Prosecution Insights
Last updated: October 02, 2026
Application No. 18/582,583

INTROSPECTION DRIVEN BY INCIDENTS FOR CONTROLLING INFILTRATION

Non-Final OA §103
Filed
Feb 20, 2024
Priority
Jan 24, 2019 — divisional of 11/416,641 +1 more
Examiner
LESNIEWSKI, VICTOR D
Art Unit
2493
Tech Center
2400 — Computer Networks
Assignee
NetSkope Inc.
OA Round
3 (Non-Final)
58%
Grant Probability
Moderate
3-4
OA Rounds
8m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 58% of resolved cases
58%
Career Allowance Rate
287 granted / 491 resolved
+0.5% vs TC avg
Strong +55% interview lift
Without
With
+55.3%
Interview Lift
resolved cases with interview
Typical timeline
3y 3m
Avg Prosecution
18 currently pending
Career history
518
Total Applications
across all art units

Statute-Specific Performance

§101
8.8%
-31.2% vs TC avg
§103
58.1%
+18.1% vs TC avg
§102
16.8%
-23.2% vs TC avg
§112
13.0%
-27.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 491 resolved cases

Office Action

§103
DETAILED ACTION The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . The amendment filed 9/4/2026 has been placed of record in the file. Claims 1, 2, 5-9, and 11-14 have been amended. Claims 15-22 have been added. Claims 1, 2, and 5-22 are now pending. The double patenting rejection remains of record. The applicant’s arguments with respect to claims 1, 2, and 5-22 have been considered but are moot in view of the following new grounds of rejection. Continued Examination Under 37 CFR 1.114 A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 9/4/2026 has been entered. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1, 2, and 5-22 are rejected under 35 U.S.C. 103 as being unpatentable over Barday et al. (U.S. Patent Application Publication Number 2018/0341784), hereinafter referred to as Barday, in view of Kurtin et al. (U.S. Patent Application Publication Number 2019/0026488), hereinafter referred to as Kurtin. Barday disclosed techniques for the identification and deletion of personal data in computer systems. In an analogous art, Kurtin disclosed techniques for the identification of sensitive data in documents. Both systems are directed toward identifying and protecting personal data. Regarding claim 1, Barday discloses a tangible non-transitory computer readable storage media, including program instructions loaded into memory that, when executed on processors, cause the processors to implement a method of responding to right to be forgotten requests (paragraph 163, right to be forgotten), the method including: a cloud access security broker (abbreviated CASB) controlling exfiltration of consumer data stored on cloud-based services by a service provider (paragraph 165, Subject Access Request Module, and paragraph 186, cloud-based servers); in response to receiving a right to be forgotten request from a particular consumer, the CASB identifying one or more locations on one or more of the cloud-based services at which consumer data for the particular consumer is stored, the one or more locations comprising document locations on the one or more cloud-based services (paragraph 165, request to delete personal data, and paragraph 166, identify database, server, etc., and paragraph 205, document of particular storage location); the CASB performing deep inspection of the consumer data stored at the identified locations, the performing the deep inspection including applying one or more content inspection rules to the consumer data stored at the identified locations to identify sensitive data related to the particular consumer, and detecting at least some sensitive data related to the particular consumer in the consumer data (paragraph 166, intelligent identity scanning, and paragraphs 137-141, scan storage locations to identify personal data); and the CASB fulfilling the right to be forgotten request by removing the detected sensitive data from the cloud-based services (paragraph 169, facilitate deletion of personal data). Barday does not explicitly state performing the deep inspection at the identified document locations to identify the sensitive data. However, performing rule-based analysis on particular user documents in such a fashion was well known in the art as evidenced by Kurtin. Since the inventions encompass the same field of endeavor, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the system of Barday by adding the ability for performing the deep inspection at the identified document locations to identify the sensitive data as provided by Kurtin (see paragraphs 33-34, searches documents for personal identity information). One of ordinary skill in the art would have recognized the benefit that identifying and protecting a user’s sensitive data in this way would assist in preventing the misuse of documents containing personal information (see Kurtin, paragraph 6). Regarding claim 2, the combination of Barday and Kurtin discloses program instructions that, when executed on processors, cause the processors to implement the method further including: in addition to removing the detected sensitive data from the cloud-based services, the CASB providing the detected sensitive data to the particular consumer (Barday, paragraph 169, display personal data). Regarding claim 5, the combination of Barday and Kurtin discloses program instructions that, when executed on processors, cause the processors to implement the method, wherein the sensitive data in the consumer data is personal data referenced by an identifier including name, identification number, location data, and online identifier (Barday, paragraph 183, unique subject identifier used to fulfill data subject access request, and paragraph 218, unique subject identifier is unique user ID, e-mail address, etc.). Regarding claim 6, the combination of Barday and Kurtin discloses program instructions that, when executed on processors, cause the processors to implement the method further including: erasing any information directly or indirectly identified as related to an identifiable person corresponding to the right to be forgotten request appearing in records containing the detected sensitive data from the cloud-based services (Barday, paragraph 2, personal data includes PII). Regarding claim 7, Barday discloses a method of responding to right to be forgotten requests (paragraph 163, right to be forgotten), the method including: a cloud access security broker (abbreviated CASB) controlling exfiltration of consumer data stored on cloud-based services by a service provider (paragraph 165, Subject Access Request Module, and paragraph 186, cloud-based servers); in response to receiving a right to be forgotten request from a particular consumer, the CASB identifying one or more locations on one or more of the cloud-based services at which consumer data for the particular consumer is stored, the one or more locations comprising document locations on the one or more cloud-based services (paragraph 165, request to delete personal data, and paragraph 166, identify database, server, etc., and paragraph 205, document of particular storage location); the CASB performing deep inspection of the consumer data stored at the identified locations, the performing the deep inspection including applying one or more content inspection rules to the consumer data stored at the identified locations to identify sensitive data related to the particular consumer, and detecting at least some sensitive data related to the particular consumer in the consumer data (paragraph 166, intelligent identity scanning, and paragraphs 137-141, scan storage locations to identify personal data); and the CASB fulfilling the right to be forgotten request by removing the detected sensitive data from the cloud-based services (paragraph 169, facilitate deletion of personal data). Barday does not explicitly state performing the deep inspection at the identified document locations to identify the sensitive data. However, performing rule-based analysis on particular user documents in such a fashion was well known in the art as evidenced by Kurtin. Since the inventions encompass the same field of