Prosecution Insights
Last updated: October 02, 2026
Application No. 18/361,344

DATA LOSS PREVENTION TECHNIQUES FOR INTERFACING WITH ARTIFICIAL INTELLIGENCE TOOLS

Final Rejection §103
Filed
Jul 28, 2023
Priority
May 05, 2023 — provisional 63/500,354
Examiner
PATEL, HARESH N
Art Unit
2496
Tech Center
2400 — Computer Networks
Assignee
Cisco Technology Inc.
OA Round
4 (Final)
78%
Grant Probability
Favorable
5-6
OA Rounds
0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 78% — above average
78%
Career Allowance Rate
651 granted / 837 resolved
+19.8% vs TC avg
Strong +21% interview lift
Without
With
+21.4%
Interview Lift
resolved cases with interview
Typical timeline
3y 0m
Avg Prosecution
25 currently pending
Career history
867
Total Applications
across all art units

Statute-Specific Performance

§101
16.4%
-23.6% vs TC avg
§103
41.9%
+1.9% vs TC avg
§102
21.3%
-18.7% vs TC avg
§112
11.4%
-28.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 837 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . DETAILED ACTION Status of Claims Claims 1-20 are subject to examination. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1, 7, 8, 14, 15, is/are rejected under 35 U.S.C. 103 as being unpatentable over NARAYANASWAMY, 20190268379 in view of Official Notice and Bjarnason et al., 20230164176 and Janaudy, 20220020020. Referring to claim(s) 1, NARAYANASWAMY substantially discloses a method comprising: [0068] Cloud-based content sensitivity scanner 165 can perform the sensitivity classification in real-time when the documents are intercepted by the inspection service 155, while in transit to or from the cloud-based services 128A-Z. It can also perform the sensitivity classification when the documents are crawled or registered by the inspection service 155, while at rest in the cloud-based services 128A-Z. It encodes the results of the sensitivity classification in the sensitivity metadata, e.g., by assigning a “sensitive” or “non-sensitive” flag (or label) to a classification field of the sensitivity metadata. Results of sensitivity scanning can be stored 578 in a cloud-based metadata store 145. Additional details about the scanner 165 can be found in the incorporated materials. determining that the communication includes a first content addressed by a data loss prevention policy, where the first content is sensitive data generated by the source [0137] One implementation of the disclosed method further includes, in response to detecting a revision or copying of a downloaded document, reevaluating sensitivity of the revised or copied document, generating sensitivity metadata that labels the revised or copied document as sensitive, and updating the local metadata store with the sensitivity metadata generated for the revised or copied document. The disclosed method can further include, in response to detecting data egress events at the endpoint that would push data in the revised or copied document from the endpoint to uncontrolled locations, determining that the revised or copied document is sensitive based on looking up the sensitivity metadata for the revised or copied document in the local metadata store and without scanning the revised or copied document at the endpoint for sensitivity; and enforcing a data loss prevention policy at the endpoint based on the determination. In some cases, the disclosed method further includes embedding the sensitivity metadata. creating an identifier for at least a first portion of the communication; storing the identifier for at least the first portion of the communication in a content tracking database; and analyzing a second portion of second content on a network, from the client device, [0069] Some examples of the sensitivity metadata generated by the inspection service 155 and the cloud-based content sensitivity scanner 165 are unique document identifier, document integrity checksum such as MD5, document fingerprint such as Rabin fingerprint, document true file type such as portable document format (PDF), name of the cloud-based service on which a document is stored, sensitivity (or non-sensitivity) of the document, type of sensitivity such as PCI, PII, and ePHI, name and sensitivity (or non-sensitivity) of the source from which the document originated (e.g., a source cloud-based service, a source website, a source server, a source database, a source partition, a source user, a source user group, a source folder, a source device), inheritance information such as a PDF file created from an original word processing application, and log of activities performed on the document such as creation, revision, versioning, cloning, deletion, sharing, and transmission to or from the cloud-based service. Additional examples of the sensitivity metadata can be found in the incorporated materials. protected by the data loss prevention policy to determine whether the second portion of the second content includes at least part of the first portion of the communication, wherein the second content a modified version of the first content. [0139] In other implementations, a combination of the endpoint traffic monitor and the file system monitor can interpret file system calls issued on common protocols used for transferring files like SMB, NFS, FTP, HTTP, and HTTPS. They can identify and store the origin from which a file has been written, such as a mounted drive (e.g., NFS, SMB) on the network, a mount point on the file system, or a domain name of a server. In one implementation, they can identify and store the original file type or format of a file as inheritance metadata. A child file, saved with a different file type or format than a parent file, inherits a subset of the parent file's metadata in the form of inheritance metadata. Put together, the origin can identify information a data source, a parent file, a user, or a user group. In yet other implementations, when a file or document is locally created on an endpoint, the decision to run a DLP scan on such a file can be conditional on the origin of the file and whether the origin is sensitive. NARAYANASWAMY also discloses sensitive data such as identity information of the sender. However, NARAYANASWAMY does not specifically mention about the software being artificial intelligence tool. However, one of ordinary skill in the art would readily know that use of the