Prosecution Insights
Last updated: August 18, 2026
Application No. 18/168,739

CREATION AND RETENTION OF IMMUTABLE SNAPSHOTS TO FACILITATE RANSOMWARE PROTECTION

Final Rejection §103
Filed
Feb 14, 2023
Examiner
BROWN, CHRISTOPHER J
Art Unit
2439
Tech Center
2400 — Computer Networks
Assignee
Netapp Inc.
OA Round
5 (Final)
75%
Grant Probability
Favorable
6-7
OA Rounds
0m
Est. Remaining
88%
With Interview

Examiner Intelligence

Grants 75% — above average
75%
Career Allowance Rate
537 granted / 713 resolved
+17.3% vs TC avg
Moderate +13% lift
Without
With
+12.6%
Interview Lift
resolved cases with interview
Typical timeline
3y 5m
Avg Prosecution
34 currently pending
Career history
757
Total Applications
across all art units

Statute-Specific Performance

§101
2.1%
-37.9% vs TC avg
§103
63.5%
+23.5% vs TC avg
§102
11.5%
-28.5% vs TC avg
§112
11.5%
-28.5% vs TC avg
Black line = Tech Center average estimate • Based on career data from 713 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Arguments Applicant’s arguments with respect to claim(s) have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. Applicant argues against the “Das” reference US 2020/0007620 regarding a “textual label” corresponding to a snapshot policy, and argues that the snapshot “does not involve copying of data” Examiner has removed the Das reference in an effort to expedite and simplify the office action. Examiner has incorporated Protopopov US 8,352,432 to meet the claims as amended. Examiner has additionally objected to claims 2, 10, and 17 which if incorporated into independent claims 1, 9, and 16, would result in an allowance. All dependent claims dependent on claims 2, 10 and 17 have also been objected to. Examiner maintains the rejection using the Volvovski reference for claims 6, 7, 14, 19, 24-26 and asserts that an encrypted file is a private file. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1, 7, 9, 12, 13, 15, 16, 18, 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Protopopov US 8,352,431 in view of Gunda US 2023/0103474 in view of Mendel US 2013/0145429. As per claim 1 Protopopov teaches maintaining a plurality of snapshot policies for a first volume of a first storage system wherein each snapshot policy of the plurality represents a set of rules that control one or more of creation, retention, mirroring and expiration of a given snapshot with which the snapshot policy is associated and each policy has a textual label and retention period. (Column 1 line 50 to Column 2 line 7) (Column 47 line 19-55)(snapshots are metadata pointers, labeled with snapshot policies and including retention period and creation) (Column 38 lines 40-55) (plurality of policy instances and descriptors) Protopopov teaches the snapshot represents a point in time image of a dataset containing metadata instead of including a copy of underlying data for the dataset. (Column 1 line 50 to Column 2 line 7) (metadata pointer in a snapshot, not the underlying data) (Column 1 lines 20-25) (Snapshots are records of a given moment in time) Protopopov teaches associating the particular snapshot policy with the snapshot includes labeling the snapshot with the textual label of the particular snapshot policy and assignment of the retention time to the snapshot includes setting the retention time based on the retention period of the particular snapshot policy. (Column 1 line 50 to Column 2 line 7) (Column 47 lines 19 to Column 48 line 5) (snapshot name and handling policy field; retention time) Protopopov fails to teach the retention time is immutable. Gunda teaches locking a snapshot stored on a first volume of a first storage system by assigning an immutable retention time to the snapshot by associating a particular snapshot schedule policy [0019][0057] (locking snapshots for a for a retention period and policy) It would have been obvious to one of ordinary skill in the art to use the teaching of Gunda with Protopopov because it prevents erasure of important backup data. Mendel teaches a tamper-proof timer. [0039][0040] (teaches a secure element that may include a timer, or a tamper-proof clock used in function as a timer) It would have been obvious to one of ordinary skill in the art at the time the invention was filed to use the teaching of Mendel with the prior art because it improves the security of the system. As per claim 4. Protopopov teaches The method of claim 1, wherein labeling the snapshot with the textual label of the particular snapshot policy is performed manually by an administrative user of the first storage system. (Column 38 lines 26-45) teaches manual user customization of policy and additionally customizing snapshot names (Column 46 lines 61-65) As per claim 5. Protopopov teaches the particular snapshot policy is automatically associated with the snapshot at a time the snapshot is created as a result of the textual label being associated with a rule of ta snapshot backup policy that triggered creation of the snapshot. (Column 1 line 50 to Column 2 line 7) (Column 47 line 19-55)(snapshots are metadata pointers, labeled with snapshot policies and including retention period and creation) (Column 38 lines 40-55) (plurality of policy instances and descriptors) As per claim 9. Protopopov teaches maintaining a plurality of snapshot policies for a first volume of a first storage system wherein each snapshot policy of the plurality represents a set of rules that control one or more of creation, retention, mirroring and expiration of a given snapshot with which the snapshot policy is associated and each policy has a textual label and retention period. (Column 1 line 50 to Column 2 line 7) (Column 47 line 19-55)(snapshots are metadata pointers, labeled with snapshot policies and including retention period and creation) (Column 38 lines 40-55) (plurality of policy instances and