endeavor, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the system of Barday by adding the ability for performing the deep inspection at the identified document locations to identify the sensitive data as provided by Kurtin (see paragraphs 33-34, searches documents for personal identity information). One of ordinary skill in the art would have recognized the benefit that identifying and protecting a user’s sensitive data in this way would assist in preventing the misuse of documents containing personal information (see Kurtin, paragraph 6). Regarding claim 8, the combination of Barday and Kurtin discloses the CASB providing the detected sensitive data to the particular consumer (Barday, paragraph 169, display personal data). Regarding claim 9, the combination of Barday and Kurtin discloses wherein the sensitive data in the consumer data is personal data referenced by an identifier including name, identification number, location data, and online identifier (Barday, paragraph 183, unique subject identifier used to fulfill data subject access request, and paragraph 218, unique subject identifier is unique user ID, e-mail address, etc.). Regarding claim 10, the combination of Barday and Kurtin discloses erasing any information directly or indirectly identified as related to an identifiable person corresponding to the right to be forgotten request appearing in records containing the detected sensitive data from the cloud-based services (Barday, paragraph 2, personal data includes PII). Regarding claim 11, Barday discloses a system for responding to requests to be forgotten (paragraph 163, right to be forgotten), the system including a processor, memory coupled to the processor, and computer instructions loaded into memory that, when executed on processors, cause the processors to implement a method including: a cloud access security broker (abbreviated CASB) controlling exfiltration of consumer data stored on cloud-based services by a service provider (paragraph 165, Subject Access Request Module, and paragraph 186, cloud-based servers); in response to receiving a right to be forgotten request from a particular consumer, the CASB identifying one or more locations on one or more of the cloud-based services at which consumer data for the particular consumer is stored, the one or more locations comprising document locations on the one or more cloud-based services (paragraph 165, request to delete personal data, and paragraph 166, identify database, server, etc., and paragraph 205, document of particular storage location); the CASB performing deep inspection of the consumer data stored at the identified locations, the performing the deep inspection including applying one or more content inspection rules to the consumer data stored at the identified location to identify sensitive data related to the particular consumer, and detecting at least some sensitive data related to the particular consumer in the consumer data (paragraph 166, intelligent identity scanning, and paragraphs 137-141, scan storage locations to identify personal data); and the CASB fulfilling the right to be forgotten request by removing the detected sensitive data from the cloud-based services (paragraph 169, facilitate deletion of personal data). Barday does not explicitly state performing the deep inspection at the identified document locations to identify the sensitive data. However, performing rule-based analysis on particular user documents in such a fashion was well known in the art as evidenced by Kurtin. Since the inventions encompass the same field of endeavor, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the system of Barday by adding the ability for performing the deep inspection at the identified document locations to identify the sensitive data as provided by Kurtin (see paragraphs 33-34, searches documents for personal identity information). One of ordinary skill in the art would have recognized the benefit that identifying and protecting a user’s sensitive data in this way would assist in preventing the misuse of documents containing personal information (see Kurtin, paragraph 6). Regarding claim 12, the combination of Barday and Kurtin discloses wherein the computer instructions further cause the processors to implement the method, the method further including: in addition to removing the detected sensitive data from the cloud-based services, the CASB providing the detected sensitive data to the particular consumer (Barday, paragraph 169, display personal data). Regarding claim 13, the combination of Barday and Kurtin discloses wherein the sensitive data in the consumer data is personal data referenced by an identifier including name, identification number, location data, and online identifier (Barday, paragraph 183, unique subject identifier used to fulfill data subject access request, and paragraph 218, unique subject identifier is unique user ID, e-mail address, etc.). Regarding claim 14, the combination of Barday and Kurtin discloses wherein the computer instructions further cause the processors to implement the method, the method further including: erasing any information directly or indirectly identified as related to an identifiable person corresponding to the right to be forgotten request appearing in records containing the detected sensitive data from the cloud-based services (Barday, paragraph 2, personal data includes PII). Regarding claim 15, the combination of Barday and Kurtin discloses program instructions that, when executed on processors, cause the processors to implement the method further including, removing records referenced by the identifier of the particular consumer from the identified document locations response to identification of the sensitive data using the one or more content inspection rules (Barday, paragraph 169, facilitate deletion of personal data). Regarding claim 16, the combination of Barday and Kurtin discloses removing records referenced by the identifier of the particular consumer (Barday, paragraph 169, facilitate deletion of personal data). Regarding claim 17, the combination of Barday and Kurtin discloses wherein the computer instructions further cause the processors to implement the method, the method further including: removing records referenced by the identifier of the particular consumer (Barday, paragraph 169, facilitate deletion of personal data). Regarding claim 18, the combination of Barday and Kurtin discloses wherein the identified document locations comprise at least one folder of a cloud-hosted email service or at least one folder of a cloud storage service (Kurtin, paragraph 33, cloud storage folders). Regarding claim 19, the combination of Barday and Kurtin discloses wherein the applying of the one or more content inspection rules is performed by a data loss prevention (DLP) engine of the CASB (Barday, paragraph 137, intelligent identity scanning module). Regarding claim 20, the combination of Barday and Kurtin discloses wherein the identified document locations comprise at least one folder of a cloud-hosted email service or at least one folder of a cloud storage service (Kurtin, paragraph 33, cloud storage folders). Regarding claim 21, the combination of Barday and Kurtin discloses wherein the applying of the one or more content inspection rules is performed by a data loss prevention (DLP) engine of the CASB (Barday, paragraph 137, intelligent identity scanning module). Regarding claim 22, the combination of Barday and Kurtin discloses wherein to perform the deep inspection, the computer instructions cause the CASB to apply the one or more content inspection rules using a data loss prevention (DLP) engine of the CASB (Barday, paragraph 137, intelligent identity scanning module). Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to Victor Lesniewski whose telephone number is (571)272-2812. The examiner can normally be reached Monday thru Friday, 9am to 5pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Carl Colin can be reached at 571-272-3862. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /Victor Lesniewski/Primary Examiner, Art Unit 2493
Read full office action

