vs TC avg
§103
43.9%
+3.9% vs TC avg
§102
25.3%
-14.7% vs TC avg
§112
8.7%
-31.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 352 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status 1. The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION 2. Claims 1, 3-12, 14-23, and 25-51 are pending. 3. This office action is in response to the RCE received 07/08/2026. 4. Claims 1, 12 and 23 are independent claims. 5. The office action is made Non-Final. Continued Examination under 37 CFR 1.114 6. A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 07/08/2026 has been entered. Information Disclosure Statement 7. Applicant’s IDS submissions are deemed excessive and not conforming to the best practices for IDS submissions, as detailed below. Applicant has no "duty to submit information which is not material to the patentability of any existing claim", and information is material to patentability only "when it is not cumulative to information already of record or being made of record in the application". See 37 CFR 1.56(a) & (b). Further, applicant is requested to "eliminate clearly irrelevant and marginally pertinent cumulative information [and] if a long list is submitted, highlight those documents which have been specifically brought to applicant’s attention and/or are known to be of most significance". See MPEP 2004(14). An applicant’s duty of disclosure of material information is not satisfied by presenting a patent examiner with “a mountain of largely irrelevant data from which he is presumed to have been able, with his expertise and with adequate time, to have found the critical data. It ignores the real-world conditions under which examiners work.” Rohm & Haas Co. v. Crystal Chemical Co., 722 F.2d 1556, 1573, 220 U.S.P.Q. 289 (Fed. Cir. 1983), cert. denied, 469 U.S. 851 (1984). An applicant has a duty to not just disclose pertinent prior art references but to make a disclosure in such way as not to “bury” it within other disclosures of less relevant prior art. See Golden Valley Microwave Foods Inc. v. Weaver Popcorn Co. Inc., 24 U.S.P.Q.2d 1801 (N.D. Ind. 1992); Molins PLC v. Textron Inc., 26 U.S.P.Q.2d 1889, 1899 (D. Del. 1992); Penn Yan Boats, Inc. v. Sea Lark Boats, Inc. et al., 175 U.S.P.Q. 260, 272 (S.D. Fl. 1972). MPEP 609 states that "consideration by the examiner of the information submitted in an IDS means nothing more than considering the documents in the same manner as other documents in Office search files are considered by the examiner while conducting a search of the prior art in a proper field of search." Because applicant did not submit any explanatory remarks along with the IDS which provide an indication of how the IDS submissions are "material to the patentability of any existing claim" nor did applicant “highlight those documents [having the] most significance", given the volume of the submissions, the examiner has conducted only a cursory review and has not reviewed the documents thoroughly or in any particularized or individualized detail. Applicant is invited and requested to submit explanatory remarks “highlighting” those portion(s) of the document(s) that are of particular relevancy to the "patentability of any existing claim". By signing the accompanying 1449 forms, Examiner is merely acknowledging the submission of the cited references and indicating that only a cursory review has been made. Finally, applicant should further note that nothing in this section is intended by the examiner to indicate a requirement for information for information under 37 CFR 1.105, but applicant is otherwise required to conform to other rules, requirements, and best practices regarding the submission of IDS documents, as noted above. Examiner Note 8. The Examiner cites particular columns and line numbers in the references as applied to the claims below for the convenience of the Applicant(s). Although the specified citations are representative of the teachings in the art and are applied to the specific limitations within the individual claim, other passages and figures may apply as well. It is respectfully requested that, in preparing responses, the Applicant fully consider the references in their entirety as potentially teaching all or part of the claimed invention, as well as the context of the passage as taught by the prior art or disclosed by the Examiner. Claim Rejections - 35 USC § 103 9. In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. 10. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: a) A patent may not be obtained through the invention is not identically disclosed or described as set forth in section 102 of this title, if the differences between the subject matter sought to be patented and the prior art are such that the subject matter as a whole would have been obvious at the time the invention was made to a person having ordinary skill in the art to which said subject matter pertains. Patentability shall not be negatived by the manner in which the invention was made. 11. Claims 1, 3-12, 14-23, and 25-51 are rejected under 35 U.S.C.103 as being unpatentable over BEDHAPUDI et al (US 20190109870 A1) hereinafter as BEDHAPUDI in view of Gopalapura Venkatesh et al (US 20170235950 A1) hereinafter as Gopalapura. BEDHAPUDI et al (US 20190109870 A1) was cited in the IDS received 07/08/2026 US Patent Pub Row 9. 