descriptors) Protopopov teaches the snapshot represents a point in time image of a dataset containing metadata instead of including a copy of underlying data for the dataset. (Column 1 line 50 to Column 2 line 7) (metadata pointer in a snapshot, not the underlying data) (Column 1 lines 20-25) (Snapshots are records of a given moment in time) Protopopov teaches associating the particular snapshot policy with the snapshot includes labeling the snapshot with the textual label of the particular snapshot policy and assignment of the retention time to the snapshot includes setting the retention time based on the retention period of the particular snapshot policy. (Column 1 line 50 to Column 2 line 7) (Column 47 lines 19 to Column 48 line 5) (snapshot name and handling policy field; retention time) Protopopov fails to teach the retention time is immutable. Gunda teaches locking a snapshot stored on a first volume of a first storage system by assigning an immutable retention time to the snapshot by associating a particular snapshot schedule policy [0019][0057] (locking snapshots for a for a retention period and policy) It would have been obvious to one of ordinary skill in the art to use the teaching of Gunda with Protopopov because it prevents erasure of important backup data. Mendel teaches a tamper-proof timer. [0039][0040] (teaches a secure element that may include a timer, or a tamper-proof clock used in function as a timer) It would have been obvious to one of ordinary skill in the art at the time the invention was filed to use the teaching of Mendel with the prior art because it improves the security of the system. As per claim 12. Protopopov teaches the particular snapshot policy is automatically associated with the snapshot at a time the snapshot is created as a result of the textual label being associated with a rule of a snapshot backup policy that triggered creation of the snapshot. (Column 1 line 50 to Column 2 line 7) (Column 47 line 19-55)(snapshots are metadata pointers, labeled with snapshot policies and including retention period and creation) (Column 38 lines 40-55) (plurality of policy instances and descriptors) As per claim 13. Protopopov teaches the particular snapshot policy is automatically associated with the snapshot at a time the snapshot is created as a result of the textual label being associated with a rule of ta snapshot backup policy that triggered creation of the snapshot. (Column 1 line 50 to Column 2 line 7) (Column 47 line 19-55)(snapshots are metadata pointers, labeled with snapshot policies and including retention period and creation) (Column 38 lines 40-55) (plurality of policy instances and descriptors) As per claim 15. Gunda teaches The system of claim 14, wherein the instructions further cause the system to: responsive to receipt of a request to delete the locked snapshot, determine whether deletion of the locked snapshot is permissible by accessing the private metafile; after a negative determination indicating deletion of the locked snapshot is not permissible, retaining the locked snapshot; and after an affirmative determination indicating deletion of the locked snapshot is permissible, deleting the locked snapshot. [0050][0068] (teaches determination of whether deletion of a snapshot is allowed) As per claim 16. Protopopov teaches maintaining a plurality of snapshot policies for a first volume of a first storage system wherein each snapshot policy of the plurality represents a set of rules that control one or more of creation, retention, mirroring and expiration of a given snapshot with which the snapshot policy is associated and each policy has a textual label and retention period. (Column 1 line 50 to Column 2 line 7) (Column 47 line 19-55)(snapshots are metadata pointers, labeled with snapshot policies and including retention period and creation) (Column 38 lines 40-55) (plurality of policy instances and descriptors) Protopopov teaches the snapshot represents a point in time image of a dataset containing metadata instead of including a copy of underlying data for the dataset. (Column 1 line 50 to Column 2 line 7) (metadata pointer in a snapshot, not the underlying data) (Column 1 lines 20-25) (Snapshots are records of a given moment in time) Protopopov teaches associating the particular snapshot policy with the snapshot includes labeling the snapshot with the textual label of the particular snapshot policy and assignment of the retention time to the snapshot includes setting the retention time based on the retention period of the particular snapshot policy. (Column 1 line 50 to Column 2 line 7) (Column 47 lines 19 to Column 48 line 5) (snapshot name and handling policy field; retention time) Protopopov fails to teach the retention time is immutable. Gunda teaches locking a snapshot stored on a first volume of a first storage system by assigning an immutable retention time to the snapshot by associating a particular snapshot schedule policy [0019][0057] (locking snapshots for a for a retention period and policy) It would have been obvious to one of ordinary skill in the art to use the teaching of Gunda with Protopopov because it prevents erasure of important backup data. Mendel teaches a tamper-proof timer. [0039][0040] (teaches a secure element that may include a timer, or a tamper-proof clock used in function as a timer) It would have been obvious to one of ordinary skill in the art at the time the invention was filed to use the teaching of Mendel with the prior art because it improves the security of the system. As per claim 18. Protopopov teaches the particular snapshot policy is automatically associated with the snapshot at a time the snapshot is created as a result of the textual label being associated with a rule of ta snapshot backup policy that triggered creation of the snapshot. (Column 1 line 50 to Column 2 