Prosecution Insights
Last updated: October 02, 2026
Application No. 17/858,974

SYSTEMS AND METHODS FOR LIMITING OPERATIONS ON DOCUMENTS AT AN EXTERNAL SYSTEM

Non-Final OA §103
Filed
Jul 06, 2022
Priority
Jul 07, 2017 — provisional 62/529,617 +1 more
Examiner
BLACK, LINH
Art Unit
2163
Tech Center
2100 — Computer Architecture & Software
Assignee
Open Text Corporation
OA Round
5 (Non-Final)
50%
Grant Probability
Moderate
5-6
OA Rounds
7m
Est. Remaining
61%
With Interview

Examiner Intelligence

Grants 50% of resolved cases
50%
Career Allowance Rate
226 granted / 448 resolved
-4.6% vs TC avg
Moderate +11% lift
Without
With
+10.6%
Interview Lift
resolved cases with interview
Typical timeline
4y 10m
Avg Prosecution
21 currently pending
Career history
481
Total Applications
across all art units

Statute-Specific Performance

§101
12.2%
-27.8% vs TC avg
§103
66.9%
+26.9% vs TC avg
§102
16.4%
-23.6% vs TC avg
§112
2.7%
-37.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 448 resolved cases

Office Action

§103
DETAILED ACTION Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 1/23/2026 has been entered. Claims 1-21 are pending in the application. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Arguments Regarding the Applicant argued on page 8 of the Remarks that “none of the cited disclosure of Caffary teaches "the external system operating in a cloud computing environment that is separate from and external to the enterprise computing environment" (users' items and copies of these items are both stored on cloud drives, and there is no separation of an external cloud computing environment for storing the copies from an enterprise environment that is behind a firewall and stores the original items)” and “wherein the content server manages privileges of internal users in the enterprise computing environment on the item and wherein the external system independently manages sharing of the copy of the item among users of the external system”, examiner respectfully disagrees. Caffary teaches at para. 6, 25: the user-defined attributes can be used to lock-down the file to a home network, e.g., as defined based on a predetermined set of user-profiles and/or devices, such that the corresponding security token thwarts any access attempt from outside of the home network. In addition, if a user intends to share a file that is stored in the user's cloud drive, a copy of the file is stored in a secondary cloud drive that other authorized users may access. If a particular file is shared with read-write permissions (e.g., for collaborative purposes), any changes made to the copy of the file stored in the secondary cloud drive is not merged with the master copy stored in the primary cloud drive unless the user of the primary cloud drive approves of the changes. This may provide the user with a flexible tool for controlling access to his/her files, while also reducing the chances of accidental or unauthorized changes to the master copy of the file. Such multi-layer security may allow for a robustly secure system for sharing files stored on massively distributed storage systems such as cloud drives; para. 28-30: storing data on cloud drives host–ed on remote storage devices may allow easy sharing of data with multiple users. For example, if a user intends to share a file stored on the primary cloud drive 205, a copy of the file is copied or mirrored in the corresponding secondary cloud drive 210 for the sharing. Subject to the user's permission, files from one or more external cloud drives 215 may be stored on the user's secondary cloud drive 210; fig. 2A: the enterprise cloud drive 220 is associated with an external cloud drive 215. Thus, the external cloud drive 215 is separate and external to the enterprise cloud drives 220 – See para. 33: each hosted cloud drive associated with a user can therefore be configured as a private network, which, under an enterprise domain, may be linked to one or more administrator accounts. The mirroring or copying of content from the users' cloud drives 205 to the enterprise cloud drives 220 may be subject to approval from the administrators. This may also be extended, for example, to third-parties that engage with the enterprise domain, for example, to control undesirable content from the third parties to infiltrate the enterprise network. Dorman further teaches in fig. 2: Enterprise Organizational Setting with workspaces; para. 22: client that is connected with a collaboration environment including a cloud-based platform (e.g., cloud-based file sharing, collaboration, and/or storage platform/service) and runs on a client device to synchronize folders and files between the collaboration environment and the user device; para. 55: display an icon to indicate whether a folder or a file is shared (collaborative) or private, whether it is locked (checked out) or unlocked, and whether it is already synchronized etc.; para. 68-59: the network interface device can include a firewall which can govern and/or manage permission to access/proxy data in a computer network and track varying levels of trust between different machines and/or applications. Thus, deploying a firewall on a network helps block unauthorized access to businesses/enterprise’s devices. The combination of references does teach the argued limitations. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-21 is/are rejected under 35 U.S.C. 103 as being unpatentable over Caffary (US 20190109857) in view of Dorman et al. (US 20140201138). As per claims 1, 8, 15, Caffary teaches a method for content management, comprising: receiving, by a content server running on a server machine, an indication to lock an item managed by the content server, the item stored in a repository managed by the content server in an enterprise computing environment wherein the indication to lock the item is received from within the enterprise computing environment (para. 4-5: receiving information about an electronic file stored on a primary cloud drive of a user, and receiving one or more user-defined attributes associated with the electronic file. The one or more user-defined attributes are indicative of a home network associated with the electronic file; generate, based on the one or more user-defined attributes, a security token that is configured to control access to the electronic file based on whether the access is from within or outside of the home network, and store a copy of the electronic file on a secondary cloud drive separate from the primary cloud drive. The copy of the electronic file is stored on the secondary cloud drive in association with the security token; para. 33: the mirroring or copying of content from the users' cloud drives to the enterprise cloud drives may be subject to approval from the administrators. This may also be extended, for example, to third-parties that engage with the enterprise domain, for example, to control undesirable content from the third parties to infiltrate the enterprise network. The files may be allowed to be mirrored or copied onto the enterprise cloud drives upon satisfying one or more criteria set by the enterprise administrators; para. 38, 44); based on the indication to lock the item managed by the content server: locking, by the content server, the item to prevent editing of the item; locking, by the content server, a copy of the item managed by an external system to prevent editing of the copy of the item (para. 25: the user-defined attributes can be used to lock-down the file to a home network, e.g., as defined based on a predetermined set of user-profiles and/or devices, such that the corresponding security token thwarts any access attempt from outside of the home network. In addition, if a user intends to share a file that is stored in the user's cloud drive, a copy of the file is stored in a secondary cloud drive that other authorized users may access. If a particular file is shared with read-write permissions (e.g., for collaborative purposes), any changes made to the copy of the file stored in the secondary cloud drive is not merged with the master copy stored in the primary cloud drive unless the user of the primary cloud drive approves of the changes. This may provide the user with a flexible tool for controlling access to his/her files, while also reducing the chances of accidental or unauthorized changes to the master copy of the file. Such multi-layer security may allow for a robustly secure system for sharing files stored on massively distributed storage systems such as cloud drives; para. 31, 33-35: in response to receiving an indication of the sharing of the access key, a server administering the access (e.g., a token server, as described below) may then automatically generate a specific system key (e.g., a key specific to the user profile associated with User B) and provide the system key to User B; fig. 2B); the external system operating in a cloud computing environment that is separate from and external to the enterprise computing environment, wherein the content server manages privileges of internal users in the enterprise computing environment on the item (para. 25: if a particular file is shared with read-write permissions (e.g., for collaborative purposes), any changes made to the copy of the file stored in the secondary cloud drive is not merged with the master copy stored in the primary cloud drive unless the user of the primary cloud drive approves of the changes. This may provide the user with a flexible tool for controlling access to his/her files, while also reducing the chances of accidental or unauthorized changes to the master copy of the file. Such multi-layer security may allow for a robustly secure system for sharing files stored on massively distributed storage systems such as cloud drives; para. 33: the mirroring or copying of content from the users' cloud drives 205 to the enterprise cloud drives 220 may be subject to approval from the administrators. This may also be extended, for example, to third-parties that engage with the enterprise domain, for example, to control undesirable content from the third parties to infiltrate the enterprise network; fig. 2A: enterprise cloud drive, external cloud drive; para. 43: security threads can include permission processes that are managed by the token server using digital rights management (DRM), and/or enterprise or user group policy privileges); and wherein the external system independently manages sharing of the copy of the item among users of the external system (para. 28-30: storing data on cloud drives host–ed on remote storage devices may allow easy sharing of data with multiple users. For example, if a user intends to share a file stored on the primary cloud drive 205, a copy of the file is copied or mirrored in the corresponding secondary cloud drive 210 for the sharing. Subject to the user's permission, files from one or more external cloud drives 215 may be stored on the user's secondary cloud drive 210; fig. 2A: the enterprise cloud drive 220 is associated with an external cloud drive 215. Thus, the external cloud drive 215 is separate and external to the enterprise cloud drives 220 – See para. 33: each hosted cloud drive associated with a user can therefore be configured as a private network, which, under an enterprise domain, may be linked to one or more administrator accounts. The mirroring or copying of content from the users' cloud drives 205 to the enterprise cloud drives 220 may be subject to approval from the administrators. This may also be extended, for example, to third-parties that engage with the enterprise domain, for example, to control undesirable content from the third parties to infiltrate the enterprise network); updating, by the content server, a user-interface (UI) to indicate that the item is locked from editing (para. 13: the environment-aware security token for a file can be configured such that the file may be viewed or accessed from outside the home network, but no changes or edits to the electronic file may be made. This can be useful, for example, in a social network, where user data (e.g., social network account) stored on a cloud drive is protected