12. Regarding claims 1, 3-11, 34-35, 40-41, 46 and 49 those claims recite at least one non-transitory tangible computer readable medium encoded with instructions which, when executed, cause a system to performs the method of claims 23, 25-33, 38-39, 44-45, 48 and 51 respectively and are rejected under the same rationale. 13. Regarding claims 12, 14-22, 36-37, 42-43, and 47 and 50, those claims recite system performs the method of claims 23, 25-33, 38-39, 44-45, 48 and 51 respectively and are rejected under the same rationale. 14. Regarding claim 23, BEDHAPUDI teaches A method comprising: accessing one or more file operation events for a file in a distributed file server ([0285], “Ransomware typically involves an input/output (I/O) heavy process of encrypting data files and/or deleting or renaming the original files. one type of file system operation that may be used to distinguish harmful ransomware from other harmless applications is file renaming.”, Fig 5, step 502, “Monitor I/O access pattern”, [0291], “the filter driver 314 may intercept data modification operations that include changes, updates, and/or new information (e.g., file creation, file deletion, file modification, file renaming, etc.) with respect to one or more of the application(s) 310.”, [0307], “monitors the I/O access of one or more processes running on the client computing device 302, the file system operations may include file creations, modifications, deletes, renames, writes, overwrites, to name a few.”), the one or more file operation events stored in a datastore (Fig 1C, [0099], “storage manager 140 with management database 146 storing file/system operations events”), and wherein the distributed file server hosts files, including the file, distributed across multiple computing nodes comprising a first computing node and a second computing node (Fig 1A, [0071], “distributed file system”, [0253]); determine the one or more file operation events for the file are indicative of malicious activity based on comparing the one or more file operation events for the file to one or more patterns of file server events associated with malicious activity ([0004], “The software module records the number of times the files in the file system are modified, created, deleted, and/or renamed (file operation events for the file). The recorded number is compared against a threshold. If the number exceeds the threshold (one or more patterns of file server events associated with malicious activity), the software module provides an alert to the user of the client machine that the client machine may be under a ransomware attack.”, Fig 5, step 508, “Anomaly detected?”, [0299], “Ransomware I/O Access Patterns”, [0302], “Based on these I/O access patterns (e.g., high number of renames, renames to known ransomware extensions, high number of writes with high entropy value data buffers, high number of deletes, etc.), the anomaly detection engine 320 may determine that the client computing device 302 may be under attack”, [0305], “identifying patterns that could be used to differentiate regular I/O access from ransomware I/O access.”, Fig 5, steps 504-506-508, [0308], “At block 504, the filter driver 314 generates process contexts based on the I/O access.”, [0309], “At block 506, the filter driver 314 compares the process contexts to a threshold for detecting a file activity anomaly.”, [0310], “thresholds (one or more patterns of file server events associated with malicious activity)”, [0311], “At block 508, the filter driver 314 determines, based on the comparison, whether a file activity anomaly is detected. For example, upon determining that the number of renames is greater than the baseline number of renames associated with the client computing device 302 by 10% (patterns of file server events), the filter driver 314 may determine that the rename operations (file operation events for the file) qualify as a file activity anomaly.”), identifying at least one affected file in the distributed file server, the at least one affected file being at least partially compromised by the detected malicious activity ([0084], “Primary data 112 stored on primary storage devices 104 may be compromised in some cases, such as when an employee deliberately or accidentally deletes or overwrites primary data 112.”, [0317], “a file is infected by TorrentLocker can be determined by checking the MIME type of the file.”, [0363], “the client computing device 302 identifies a portion of the file system 316 (or a portion of the primary data 324) affected by the potential ransomware attack, and restores only a portion of the backup copy that corresponds to the affected portion of the file system 316 (or the primary data 324).”); and implicitly teaches recovering a share of the distributed file server including the at least one affected file, comprising: replacing the at least one affected file with a stored version of the at least