artificial intelligence tool is well-known in the art, rather novel and hence official notice is taken. For example, CN 110620846 B discloses, after obtaining the encryption processing result, can intercept all content or part of the content from the encryption processing result as the sender identification. As an example, MD5 can be used to encrypt the first time stamp to obtain a 32-bit character string, then intercepting the content of the middle 8-24 bit of the 32-bit character string as the sender identifier, 2nd last para, page 8 the first message identifier comprises a sender identifier, further comprises a message type identifier, message template identifier, intelligent message identifier, safety least one of the identifier and the combination condition. wherein the message type identification is used for indicating message type of message content, message template identification is used for indicating message content is message template generated based on message template or message content, intelligent message identification for indicating message content is generated by artificial intelligence; safety is used for safety the message, last para, page 8 the adopted encryption algorithm can be MD5, Base64 or hash algorithm and so on. Optionally, after obtaining the encryption processing result, it can intercept all content or part of the content from the encryption processing result as a message type identification. For example, the 16-bit character can be taken as the message template identifier, 2nd para, page 10 the message content is generated by artificial intelligence, such as generated by intelligent customer service, the message can be called intelligent message, and generating intelligent message identifier for the message content, last 4th para, page 10 Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention disclosed by NARAYANASWAMY to include the software being artificial intelligence tool and also one of ordinary skill in the art would have been motivated to do so because it could provide utilizing the software (tool) for communicating information/message to another entity. The tool provided communication would enable generating and transferring information to a remote device for further processing to implement an action. NARAYANASWAMY do not disclose, which Bjarnason discloses subsequent to intercepting the communication (analyzing subsequent to the interception, para 31). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention disclosed by NARAYANASWAMY and also one of ordinary skill in the art would have been motivated to do so because it could provide utilizing the intercepting along with the analyzing. The intercepting would enable collection of data, which would be available so that analyzing of the data would be possible. The analyzing of the data would enable implementing the security for the communications. NARAYANASWAMY and Bjarnason do not disclose, which Janaudy discloses comparing a second identifier derived from the second portion of the second content with the stored identifier (comparing the second hash to the derived hash and responsive to a determination that the second hash matches the derived hash providing a confirmation that the second entity/portion includes the first entity/portion, claim 25. [0249] For example, “communication,” “communicate,” “connection,” “connect,” or other similar terms should generally be construed broadly to mean a wired, wireless, and/or other form of, as applicable, connection between elements, devices, computing devices, telephones, processors, controllers, servers, networks, telephone networks, the cloud, and/or the like, which enable voice and/or data to be sent, transmitted, broadcasted, received, intercepted, acquired, and/or transferred (each as applicable). [0250] Furthermore, a digital asset (as used in the present disclosure) is a term known in the art and, where applicable, may include and/or broadly and equivalently refer to, public key and private key pairs, and the like. Furthermore, hashing (as used in the present disclosure), or the like, is a term known in the art and, where applicable, may include and/or broadly and equivalently refer to a transformation or mapping of an input into a fixed-length string or series of characters (e.g., by using a hashing algorithm, hashing function, or the like). Similarly, a hash (as used in the present disclosure) is a term known in the art and, where applicable, may include and/or broadly refer to a fixed-length string or series of characters resulting from the hashing of an input (e.g., by using a hashing algorithm (e.g., SHA-256), hashing function, or the like). Furthermore, digitally signing, digital signing, digitally sign, signing, sign, and the like, are terms known in the art and, where applicable, may include and/or broadly and equivalently refer to creating digital signatures, including encrypting an input using a private key (i.e., for digital signatures, which is unlike the general approach of encrypting a message using a public key) so as to create a digital signature in such a manner that a recipient can, by applying a corresponding public key (i.e., a public key that corresponds to the private key used to create the digital signature; for digital signatures, the public key is used to decrypt the digital signature, which is unlike the general approach of decrypting a message using a private key), validate that the digital signature was signed (or encrypted) by the private key. [0045] software, software licenses [0246] Another example embodiment of the proof of authority verification process, which is used to verify whether or not an entity has been authorized by the owner of the digital asset to be the custodian of the digital asset, may include obtaining a public key of the digital asset. For example, the public key of the digital asset may be stored in and/or accessible/available (e.g., publicly available) from database 130. The proof of authority verification process may also include obtaining a signed proof of authority hash of the digital asset (e.g., obtaining from the database 130). In addition to obtaining the signed proof of authority hash of the digital asset, the proof of authority verification process may also include obtaining a proof of authority hash of the digital asset. The proof of authority verification process may also include obtaining a proof of management hash and/or a signed proof of management hash of the digital asset (e.g., obtaining from the database 130). Alternatively or in addition, the proof of authority verification process may include obtaining the proof of ownership hash and/or signed proof of ownership hash of the digital asset (e.g., obtaining from the database 130), obtaining the public key of the authorized custodian (e.g., obtaining from the database 130), and generating (or verifying) the proof of management hash and/or signed proof of management hash using the obtained proof of ownership hash and/or signed proof of ownership hash (in the same manner as described above and in the present disclosure). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention disclosed by NARAYANASWAMY and also one of ordinary skill in the art would have been motivated to do so because it could provide utilizing the comparison of the two identifiers. The comparison would enable whether two content are different or not, which would further enable determining whether both the content belongs to the same owner or not, para 45. Referring to claims 8, 15, the apparatus/medium claims is similarly analyzed and rejected for the same rationale as the method claim 1. Claim(s) 7, 14, is/are rejected under 35 U.S.C. 103 as being unpatentable over NARAYANASWAMY in view of Ylonen et al., 20130191631, Bjarnason, Janaudy and Official Notice. Referring to claim(s) 7, 14, NARAYANASWAMY, Bjarnason do not disclose, which Ylonen discloses wherein the communication is an in-bound communication coming from an external software into the network protected by the data loss prevention policy. [0149]. For example, an external network through an interceptor. Regarding, artificial intelligence tool, it is rejected as in claim under Official Notice. See claim 1, For example, CN 110620846 B discloses, Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention disclosed by NARAYANASWAMY and also one of ordinary skill in the art would have been motivated to do so because it could provide utilizing the in-bound communication. The in-bound communication would enable receiving data/information from a remote software. The data would be available for the DLP processing for security. Claim(s) 2, 3, 4, 9, 10, 11, 16-18, is/are rejected under 35 U.S.C. 103 as being unpatentable over NARAYANASWAMY in view of Bailey et al., 8621237 2013, Bjarnason, Janaudy and Official Notice. Referring to claim(s) 2, 9, 16, NARAYANASWAMY, Bjarnason, Janaudy do not disclose, which Bailey discloses wherein the second portion of content is a portion of code ( (32) Another remedial operation 36 involves the controller 54 intercepting and/or deleting the cryptographic key 34 from the source code 30. In the context of intercepting source code 30 at rest (e.g., a source file) with a discovered cryptographic key 34, the controller 54 may quarantine the source file until an authorized user has reviewed the source code 30 and approved the source code 30 for further processing. In the context of intercepting source code 30 with a discovered cryptographic key 34 en route between end points (e.g., an email message or other electronic communication), the controller 54 may block further transmission of the source code 30 and buffer the source code 30 within the source code storage 56 (FIG. 2) until the authorized user has addressed the discovery. col., 6, lines 12-26, Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention disclosed by NARAYANASWAMY and also one of ordinary skill in the art would have been motivated to do so because it could provide utilizing the code for performing a task. The code would enable analyzing information by the provided software for handling the code for further use when it is determined that the code is safe, col., 6, lines 12-26. Referring to claim(s) 3, 10, 17, Bailey discloses wherein the analyzing the portion of the code occurs prior to checking the portion of the code into a source code database ( (32) Another remedial operation 36 involves the controller 54 intercepting and/or deleting the cryptographic key 34 from the source code 30. In the context of intercepting source code 30 at rest (e.g., a source file) with a discovered cryptographic key 34, the controller 54 may quarantine the source file until an authorized user has reviewed the source code 30 and approved the source code 30 for further processing. In the context of intercepting source code 30 with a discovered cryptographic key 34 en route between end points (e.g., an email message or other electronic communication), the controller 54 may block further transmission of the source code 30 and buffer the source code 30 within the source code storage 56 (FIG. 2) until the authorized user has addressed the discovery. col., 6, lines 12-26 (23) the controller 54 may store the source code 30 in one or more files (i.e., source code 30 at rest) within a file system. the controller 54 may store the source code 30 as one or more temporarily buffered electronic communications (i.e., source code 30 en route between end point devices). As yet another example, if the electronic device 22 is a software development system and if the source code storage 56 includes a database, the controller 54 may store the source code 30 as one or more entries in a source code repository. Col., 4, lines 60-67. Referring to claim(s) 4, 11, 18, Bailey discloses when it is determined that the portion of code includes at least the first portion of the communication, preventing the first portion of code from being checked into the source code database (32) Another remedial operation 36 involves the controller 54 intercepting and/or deleting the cryptographic key 34 from the source code 30. In the context of intercepting source code 30 at rest (e.g., a source file) with a discovered cryptographic key 34, the controller 54 may quarantine the source file until an authorized user has reviewed the source code 30 and approved the source code 30 for further processing. In the context of intercepting source code 30 with a discovered cryptographic key 34 en route between end points (e.g., an email message or other electronic communication), the controller 54 may block further transmission of the source code 30 and buffer