Prosecution Insights
Last updated: October 02, 2026
Application No. 18/618,826

MIGRATING COMPROMISED WORKLOADS TO THREAT DETECTING COMPUTATIONAL STORAGE

Non-Final OA §103
Filed
Mar 27, 2024
Examiner
JOHNSON, TODD JEFFREY
Art Unit
Tech Center
Assignee
International Business Machines Corporation
OA Round
1 (Non-Final)
Grant Probability
Favorable
1-2
OA Rounds

Examiner Intelligence

Grants only 0% of cases
0%
Career Allowance Rate
0 granted / 0 resolved
-60.0% vs TC avg
Minimal +0% lift
Without
With
+0.0%
Interview Lift
resolved cases with interview
Typical timeline
Avg Prosecution
7 currently pending
Career history
1
Total Applications
across all art units
This examiner has no resolved cases yet (career too new); statute-level performance unavailable. The Grant Probability card shows Tech Center averages instead.

Office Action

§103
DETAILED ACTION The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This office action is in response to claims filed 03/27/2024. Claims 1-20 are pending. Specification The disclosure is objected to because of the following informalities: block 200 is mentioned but not labeled or explained in the specification. It is also not labeled on the drawings. . Appropriate correction is required. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1, 2, 4, 6-9, 11, 13-16, 18, 20 are rejected under 35 U.S.C. 103 as being unpatentable over Yim et al Pub. No. US 20240143764 A1 (hereafter Yim) in view of Takahashi et al Pub. No. US 8799600 B2 (hereafter Takahashi) and in further view of Pabón et al Pub. No. US 20240037259 A1 (here after Pabón) and in further view of Bhagi et al Pub. No. US 12259977 B2 (hereafter Bhagi). With regards to claim 1, Yim teaches A computer program product, the computer program product comprising a computer readable storage medium having program instructions embodied therewith, the program instructions executable by a processor to cause the processor to perform operations for: (These program instructions may also be stored in a computer readable storage medium that can direct a computer system, other programmable data processing apparatus, controller, or other device to operate in a particular manner, such that the instructions stored in the computer readable medium produce an article of manufacture including instructions which implement the operations specified in the block diagram block or blocks. [0076])receiving a notification of a compromised workload from a threat detecting computational storage that identified a threat, wherein the threat detecting computational storage comprises compute capabilities on computational storage, (The ransomware protection engine may also implement ransomware detection in the domain of the storage device by implementing inline ransomware attack detection, and/or implementing near-line ransomware attack detection, using periodic snapshots and evaluating probability of a ransomware attack based, at least in part, on a delta change set in consecutive snapshots. [0009]An administrator, or administrative function, may, in accordance with various embodiments of the present systems and methods, be alerted to this event to take appropriate actions while the end-point device (IHS) continues to operate fully using the secure alternate boot device [0070])and wherein one or more initial volumes of the compromised workload are stored on the computational storage; (there are many types of ransomware attacks. Some focus on encrypting the data and others on encrypting the boot device by either encrypting the entire device, critical portions of the device [0005]. Fig 2-4 show a possible embodiment of initial volumes as NAND blocks. Eventually, the SSD may need space and its garbage collection firmware reclaims the space in NAND blocks with invalid data. To that end, (the) garbage collection function(s) copies the data still valid to a new NAND block and erases the old NAND block. FTL is updated to point to new NAND block for corresponding moved data. [0064]).Yim does not teach identifying or migrating compromised and uncompromised workloads. However, in analogous art, Pabón teaches identifying one or more additional volumes of the compromised workload stored on one or more storage devices; identifying one or more related volumes of the compromised workload stored on the one or more storage devices; (Based on a mapping of such dependencies between volumes, the storage management system may determine whether a request to perform an operation on a particular volume may affect other volumes in the storage system. Based on such a determination, the storage management system may determine that the request to perform the operation may be a security threat [0274]). It would have been obvious to a person have ordinary skill in the art prior to the effective filing date of the claimed invention to combine identifying additional and related volumes of Pabón with the identifying and notifying the system of a compromised workload on a computational storage of Yim in order to provide a complete detection of all initial, additional and related volumes of compromised workloads. A person having ordinary skill in the art would have motivated to make this combination, with a reasonable expectation of success for the purpose of identifying all additional and related volumes of the compromised initial volumes