one affected file from a snapshot of the share taken prior to the detected malicious activity, the snapshot of the share comprising a first portion at the first computing node and a second portion at the second computing node ([0084], [0104], “initiating restore and recovery operations”, [0158], “For block-level backups, files are broken into constituent blocks, and changes are tracked at the block level. Upon restore, system 100 reassembles the blocks into files in a transparent fashion”, [0168], “restore primary data 112 from a snapshot taken at a given point in time”, [0363], “performs a point-in-time restore to cause at least a portion of the file system 316 to be in a state prior to the time specified by the recorded timestamp…identifies a portion of the file system 316 (or a portion of the primary data 324) affected by the potential ransomware attack, and restores only a portion of the backup copy that corresponds to the affected portion of the file system 316 (or the primary data 324).”). However, Gopalapura explicitly teaches recovering a share of the distributed file server including the at least one affected file, comprising: replacing the at least one affected file with a stored version of the at least one affected file from a snapshot of the share taken prior to the detected malicious activity, the snapshot of the share comprising a first portion at the first computing node and a second portion at the second computing node ([0008], “a virtualized file server (VFS) self-healing system may automatically identify data corruption and perform data recovery operations at multiple levels in the storage hierarchy, including the file level, filesystem level, and storage level.”, [0009], identify corrupted or infected data and recover a consistent version of the data from a VFS. Data may be infected by a virus or corrupted by a file system or storage system failure, for example. A distributed self-healing mechanism of the VFS may frequently take snapshots of file system and storage pools, and may monitor the user data at file system and storage system levels. [232-238], a virtualized file server that runs across multiple host machines and presents storage to users as one shared namespace. The file server is split into multiple file server virtual machines, or FSVMs, each of which handles I/O for the data stored on its host or associated storage. The system also includes a self-healing feature that watches for corrupted data and tries to repair it automatically. Corruption can be detected at different levels, including a file, an entire filesystem, or a storage unit such as a volume group., [239-240], When the system finds bad data, it causes the FSVM that hosts that data, or another FSVM taking over for it, to recover the affected unit from a snapshot or backup. [238], The disclosure says this monitoring and recovery can be done in parallel across the cluster so that one problem does not stop the whole file service.). It would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to incorporate the concept of teachings suggested in Gopalapura’s system into BEDHAPUDI’s and by incorporating Gopalapura into BEDHAPUDI because both systems are related to file servers in virtualized environments would provide a virtualized file server (VFS) self-healing system may automatically identify data corruption and perform data recovery operations at multiple levels in the storage hierarchy, including the file level, filesystem level, and storage level (Gopalapura Venkatesh, [0008]). 15. Regarding claim 25, BEDHAPUDI and Gopalapura teach the invention as claimed in claim 23 above and further BEDHAPUDI teaches wherein determining the one or more file operation events for the file indicative of malicious activity comprises comparing a file entropy measurement of a file of the distributed file server to a threshold file entropy measurement ([0299], “The ransomware may rewrite the selected files with high entropy buffers (e.g., encryption). For example, the filter driver 314 may determine the entropy difference in the data buffers before and after the write.”, [0304], [0308], [0311], [0317]). 16. Regarding claim 26, BEDHAPUDI and Gopalapura teach the invention as claimed in claim 23 above and further BEDHAPUDI updating criteria indicating malicious activity based on a characteristic of the at least one affected file ([0084], [0303], [0317]). 