Prosecution Timeline

Show 2 earlier events
May 12, 2026
Response Filed
Jul 17, 2026
Final Rejection mailed — §103
Aug 26, 2026
Interview Requested
Sep 01, 2026
Examiner Interview Summary
Sep 01, 2026
Applicant Interview (Telephonic)
Sep 04, 2026
Request for Continued Examination
Sep 11, 2026
Response after Non-Final Action
Sep 21, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750362
SECURE ELEMENT ARRAYS IN INTERNET-OF-THINGS SYSTEMS
3y 5m to grant Granted Sep 29, 2026
Patent 12743512
SYSTEMS AND METHODS FOR REAL-TIME DATABASE SCANNING USING REPLICATION STREAM
2y 3m to grant Granted Sep 22, 2026
Patent 12739249
Method and Apparatus for Authentication and Authorization
3y 9m to grant Granted Sep 15, 2026
Patent 12730866
ADAPTIVE USER ENROLLMENT FOR ELECTRONIC DEVICES
3y 11m to grant Granted Sep 08, 2026
Patent 12713233
METHOD AND APPARATUS FOR UE AND APPLICATION FUNCTION SESSION PROTECTION FOR MODEL TRANSFER
1y 9m to grant Granted Aug 18, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
58%
Grant Probability
99%
With Interview (+55.3%)
3y 3m (~8m remaining)
Median Time to Grant
High
PTA Risk
Based on 491 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month