the source code 30 within the source code storage 56 (FIG. 2) until the authorized user has addressed the discovery. col., 6, lines 12-26, Claim(s) 5, 12, 19, is/are rejected under 35 U.S.C. 103 as being unpatentable over NARAYANASWAMY in view of BRANDER et al., 20150350895, Bjarnason, Janaudy and Official Notice. Referring to claim(s) 5, 12, 19, NARAYANASWAMY, Bjarnason do not disclose, which Brander discloses wherein the identifier for the at least the first portion of the communication is a first hash value derived from at least the first portion of the communication, deriving a second hash value for the second portion of the second content; comparing the first hash value and the second hash value; determining that the second portion of the second content includes at least partially the portion of the communication when the first hash value substantially matches the second hash value ( decrypting an incoming message comprises: receiving the incoming message; parsing the incoming message to obtain a signed hash portion, random keying material and an encrypted message portion; hashing the random keying material and the encrypted message portion to create a local hash; decrypting the signed hash portion with the first public signing key to obtain a sent hash; comparing the sent hash with the local hash; responsive to determining that the sent hash and the local hash match, deriving a message key from the first public encryption key, the second private encryption key and the random keying material; and decrypting the incoming message using the message key, claim 8. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention disclosed by NARAYANASWAMY and also one of ordinary skill in the art would have been motivated to do so because it could provide utilizing comparing of derived hash values. In responsive to determining that the first hash and the second hash matches, deriving a message key from the first public encryption key, the second private encryption key and the random keying material; and decrypting the incoming message using the message key, claim 8. Claim(s) 6, 13, 20, is/are rejected under 35 U.S.C. 103 as being unpatentable over NARAYANASWAMY in view of Brander, Janaudy, Official Notice, Bjarnason, Miles et al., 11734411 and Zachary, 20190385269. Referring to claim(s) 6, 13, 20, Brander discloses wherein the identifier for the at least the first portion of the communication is a first unit derived from at least the first portion of the communication, the analyzing the first portion of the content comprises: deriving a second unit for the second portion of the second content; comparing the first unit and the second unit; determining that the second portion of the second content includes at least partially the portion of the first communication upon condition ( decrypting an incoming message comprises: receiving the incoming message; parsing the incoming message to obtain a signed hash portion, random keying material and an encrypted message portion; hashing the random keying material and the encrypted message portion to create a local hash; decrypting the signed hash portion with the first public signing key to obtain a sent hash; comparing the sent hash with the local hash; responsive to determining that the sent hash and the local hash match, deriving a message key from the first public encryption key, the second private encryption key and the random keying material; and decrypting the incoming message using the message key, claim 8. NARAYANASWAMY, Bjarnason, Janaudy and Brander do not disclose, which Miles discloses first and second unit, when a similarity score between the first unit and the second unit is above a threshold ( (56) The server system may perform verification of the confirmation data by generating a hash value related to one or more portions of the records (of the second set of records) and a reference value related to the confirmation data, and then compare the hash value and the reference value to determine a similarity score. In one use case, the similarity score may be a binary score of TRUE (e.g., the hash value and the reference value are identical) or FALSE (e.g., the hash value and the reference value are not identical). A similarity score of TRUE may indicate a match between the relevant set of records at the server system and the modified record instances generated by the user device, thereby indicating that the confirmation data is valid. A similarity score of FALSE may indicate that a lack of a match between the relevant set of records at the server system and the modified record instances generated by the user device, thereby indicating that the confirmation data is invalid. Col., 17, lines 19-29. performing verification of the authentication data using a hash-based value derived from hashing of a combination of inputs comprising a first account identifier and account resource amount of the first record stored in the first memory area and a second account identifier and account resource amount of the second record stored in the first memory area; and in response to (i) the user-application-generated request comprising the one or more commands and (ii) the verification indicating a match between the authentication data and the hash-based value derived from the hashing of the combination of inputs, claim 3. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention disclosed by NARAYANASWAMY and also one of ordinary skill in the art would have been motivated to do so because it could provide utilizing the similarity score. A similarity score of false would indicate that a lack of a match between the relevant entities and the modified record instances generated by the user device, thereby indicating that the confirmation data is invalid, claim 3. NARAYANASWAMY, Miles, Bjarnason, Janaudy and Brander do not disclose, which Zachary discloses first and second embedding ( [0081] This transaction on the blockchain includes the embedded hash(es) (or information from which the embedded hash(es) can be derived) and, therefore, the transaction on the blockchain can be used to validate or verify the authenticity of the data through comparing the embedded hash(es) with the hash(es) of the transaction (i.e., the hash(es) stored on the blockchain). In this way, at least in some embodiments, the embedded hash(es) of the data can be used to cross-reference and validate the data that are recorded on the blockchain. [0089] This event-specific transaction on the blockchain includes the embedded hash(es) (or information from which the embedded hash(es) can be derived) and the event-specific data that was received from the vehicle (along with a timestamp, for example). Therefore, the transaction on the blockchain can be used to validate or verify the authenticity of the data through comparing the embedded hash(es) with the hash(es) of the event-specific transaction (i.e., the hash(es) stored on the blockchain). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention disclosed by NARAYANASWAMY and also one of ordinary skill in the art would have been motivated to do so because it could provide utilizing embedding data/information. The embedded of the message/transaction/units would enable storing the information/message. The stored data/information would be available or later use for the processing an action, para 89. Response to Arguments Remarks/Arguments filed 7/06/26, page 8-17, have been fully considered but they are not persuasive. Therefore, rejection of claims 1-20 is maintained. Regarding the remarks for the amended claims, the rejections are updated accordingly. Please refer to the updated rejections for the amended limitations (with new prior art). Regarding the remarks, A. Narayanaswamy Does Not Teach the Amended Identifier-Comparison Limitation, the Amended Identifier-Comparison Limitation is rather rejected under the new prior art. Narayanaswamy Does Not Teach Second Content That Is a Modified Version Detected Through Identifier Comparison, the Amended Identifier-Comparison Limitation is rather rejected under the new prior art. The relied upon limitations on Narayanaswamy are NARAYANASWAMY substantially discloses a method comprising: [0068] Cloud-based content sensitivity scanner 165 can perform the sensitivity classification in real-time when the documents are intercepted by the inspection service 155, while in transit to or from the cloud-based services 128A-Z. It can also perform the sensitivity classification when the documents are crawled or registered by the inspection service 155, while at rest in the cloud-based services 128A-Z. It encodes the results of the sensitivity classification in the sensitivity metadata, e.g., by assigning a “sensitive” or “non-sensitive” flag (or label) to a classification field of the sensitivity metadata. Results of sensitivity scanning can be stored 578 in a cloud-based metadata store 145. Additional details about the scanner 165 can be found in the incorporated materials. determining that the communication includes a first content addressed by a data loss prevention policy, where the first content is sensitive data generated by the source [0137] One implementation of the disclosed method further includes, in response to detecting a revision or copying of a downloaded document, reevaluating sensitivity of the revised or copied document, generating sensitivity metadata that labels the revised or copied document as sensitive, and updating the local metadata store with the sensitivity metadata generated for the revised or copied document. The disclosed method can further include, in response to detecting data egress events at the endpoint that would push data in the revised or copied document from the endpoint to uncontrolled locations, determining that the revised or copied document is sensitive based on looking up the sensitivity metadata for the revised or copied document in the local metadata store and without scanning the revised or copied document at the endpoint for sensitivity; and enforcing a data loss prevention policy at the endpoint based on the determination. In some cases, the disclosed method further includes embedding the sensitivity metadata. creating an identifier for at least a first portion of the communication; storing the identifier for at least the first portion of the communication in a content tracking database; and analyzing a second portion of second content on a network, from the client device, [0069] Some examples of the sensitivity metadata generated by the inspection service 155 and the cloud-based content sensitivity scanner 165 are unique document identifier, document integrity checksum such as MD5, document fingerprint such as Rabin fingerprint, document true file type such as portable document format (PDF), name of the cloud-based service on which a document is stored, sensitivity (or non-sensitivity) of the document, type of sensitivity such as PCI, PII, and ePHI, name and sensitivity (or non-sensitivity) of the source from which the document originated (e.g., a source cloud-based service, a source website, a source server, a source database, a source partition, a source user, a source user group, a source folder, a source device), inheritance information such as a PDF file created from an original word processing application, and log of activities performed on the document such as creation, revision, versioning, cloning, deletion, sharing, and transmission to or from the cloud-based service. Additional examples of the sensitivity metadata can be found in the incorporated materials. protected by the data loss prevention policy to determine whether the second portion of the second content includes at least part of the first portion of the communication, wherein the second content a modified version of the first content. [0139] In other implementations, a combination of the endpoint traffic monitor and the file system monitor can interpret file system calls issued on common protocols used for transferring files like SMB, NFS, FTP, HTTP, and HTTPS. They can identify and store the origin from which a file has been written, such as a mounted drive (e.g., NFS, SMB) on the network, a mount point on the file system, or a domain name of a server. In one implementation, they can identify and store the original file type or format of a file as inheritance metadata. A child file, saved with a different file type or format than a parent file, inherits a subset of the parent file's metadata in the form of inheritance metadata. Put together, the origin can identify information a data source, a parent file, a user, or a user group. In yet other implementations, when a file or