17. Regarding claim 27, BEDHAPUDI and Gopalapura teach the invention as claimed in claim 23 above and further BEDHAPUDI wherein recovering the share of the distributed file server comprises retrieving a first portion of the snapshot of the share from the first computing node of the multiple computing nodes and a second portion of the snapshot of the share from the second computing node of the multiple computing nodes ([0084], [0104], “initiating restore and recovery operations”, [0158], “For block-level backups, files are broken into constituent blocks, and changes are tracked at the block level. Upon restore, system 100 reassembles the blocks into files in a transparent fashion”, [0168], “restore primary data 112 from a snapshot taken at a given point in time”, [0363], “performs a point-in-time restore to cause at least a portion of the file system 316 to be in a state prior to the time specified by the recorded timestamp…identifies a portion of the file system 316 (or a portion of the primary data 324) affected by the potential ransomware attack, and restores only a portion of the backup copy that corresponds to the affected portion of the file system 316 (or the primary data 324).”). Also, Gopalapura teaches the limitation at ([0009], identify corrupted or infected data and recover a consistent version of the data from a VFS. Data may be infected by a virus or corrupted by a file system or storage system failure, for example. A distributed self-healing mechanism of the VFS may frequently take snapshots of file system and storage pools, and may monitor the user data at file system and storage system levels. [232-238], a virtualized file server that runs across multiple host machines and presents storage to users as one shared namespace. The file server is split into multiple file server virtual machines, or FSVMs, each of which handles I/O for the data stored on its host or associated storage. The system also includes a self-healing feature that watches for corrupted data and tries to repair it automatically. Corruption can be detected at different levels, including a file, an entire filesystem, or a storage unit such as a volume group., [239-240], When the system finds bad data, it causes the FSVM that hosts that data, or another FSVM taking over for it, to recover the affected unit from a snapshot or backup. [238], The disclosure says this monitoring and recovery can be done in parallel across the cluster so that one problem does not stop the whole file service.). 18. Regarding claim 28, BEDHAPUDI and Gopalapura teach the invention as claimed in claim 23 above and further BEDHAPUDI updating a file blocking policy of the distributed file server based on the one or more file operation events for the file associated with the malicious activity ([0168], “Users in some cases gain read-only access to the record of files and directories of the snapshot. By electing to restore primary data 112 from a snapshot taken at a given point in time, users may also return the current file system to the state of the file system that existed when the snapshot was taken.”, [0319], “processes or applications other than that performing the file activity anomaly detection may have read-only access to the local database. In some embodiments, the filter driver 314 blocks any I/O requests to the local database originating from an unknown process or application. In some cases, the database is not local and is remotely located from the client computing device 302.”, [0342]). Also, Gopalapura teaches the limitation at ([0237], “the FSVM leader may make all filesystems for that share across FSVMs read-only to respect the storage quota limit.”). 19. Regarding claim 29, BEDHAPUDI and Gopalapura teach the invention as claimed in claim 23 above and further BEDHAPUDI generating a report of the malicious activity including the at least one affected file and the share including the at least one affected file (Fig 15, [0324], [0123], [0191], [0202]). Also, Gopalapura teaches the limitation at ([0154], “a file on the existing FSVM 1203a named Report.doc in the directory \Office\HR of a share 1204a may be transferred to the new FSVM 1209a and stored in the directory \ HR of a share 1210a on the new FSVM 1209a or in a different directory on the new FSVM 1209a, e.g., \HumanResources. The file name may remain the same on the new FSVM 1209a, e.g., Report.doc”, [0278]). 20. Regarding claim 30, BEDHAPUDI and Gopalapura teach the invention as claimed in claim 23 above and further Gopalapura wherein recovering the share of the distributed file server including the at least one affected file comprises: deleting the at least one affected file from the share; and copying the stored version of the at least one file from the snapshot of the share to the share ([0068], “Upon determining that a file is to be moved, VFS 202 may change the location of the file by, for example, copying the file from its existing location(s), such as local storage 122a of a host machine 201a, to its new location(s), such as local storage 122b of host machine 201b (and to or from other host machines, such as local storage 122c of host machine 201c if appropriate), and deleting the file from its existing location(s). Write operations on the file may be blocked or queued while the file is being copied, so that the copy is consistent. The VFS 202 may also redirect storage access requests for the file from an FSVM 170a at the file's existing location to a FSVM 170b at the file's new location.”). 