using one or more security tokens; fig. 2B or para. 46: the document agent may allow, for example via a second user interface, to specify whether a password would be required to access the document, or if one or more actions (e.g., printing, editing, copying etc.) should be restricted). Caffary does not explicitly teach operating behind a firewall, wherein the indication to lock the item is received from within the enterprise computing environment; by configuring the UI to display listings of the item with an icon indicating a lock, adjacent to the item in the displayed listings. Dorman teaches operating behind a firewall, wherein the indication to lock the item is received from within the enterprise computing environment, locking through the firewall (fig. 2: Enterprise Organizational Setting with workspaces; para. 22: client that is connected with a collaboration environment including a cloud-based platform (e.g., cloud-based file sharing, collaboration, and/or storage platform/service) and runs on a client device to synchronize folders and files between the collaboration environment and the user device; para. 55: display an icon to indicate whether a folder or a file is shared (collaborative) or private, whether it is locked (checked out) or unlocked, and whether it is already synchronized etc.; para. 68-69: the network interface device can include a firewall which can, in some embodiments, govern and/or manage permission to access/proxy data in a computer network, and track varying levels of trust between different machines and/or applications. The firewall may additionally manage and/or have access to an access control list which details permissions including for example, the access and operation rights of an object by an individual, a machine, and/or an application, and the circumstances under which the permission rights stand. Thus, deploying a firewall on a network helps block unauthorized access to businesses /enterprise’s devices); by configuring the UI to display listings of the item with an icon indicating a lock, adjacent to the item in the displayed listings (para. 55: display an icon to indicate whether a folder or a file is shared (collaborative) or private, whether it is locked (checked out) or unlocked. The icon could show one of these statuses at a time or more than one of them at the same time). Thus, it would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Caffary et al. and the lock icon of Dorman to effectively block unauthorized access to a computer network and allow users to securely share, interact, and/or collaborate available data – See Dorman, para. 69. As per claims 2, 9, 16, Caffary teaches wherein locking the copy of the item comprises a sending a request to the external system to lock the copy of the item to prevent editing of the copy of the item (para. 8: the information about the electronic file can include a user-input indicative of an intent to share the electronic file with one or more other users. The one or more user-defined attributes can include information indicative of one or more users permitted to access the copy of the electronic file. The one or more user-defined attributes can include a level of permitted access for one or more users. The level of permitted access can include a read-only access or a read-write access. Thus, at least users at the secondary cloud drive would receive for read only access, no editing to the copy file is allowed). As per claims 3, 10, 17, Caffary teaches wherein the indication to lock the item is an indication from a user of the content server to share the item with a user of the external system, and wherein locking the copy of the item managed by the external system to prevent editing of the copy of the item comprises sending information identifying a user of the external system and information to prevent the user of the external system from editing the copy of the item to the external system (para. 25: the user-defined attributes can be used to lock-down the file to a home network, e.g., as defined based on a predetermined set of user-profiles and/or devices, such that the corresponding security token thwarts any access attempt from outside of the home network. In addition, if a user intends to share a file that is stored in the user's cloud drive, a copy of the file is stored in a secondary cloud drive that other authorized users may access. If a particular file is shared with read-write permissions (e.g., for collaborative purposes), any changes made to the copy of the file stored in the secondary cloud drive is not merged with the master copy stored in the primary cloud drive unless the user of the primary cloud drive approves of the changes. This may provide the user with a flexible tool for controlling access to his/her files, while also reducing the chances of accidental or unauthorized changes to the master copy of the file. Such multi-layer security may allow for a robustly secure system for sharing files stored on massively distributed storage systems such as cloud drives). As per claims 7, 14, 21, Caffary teaches wherein the item comprises a file or a folder (para. 4-5: receiving information about an electronic file stored on a primary cloud drive of a user and receiving one or more user-defined attributes associated with the electronic file. The one or more user-defined attributes are indicative of a home network associated with the electronic file). Claim(s) 4-6, 11-13, 18-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Caffary (US 20190109857) in view of Dorman et al. (US 20140201138) and further in view of Meyer et al. (US 20140047560). As per claims 4, 11, 18, Caffary teaches establishing, by the content server, a link between the item in the repository and the copy of the item in the external system (para. 4-5: receiving information about an electronic file stored on a primary cloud drive of a user, and receiving one or more user-defined attributes associated with the electronic file. The one or more user-defined attributes are indicative of a home network associated with the electronic