document is locally created on an endpoint, the decision to run a DLP scan on such a file can be conditional on the origin of the file and whether the origin is sensitive. NARAYANASWAMY also discloses sensitive data such as identity information of the sender. Regarding, AI-generated communication, the claim 1 does not contain any generation of the communication by the AI (software). Regarding, C. Narayanaswamy Does Not Teach Intercepting AI-Generated Content or Treating AI-Generated Content as Sensitive Data Under the Claimed Workflow Narayanaswamy does not disclose artificial intelligence tools, AI-generated output, or AI-generated content treated as sensitive under a DLP policy. Narayanaswamy is directed to small-footprint endpoint DLP using previously generated sensitivity metadata for documents, not to tracking AI- generated content across later modified content. However, the claim 1 does not claim above underlined limitations. The claimed tool is not limited to AI-generated. As Applicant claimed, all the content is subject to generate other than AI. Regarding, CN does not teach the claimed DLP workflow; the CN reference is not relied upon for it. Regarding, Claim 1 does not merely require analysis after interception. It requires intercepting AI-generated first content, creating and storing an identifier for a first … However, the claim 1 fails to claim that the AI-generated first content. It is the communication that is originated from the tool like any device would communicate. It does not mean that the AI-generated first content. Communicating and generating a content is not same. F. Official Notice Cannot Supply the Missing Identifier-Comparison Architecture the Amended Identifier-Comparison Limitation is rather rejected under the new prior art. The Examiner must provide documentary evidence to support the noticed facts if the rejection is to be maintained. However, the remarks are contrary to each other. The applicant already argued against the CN 110620846 B (evidence of the official notice). Official Notice is limited to facts capable of instant and unquestionable demonstration as being well-known. The missing features here are not peripheral facts. They include treating AI-generated content as sensitive under a DLP policy, storing an identifier for the AI-generated content in a content tracking database, and later comparing a second identifier derived from modified second content with the stored identifier. However, the above limitations are not part of the argued claim 1. Also, the official notice is not taken for it. The comparing is rejected using the new reference. NARAYANASWAMY substantially discloses a method comprising: [0068] Cloud-based content sensitivity scanner 165 can perform the sensitivity classification in real-time when the documents are intercepted by the inspection service 155, while in transit to or from the cloud-based services 128A-Z. It can also perform the sensitivity classification when the documents are crawled or registered by the inspection service 155, while at rest in the cloud-based services 128A-Z. It encodes the results of the sensitivity classification in the sensitivity metadata, e.g., by assigning a “sensitive” or “non-sensitive” flag (or label) to a classification field of the sensitivity metadata. Results of sensitivity scanning can be stored 578 in a cloud-based metadata store 145. Additional details about the scanner 165 can be found in the incorporated materials. determining that the communication includes a first content addressed by a data loss prevention policy, where the first content is sensitive data generated by the source [0137] One implementation of the disclosed method further includes, in response to detecting a revision or copying of a downloaded document, reevaluating sensitivity of the revised or copied document, generating sensitivity metadata that labels the revised or copied document as sensitive, and updating the local metadata store with the sensitivity metadata generated for the revised or copied document. The disclosed method can further include, in response to detecting data egress events at the endpoint that would push data in the revised or copied document from the endpoint to uncontrolled locations, determining that the revised or copied document is sensitive based on looking up the sensitivity metadata for the revised or copied document in the local metadata store and without scanning the revised or copied document at the endpoint for sensitivity; and enforcing a data loss prevention policy at the endpoint based on the determination. In some cases, the disclosed method further includes embedding the sensitivity metadata. creating an identifier for at least a first portion of the communication; storing the identifier for at least the first portion of the communication in a content tracking database; and analyzing a second portion of second content on a network, from the client device, [0069] Some examples of the sensitivity metadata generated by the inspection service 155 and the cloud-based content sensitivity scanner 165 are unique document identifier, document integrity checksum such as MD5, document fingerprint such as Rabin fingerprint, document true file type such as portable document format (PDF), name of the cloud-based service on which a document is stored, sensitivity (or non-sensitivity) of the document, type of sensitivity such as PCI, PII, and ePHI, name and sensitivity (or non-sensitivity) of the source from which the document originated (e.g., a source cloud-based service, a source website, a source server, a source database, a source partition, a source user, a source user group, a source folder, a source device), inheritance information such as a PDF file created from an original word processing application, and log of activities performed on the document such as creation, revision, versioning, cloning, deletion, sharing, and transmission to or from the cloud-based service. Additional examples of the sensitivity metadata can be found in the incorporated materials. protected by the data loss prevention policy to determine whether the second portion of the second content includes at least part of the first portion of the communication, wherein the second content a modified version of the first content. [0139] In other implementations, a