21. Regarding claim 31, BEDHAPUDI and Gopalapura teach the invention as claimed in claim 23 above and further BEDHAPUDI restricting access to the at least one affected file in the distributed file server prior to recovering the share of the distributed file server including the at least one affected file ([0168], “Users in some cases gain read-only access to the record of files and directories of the snapshot. By electing to restore primary data 112 from a snapshot taken at a given point in time, users may also return the current file system to the state of the file system that existed when the snapshot was taken.”, [0319], “processes or applications other than that performing the file activity anomaly detection may have read-only access to the local database. In some embodiments, the filter driver 314 blocks any I/O requests to the local database originating from an unknown process or application. In some cases, the database is not local and is remotely located from the client computing device 302.”, [0342]). Also, Gopalapura teaches the limitation at ([0196], [0202]). 22. Regarding claim 32, BEDHAPUDI and Gopalapura teach the invention as claimed in claim 23 above and further BEDHAPUDI wherein the detected malicious activity is a ransomware attack ([0004], “the software module provides an alert to the user of the client machine that the client machine may be under a ransomware attack.”, Fig 5, step 508, “Anomaly detected?”, [0299], “Ransomware I/O Access Patterns”, [0302], [0305], “identifying patterns that could be used to differentiate regular I/O access from ransomware I/O access.”, Fig 5, steps 504-506-508, [0308]). 23. Regarding claim 33, BEDHAPUDI and Gopalapura teach the invention as claimed in claim 23 above and further BEDHAPUDI wherein the snapshot of the share is an immutable snapshot ([0168], “Users in some cases gain read-only access to the record of files and directories of the snapshot. By electing to restore primary data 112 from a snapshot taken at a given point in time, users may also return the current file system to the state of the file system that existed when the snapshot was taken.”, [0319], “processes or applications other than that performing the file activity anomaly detection may have read-only access to the local database. In some embodiments, the filter driver 314 blocks any I/O requests to the local database originating from an unknown process or application. In some cases, the database is not local and is remotely located from the client computing device 302.”, [0342]). Also, Gopalapura teaches the limitation at ([0237], “the FSVM leader may make all filesystems for that share across FSVMs read-only to respect the storage quota limit.”). 24. Regarding claim 38, BEDHAPUDI and Gopalapura teach the invention as claimed in claim 23 above and further BEDHAPUDI wherein said determining the one or more file operation events for the file in the distributed file server are indicative of malicious activity is performed by an analytics virtual machine (AVM), and wherein said recovering the share of the distributed file server comprises mounting a snapshot of the share comprising a snapshot of the affected file of the share by the AVM ([0070], [0087]). Also, Gopalapura teaches the limitation at ([0046], [0072], “The VFS 202 may facilitate I/O operations between a user VM 105 and a virtualized filesystem. The virtualized filesystem may appear to the user VM 105 as a namespace of mappable shared drives or mountable network filesystems of files and directories.”, [0279]). 25. Regarding claim 39, BEDHAPUDI and Gopalapura teach the invention as claimed in claim 23 above and further BEDHAPUDI wherein said determining the one or more file operation events for the file are indicative of malicious activity comprises interfacing with multiple computing nodes of the distributed file server (Fig 1A, [0071], “distributed file system”, [0253]). Also, Gopalapura teaches the limitation at ([0043], Fig 22, “recovering from multi-node file service failures in a virtualized file server.”). 26. Regarding claim 44, BEDHAPUDI and Gopalapura teach the invention as claimed in claim 23 above and further BEDHAPUDI responsive to identifying the at least one affected file, modifying access to the affected file, the modifying comprising changing the affected file to read only for users of the distributed file server while maintaining unmodified access to the remainder of the share comprising the affected file ([0168], “Users in some cases gain read-only access to the record of files and directories of the snapshot. By electing to restore primary data 112 from a snapshot taken at a given point in time, users may also return the current file system to the state of the file system that existed when the snapshot was taken.”, [0319], “processes or applications other than that performing the file activity anomaly detection may have read-only access to the local database. In some embodiments, the filter driver 314 blocks any I/O requests to the local database originating from an unknown process or application. In some cases, the database is not local and is remotely located from the client computing device 302.”, [0342]). 