file; generate, based on the one or more user-defined attributes, a security token that is configured to control access to the electronic file based on whether the access is from within or outside of the home network, and store a copy of the electronic file on a secondary cloud drive separate from the primary cloud drive. The copy of the electronic file is stored on the secondary cloud drive in association with the security token; para. 56). Caffary and Dorman do not explicitly teach a revocable link. Meyer teaches at para. 132: provide a secure content sharing and collaboration environment that goes beyond the enterprise firewall; para. 137-138: the revoking of sharing access to the content revokes access to all instances of the shared content and all copies of the content made by the plurality of users. Thus, it would have been obvious to one or ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Caffary, Dorman et al. and the revocable link of Meyer to effectively revoke access without having to contact or to track down the recipients, who may not have any indication sent to them that access has been revoked. With the unsharing facility, the content simple stops being accessible – See Meyer, para. 128. As per claims 5, 12, 19, Caffary teaches wherein the establishing further comprises receiving a unique identifier for the copy of the item from the external system and storing, in a tracking data structure, the unique identifier for the copy of the item and a unique identifier for the item with a user identifier for a user of the content server (para. 31: security tokens can also be generated for the copies of the files stored in the primary cloud drives to lock down such copies to the primary cloud drives. In some implementations, generating a security token for a file stored in a secondary cloud drive can include modifying a security token of the corresponding copy of the file stored in the primary cloud drive). As per claims 6, 13, 20, Caffary teaches wherein the tracking data structure comprises a field for storing the unique identifier for the item in the content server, a field for storing the unique identifier for the copy of the item in the external system, a field for storing a version identifier of the item in the external system, a field for storing a version identifier of the item in the content server, and a field for storing the user identifier for a user of the content server (para. 25: allow for a robustly secure system for sharing files stored on massively distributed storage systems; para. 33: a user's primary cloud drive or secondary cloud drive can be mirrored on the enterprise cloud drive using a key (also referred to as an enterprise key) generated for the corresponding enterprise; para. 40: the user-defined attributes can include various identification information associated with an electronic file and access thereof. The user-defined attributes can include identification of electronic files and documents and/or the corresponding storage locations on various devices associated with the home network; para. 53: the environment-aware security token can also be configured to be synchronized with the server periodically, for example, after predetermined time intervals or when any changes to the corresponding electronic file/modified version is detected; para. 70: file management does not only secure the files in isolation, but includes user profiles, file identifiers, and/or device profiles in the security layer. The security layer can be used, for example, to control and verify various assets via attached, encapsulated, or embedded security objects). Dorman also teaches at para. 39: items or content downloaded or edited can cause notifications to be generated. Such notifications can be sent to relevant users to notify them of actions surrounding a download, an edit, a change, a modification, a new file, a conflicting version, an upload of an edited or modified file. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Kopf et al. (20170272444) teaches at para. 33: concurrent modification of content can be facilitated for users who are either inside an enterprise firewall or external to the enterprise firewall. Doak (9875269) teaches at col. 2, first paragraph: receive an edit request from a workstation to edit a selected segment within a file, wherein the file comprises a plurality of segments including the selected segment, and wherein the file is stored in a data store, determine if the selected segment is locked, wherein file segments that are locked are unavailable for editing, upon determining that the selected segment is unlocked, provide access to the selected segment to the workstation, lock the selected segment for a period of time, wherein the selected segment is unavailable for editing by any other workstations, receive a save request from the workstation to save changes made to the selected segment, save the changes made in the selected segment within the file, and unlock the selected segment, wherein the unlocked segment is available for editing by any workstation. Wong et al. (US 20160127808) teaches at para. 346: cloud network and an enterprise network; para. 551: Web Application Firewalls may Dynamic security testing tools may be simple hardware appliances continually verify protection against that can also accelerate and load known signatures and patterns. Ow (US 20140165176) teaches at fig. 3C, item 351: lock icon displayed next to the item. Kiang (US 20140259190) teaches at 103-108: enterprise account, cloud-based platform, file sharing, set shared link expiration. Any inquiry concerning this communication or earlier communications from the examiner should be directed to LINH BLACK whose telephone number is (571)272-4106. The examiner can normally be reached 9AM-5PM EST M-F. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Tony Mahmoudi can be reached on 571-272-4078. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /LINH BLACK/Examiner, Art Unit 2163 7/25/2026 /TONY MAHMOUDI/Supervisory Patent Examiner, Art Unit 2163
Read full office action