line 7) (Column 47 line 19-55)(snapshots are metadata pointers, labeled with snapshot policies and including retention period and creation) (Column 38 lines 40-55) (plurality of policy instances and descriptors) As per claim 20. Gunda teaches The non-transitory machine readable medium of claim 19, wherein the instructions further cause the system to: responsive to receipt of a request to delete the locked snapshot, determine whether deletion of the locked snapshot is permissible by accessing the private metafile; after a negative determination indicating deletion of the locked snapshot is not permissible, retaining the locked snapshot; and after an affirmative determination indicating deletion of the locked snapshot is permissible, deleting the locked snapshot. [0050][0068] (teaches determination of whether deletion of a snapshot is allowed) As per claim 21, Mendel teaches the method of claim 1, the tamper-proof timer is initialized with a time value upon creation, stored in memory, and updated independently of a system time of the first storage system. [0039][0040] (teaches a secure element that may include a timer, or a tamper-proof clock used in function as a timer; teaches that the clock uses an outside server rather than the local system clock to update.) As per claim 22, Mendel teaches the system of claim 9, the tamper-proof timer is initialized with a time value upon creation, stored in memory, and updated independently of a system time of the first storage system. [0039][0040] (teaches a secure element that may include a timer, or a tamper-proof clock used in function as a timer; teaches that the clock uses an outside server rather than the local system clock to update.) As per claim 23, Mendel teaches the non-transitory machine readable medium of claim 16, the tamper-proof timer is initialized with a time value upon creation, stored in memory, and updated independently of a system time of the first storage system. [0039][0040] (teaches a secure element that may include a timer, or a tamper-proof clock used in function as a timer; teaches that the clock uses an outside server rather than the local system clock to update.) Claim(s) 6, 7, 14, 19, 24-26 is/are rejected under 35 U.S.C. 103 as being unpatentable over Protopopov US 8,352,431 in view of Gunda US 2023/0103474 in view of Mendel US 2013/0145429 in view of Volvovski US 2019/0005261 As per claim 6. Gunda teaches The method of claim 1, wherein the immutable retention time is stored in a private metafile corresponding to the locked snapshot that is inaccessible to end users of the first storage system. [0048]-[0050] (teaches the snapshot time is in metadata in an inode) Volvovski teaches the metafile is private an inaccessible [0043][0044][0045][0053] (teaches the inode is private and encrypted) It would have been obvious to one of ordinary skill in the art at the time the invention was filed to use the teachings of Volvovski with the prior art because it increases security. As per claim 7. Gunda teaches The method of claim 6, further comprising: responsive to receipt of a request to delete the locked snapshot, determining by the first storage system whether deletion of the locked snapshot is permissible by accessing the private metafile; after a negative determination indicating deletion of the locked snapshot is not permissible, retaining the locked snapshot; and after an affirmative determination indicating deletion of the locked snapshot is permissible, deleting the locked snapshot. [0050][0068] (teaches determination of whether deletion of a snapshot is allowed) Volvovski teaches the metafile is private an inaccessible [0043][0044][0045][0053] (teaches the inode is private and encrypted) It would have been obvious to one of ordinary skill in the art at the time the invention was filed to use the teachings of Volvovski with the prior art because it increases security. As per claim 14. Gunda teaches The system of claim 9, wherein the immutable retention time is stored in a private metafile corresponding to the locked snapshot that is inaccessible to end users of the first storage system. [0048]-[0050] (teaches the snapshot time is in metadata in an inode) Volvovski teaches the metafile is private an inaccessible [0043][0044][0045][0053] (teaches the inode is private and encrypted) As per claim 19. Gunda teaches The non-transitory machine readable medium of claim 16, wherein the immutable retention time is stored in a private metafile corresponding to the locked snapshot that is inaccessible to end users of the first distributed storage system. [0048]-[0050] (teaches the snapshot time is in metadata in an inode) Volvovski teaches the metafile is private an inaccessible [0043][0044][0045][0053] (teaches the inode is private and encrypted) As per claim 24 Volvovski teaches the method of claim 6, wherin the private metafile is stored in a private index (inode) space. [0043][0044][0045][0053] (teaches the inode is private and encrypted) As per claim 25 Volvovski teaches the system of claim 14, wherin the private metafile is stored in a private index (inode) space. [0043][0044][0045][0053] (teaches the inode is private and encrypted) As per claim 26 Volvovski teaches the non-transitory machine readable medium of claim 19, wherin the private metafile is stored in a private index (inode) space. [0043][0044][0045][0053] (teaches the inode is private and encrypted) Allowable Subject Matter Claims 2, 3, 8, 10, 11, 17, are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to CHRISTOPHER BROWN whose telephone number is (571)272-3833. The examiner can normally be reached M-F 8-5. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Luu Pham can be reached on (571) 270-5002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /CHRISTOPHER J BROWN/Primary Examiner, Art Unit 2439
Read full office action