27. Regarding claim 45, BEDHAPUDI and Gopalapura teach the invention as claimed in claim 23 above and further BEDHAPUDI responsive to identifying the at least one affected file, modifying access to the affected file, the modifying comprising changing the affected file to read only for users associated with the one or more file server events indicative of malicious activity ([0168], “Users in some cases gain read-only access to the record of files and directories of the snapshot. By electing to restore primary data 112 from a snapshot taken at a given point in time, users may also return the current file system to the state of the file system that existed when the snapshot was taken.”, [0319], “processes or applications other than that performing the file activity anomaly detection may have read-only access to the local database. In some embodiments, the filter driver 314 blocks any I/O requests to the local database originating from an unknown process or application. In some cases, the database is not local and is remotely located from the client computing device 302.”, [0342]). 28. Regarding claim 48, BEDHAPUDI and Gopalapura teach the invention as claimed in claim 23 above and further BEDHAPUDI wherein the one or more file operation events for the file comprise an open operation, a read operation, a write operation, a rename operation, or combinations thereof ([0285], “Ransomware typically involves an input/output (I/O) heavy process of encrypting data files and/or deleting or renaming the original files. one type of file system operation that may be used to distinguish harmful ransomware from other harmless applications is file renaming.”, Fig 5, step 502, “Monitor I/O access pattern”, [0291], “the filter driver 314 may intercept data modification operations that include changes, updates, and/or new information (e.g., file creation, file deletion, file modification, file renaming, etc.) with respect to one or more of the application(s) 310.”, [0307], “monitors the I/O access of one or more processes running on the client computing device 302, the file system operations may include file creations, modifications, deletes, renames, writes, overwrites, to name a few.”). Also, Gopalapura teaches the limitation at ([0063], “such as operations to list folders and files in a specified folder, create a new file or folder, open an existing file for reading or writing, and read data from or write data to a file, as well as storage item manipulation operations to rename, delete, copy, or get details, such as metadata, of files or folders. Note that folders may also be referred to herein as “directories.”, [0107]). 29. Regarding claim 51, BEDHAPUDI and Gopalapura teach the invention as claimed in claim 23 above and further BEDHAPUDI accessing an event log based at least in part on an analysis of one or more snapshots of the distributed file server, wherein the event log comprises event data records and metadata, to access the one or more file operation events for the file in the distributed file server indicative of malicious activity ([0236], “file system data (e.g., regular files, file tables, mount points, etc.), operating system data (e.g., registries, event logs, etc.), and the like.”, see also Fig 1C, [0099], “storage manager 140 with management database 146 storing file/system operations events”). Also, Gopalapura teaches the limitation at ([0009], [0239], “Data loss may be identified automatically by, for example, checking logs that record data write operations. Data loss and corruption may also be identified by detecting events that may lead to corrupted or lost data, such as storage device disconnections, read or write error, power failures, and so on.”). CONCLUSION Any inquiry concerning this communication or earlier communications from the examiner should be directed to HICHAM SKHOUN whose telephone number is (571)272-9466. The examiner can normally be reached Normal schedule: Mon-Fri 10am-6:30pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Amy Ng can be reached at 5712701698. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /HICHAM SKHOUN/Primary Examiner, Art Unit 2164
Read full office action

Prosecution Timeline

Show 14 earlier events
Nov 14, 2025
Response Filed
Dec 01, 2025
Final Rejection mailed — §103
Feb 27, 2026
Notice of Allowance
Apr 24, 2026
Response after Non-Final Action
May 10, 2026
Response after Non-Final Action
Jul 08, 2026
Request for Continued Examination
Jul 09, 2026
Response after Non-Final Action
Jul 23, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12705225
Compaction of Documents in a High Density Data Storage System
1y 4m to grant Granted Aug 11, 2026
Patent 12687979
OFFLOADING DATA COMPRESSION DURING RESTORES TO A DATA PROCESSING UNIT IN A DEDUPLICATION BACKUP SYSTEM
3y 3m to grant Granted Jul 21, 2026
Patent 12681991
PROACTIVE DETERMINATION OF DATA INSIGHTS
2y 6m to grant Granted Jul 14, 2026
Patent 12682008
TECHNIQUES TO EMBED A DATA OBJECT INTO A MULTIDIMENSIONAL FRAME
2y 5m to grant Granted Jul 14, 2026
Patent 12681989
INFORMATION PROCESSING APPARATUS, INFORMATION PROCESSING METHOD, AND INFORMATION PROCESSING COMPUTER PROGRAM PRODUCT
2y 1m to grant Granted Jul 14, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
77%
Grant Probability
82%
With Interview (+4.9%)
3y 2m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 352 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month