combination of the endpoint traffic monitor and the file system monitor can interpret file system calls issued on common protocols used for transferring files like SMB, NFS, FTP, HTTP, and HTTPS. They can identify and store the origin from which a file has been written, such as a mounted drive (e.g., NFS, SMB) on the network, a mount point on the file system, or a domain name of a server. In one implementation, they can identify and store the original file type or format of a file as inheritance metadata. A child file, saved with a different file type or format than a parent file, inherits a subset of the parent file's metadata in the form of inheritance metadata. Put together, the origin can identify information a data source, a parent file, a user, or a user group. In yet other implementations, when a file or document is locally created on an endpoint, the decision to run a DLP scan on such a file can be conditional on the origin of the file and whether the origin is sensitive. NARAYANASWAMY also discloses sensitive data such as identity information of the sender. However, NARAYANASWAMY does not specifically mention about the software being artificial intelligence tool. However, one of ordinary skill in the art would readily know that use of the artificial intelligence tool is well-known in the art, rather novel and hence official notice is taken. For example, CN 110620846 B discloses, after obtaining the encryption processing result, can intercept all content or part of the content from the encryption processing result as the sender identification. As an example, MD5 can be used to encrypt the first time stamp to obtain a 32-bit character string, then intercepting the content of the middle 8-24 bit of the 32-bit character string as the sender identifier, 2nd last para, page 8 the first message identifier comprises a sender identifier, further comprises a message type identifier, message template identifier, intelligent message identifier, safety least one of the identifier and the combination condition. wherein the message type identification is used for indicating message type of message content, message template identification is used for indicating message content is message template generated based on message template or message content, intelligent message identification for indicating message content is generated by artificial intelligence; safety is used for safety the message, last para, page 8 the adopted encryption algorithm can be MD5, Base64 or hash algorithm and so on. Optionally, after obtaining the encryption processing result, it can intercept all content or part of the content from the encryption processing result as a message type identification. For example, the 16-bit character can be taken as the message template identifier, 2nd para, page 10 the message content is generated by artificial intelligence, such as generated by intelligent customer service, the message can be called intelligent message, and generating intelligent message identifier for the message content, last 4th para, page 10 Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention disclosed by NARAYANASWAMY to include the software being artificial intelligence tool and also one of ordinary skill in the art would have been motivated to do so because it could provide utilizing the software (tool) for communicating information/message to another entity. The tool provided communication would enable generating and transferring information to a remote device for further processing to implement an action. NARAYANASWAMY do not disclose, which Bjarnason discloses subsequent to intercepting the communication (analyzing subsequent to the interception, para 31). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention disclosed by NARAYANASWAMY and also one of ordinary skill in the art would have been motivated to do so because it could provide utilizing the intercepting along with the analyzing. The intercepting would enable collection of data, which would be available so that analyzing of the data would be possible. The analyzing of the data would enable implementing the security for the communications. NARAYANASWAMY and Bjarnason do not disclose, which Janaudy discloses comparing a second identifier derived from the second portion of the second content with the stored identifier (comparing the second hash to the derived hash and responsive to a determination that the second hash matches the derived hash providing a confirmation that the second entity/portion includes the first entity/portion, claim 25. [0249] For example, “communication,” “communicate,” “connection,” “connect,” or other similar terms should generally be construed broadly to mean a wired, wireless, and/or other form of, as applicable, connection between elements, devices, computing devices, telephones, processors, controllers, servers, networks, telephone networks, the cloud, and/or the like, which enable voice and/or data to be sent, transmitted, broadcasted, received, intercepted, acquired, and/or transferred (each as applicable). [0250] Furthermore, a digital asset (as used in the present disclosure) is a term known in the art and, where applicable, may include and/or broadly and equivalently refer to, public key and private key pairs, and the like. Furthermore, hashing (as used in the present disclosure), or the like, is a term known in the art and, where applicable, may include and/or broadly and equivalently refer to a transformation or mapping of an input into a fixed-length string or series of characters (e.g., by using a hashing algorithm, hashing function, or the like). Similarly, a hash (as used in the present disclosure) is a term known in the art and, where applicable, may include and/or broadly refer to a fixed-length string or series of characters resulting from the hashing of an input (e.g., by using a hashing algorithm (e.g., SHA-256), hashing function, or the like). Furthermore, digitally signing, digital signing, digitally sign, signing, sign, and the like, are terms known in the art and, where applicable, may include and/or broadly and equivalently refer to creating digital signatures, including encrypting an input using a private key (i.e., for digital signatures, which is unlike the general approach of encrypting a message using a public key) so as to create a digital