Prosecution Timeline

Show 4 earlier events
Jun 25, 2025
Response Filed
Oct 06, 2025
Final Rejection mailed — §103
Dec 03, 2025
Response after Non-Final Action
Dec 12, 2025
Request for Continued Examination
Dec 19, 2025
Response after Non-Final Action
Jan 13, 2026
Non-Final Rejection mailed — §103
Apr 27, 2026
Response Filed
Jul 16, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12694100
CREATION AND RETENTION OF IMMUTABLE SNAPSHOTS TO FACILITATE RANSOMWARE PROTECTION
3y 5m to grant Granted Jul 28, 2026
Patent 12689631
USING MESSAGE CONTEXT TO EVALUATE SECURITY OF REQUESTED DATA
5y 10m to grant Granted Jul 21, 2026
Patent 12688291
RANSOMWARE DETECTION AND DATA PRUNING MANAGEMENT
1y 11m to grant Granted Jul 21, 2026
Patent 12652290
CYBER SECURITY FOR SOFTWARE-AS-A-SERVICE FACTORING RISK
5y 3m to grant Granted Jun 09, 2026
Patent 12652315
REMOTE MONITORING OF A SECURITY OPERATIONS CENTER (SOC)
3y 8m to grant Granted Jun 09, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

6-7
Expected OA Rounds
75%
Grant Probability
88%
With Interview (+12.6%)
3y 5m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 713 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month