Prosecution Timeline

Show 6 earlier events
Apr 11, 2025
Non-Final Rejection mailed — §103
Jul 11, 2025
Response Filed
Oct 23, 2025
Final Rejection mailed — §103
Jan 21, 2026
Examiner Interview Summary
Jan 21, 2026
Applicant Interview (Telephonic)
Jan 23, 2026
Request for Continued Examination
Jan 30, 2026
Response after Non-Final Action
Sep 23, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12645637
GENERATING GUARANTEED RETENTION LOCK AUDIT REPORTS FOR CASCADED REPLICATION IN A DEDUPLICATION BACKUP SYSTEM
2y 7m to grant Granted Jun 02, 2026
Patent 12638952
Data Preparation User Interface with Conglomerate Heterogeneous Process Flow Elements
5y 10m to grant Granted May 26, 2026
Patent 12632453
GENETIC-ALGORITHM-ASSISTED QUERY GENERATION
2y 6m to grant Granted May 19, 2026
Patent 12602376
SYSTEMS AND METHODS FOR DATA CURATION IN A DOCUMENT PROCESSING SYSTEM
4y 9m to grant Granted Apr 14, 2026
Patent 12530339
DISTRIBUTED PLATFORM FOR COMPUTATION AND TRUSTED VALIDATION
4y 0m to grant Granted Jan 20, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
50%
Grant Probability
61%
With Interview (+10.6%)
4y 10m (~7m remaining)
Median Time to Grant
High
PTA Risk
Based on 448 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month