signature in such a manner that a recipient can, by applying a corresponding public key (i.e., a public key that corresponds to the private key used to create the digital signature; for digital signatures, the public key is used to decrypt the digital signature, which is unlike the general approach of decrypting a message using a private key), validate that the digital signature was signed (or encrypted) by the private key. [0045] software, software licenses [0246] Another example embodiment of the proof of authority verification process, which is used to verify whether or not an entity has been authorized by the owner of the digital asset to be the custodian of the digital asset, may include obtaining a public key of the digital asset. For example, the public key of the digital asset may be stored in and/or accessible/available (e.g., publicly available) from database 130. The proof of authority verification process may also include obtaining a signed proof of authority hash of the digital asset (e.g., obtaining from the database 130). In addition to obtaining the signed proof of authority hash of the digital asset, the proof of authority verification process may also include obtaining a proof of authority hash of the digital asset. The proof of authority verification process may also include obtaining a proof of management hash and/or a signed proof of management hash of the digital asset (e.g., obtaining from the database 130). Alternatively or in addition, the proof of authority verification process may include obtaining the proof of ownership hash and/or signed proof of ownership hash of the digital asset (e.g., obtaining from the database 130), obtaining the public key of the authorized custodian (e.g., obtaining from the database 130), and generating (or verifying) the proof of management hash and/or signed proof of management hash using the obtained proof of ownership hash and/or signed proof of ownership hash (in the same manner as described above and in the present disclosure). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the invention disclosed by NARAYANASWAMY and also one of ordinary skill in the art would have been motivated to do so because it could provide utilizing the comparison of the two identifiers. The comparison would enable whether two content are different or not, which would further enable determining whether both the content belongs to the same owner or not, para 45. Conclusion The additional limitations, comparing a second identifier derived from the second portion of the second content with the stored identifier, which includes for example, comparing the hashes with deriving is well-known technique in the art for deciding whether two entities/contents match or not. When they do not match it means that the contents are not related and an action can be taken. Mere addition of such well-known comparison using hashes for software entity, would not overcome the rejections. Please see above response to arguments, which argues about AI-generated content, etc., which do not exist in the claim 1. Pertinent prior art: Bjarnason et al., 20230164176 [0031] More specifically, at step 202, the mitigation device 102 receives a subset of structured data having a plurality of fields. For example, this subset may include a subset (snapshot) of the traffic flow records. In one embodiment, the mitigation device 102 may obtain data that is representative of particular network traffic transmitted over a network during a particular time interval which may be loaded, for example, from a Packet Capture (PCAP) file or some other type of log file. In another embodiment, packets flowing through the network may be intercepted and analyzed by the mitigation device 102 to detect whether or not one or more components of the protected network 100 are being attacked and/or protect the one or more protected components 108 from being overloaded. In some embodiments functionality of the mitigation device 102 may include selective interception of packets, selective modification of those intercepted packets and the subsequent release/reinsertion of the packets, modified or unmodified, and/or release of new packets, back into the general stream of network traffic. Table 1 shown below illustrates an exemplary snapshot that includes packet header information associated with ten different packets. While only ten packets are shown in Table 1, a subset can comprise any number of packets. For example, a subset can comprise from approximately 1000 packets to approximately 5000 packets. As computational systems become more powerful, it is conceivable that the mitigation device 102 can process a substantially higher number of packets without degrading the overall performance of the system. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jorge L. Ortiz-Criado, can be reached at (571) 272-7624. The fax phone number for the organization where this application or proceeding is assigned is (571) 273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /HARESH N PATEL/Primary Examiner, Art Unit 2496
Read full office action

Prosecution Timeline

Show 6 earlier events
Sep 29, 2025
Examiner Interview Summary
Sep 29, 2025
Examiner Interview (Telephonic)
Oct 20, 2025
Final Rejection mailed — §103
Jan 20, 2026
Request for Continued Examination
Jan 27, 2026
Response after Non-Final Action
Apr 06, 2026
Non-Final Rejection mailed — §103
Jul 06, 2026
Response Filed
Sep 21, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12739244
LIGHTWEIGHT AUTHENTICATION PROTOCOL USING DEVICE TOKENS
3y 8m to grant Granted Sep 15, 2026
Patent 12732813
COMMUNICATION METHOD, APPARATUS, AND SYSTEM
2y 6m to grant Granted Sep 08, 2026
Patent 12724867
Cross-Device Authentication Using Target Authentication Manner Method and Electronic Device
3y 0m to grant Granted Sep 01, 2026
Patent 12726818
INFORMATION PROCESSING APPARATUS, METHOD OF CONTROLLING INFORMATION PROCESSING APPARATUS, AND STORAGE MEDIUM
2y 11m to grant Granted Sep 01, 2026
Patent 12719861
AUTHENTICATING USERS DURING AND AFTER SUSPICIOUS VOICE CALLS AND BROWSING
3y 4m to grant Granted Aug 25, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
78%
Grant Probability
99%
With Interview (+21.4%)
3y 0m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 837 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month