in order to perform remedial actions. (Remedial action 510 may include any suitable action that may counteract and/or mitigate potential effects of the possible security threat. [0288])Yim and Pabón do not teach identifying volumes for the purpose of migrating them to other storage locations. However, in analogous art, Takahashi teaches identifying one or more additional volumes of the compromised workload stored on one or more storage devices; identifying one or more related volumes of the compromised workload stored on the one or more storage devices; (a migration group is constituted by a plurality of mutually related volumes, in such a manner that data can be relocated with respect to a group unit, in a single operation. It is possible to extract a group of mutually related volumes by searching the corresponding host management table T4. Col 15 lines 12-18. Each migration group may be constituted by grouping together volumes storing data groups used by the same application program, or volumes storing data groups forming the same file system. Col 15 lines 25-28)migrating the one or more additional volumes and the one or more related volumes from the one or more storage devices to the computational storage; (the user investigates relocation of the data stored in the plurality of mutually related volumes V1, V2, and decides, for example, to move the data from storage layer 1 to storage layer 3…The user issues a single instruction indicating relocation of the source volumes V1, V2, and instructs that they be moved to storage layer 3. Col 6 lines 57-63) It would have been obvious to a person have ordinary skill in the art prior to the effective filing date of the claimed invention to combine identifying and migrating additional and related volumes of Takahashi with the identifying and notifying the system of a compromised workload on a computational storage of Yim and Pabón in order to provide a complete detection and migration of all initial, additional and related volumes of compromised workloads. A person having ordinary skill in the art would have motivated to make this combination, with a reasonable expectation of success to provide a storage system and a data relocation control device having improved usability, by allowing the data stored respectively in a plurality of mutually related volumes to be relocated together, in one operation (in at least Takahashi Col 2 lines 3-6)Yim, Pabón, and Takahashi do not teach migrating or relocating uncompromised volumes.However, in analogous art, Bhagi teaches and migrating one or more uncompromised volumes on the computational storage to the one or more storage devices. (when potential malware and/or ransomware is detected, and after locking one or more data volumes, the volume driver 306 may instruct the one or more data agent(s) 142 to back up unaffected file(s) 416 to the secure cloud storage 310 in an attempt to preserve files that have yet to be affected by the ransomware and/or malware, and to ensure that such files will not be subject to other ransomware and/or malware. Col 54 lines 36 - 43). It would have been obvious to a person having ordinary skill in the art prior to the effective filing date of the claimed invention to combine the migration of uncompromised volumes of Bhagi with the threat monitoring detection of Yim and Pabón who also illustrates volume dependencies with the relocating of related/additional volumes of Takahashi to provide a storage-security system that detects a compromised workload, its associated volumes, and consolidates them for effective threat handling, while moving uncompromised volumes away from the affected storage. A person having ordinary skill in the art would have motivated to make this combination, with a reasonable expectation of success, to back up unaffected files to secure cloud storage, where the unaffected files in the secure cloud storage are protected from potential modification and/or corruption by the detected ransomware and/or malware. (in at least Bhagi Col 2 lines 24-28). With regards to claim 2, Yim teaches wherein the compute capabilities comprise hardware for performing operations on data stored on the computational storage (The ransomware protection logic is implemented as part of NVMe controller 405, in a computational storage approach. In such an implementation, the ransomware protection logic...and, in some embodiments, ransomware detection engine 240...run on the integrated CPU complex 410, such as a set of ARM® processor cores, or the like in the controller 405, working on local memory 415 [0050]). With regards to claim 4, Takahashi teaches wherein the program instructions are executable by the processor to cause the processor to perform further operations for: in response to identifying the one or more additional volumes and the one or more related volumes, allocating additional capacity for the one or more additional volumes and the one or more related volumes on the computational storage. (It is possible to extract a group of mutually related volumes, by searching the corresponding host management table T4 Col 15 lines 16-18. If, at step S45, there is not free capacity equal to or greater than the capacity of the source volume, then the free capacity (Q2) in that VDEV is secured (S81), and the differential capacity (Q3) between the capacity (Q1) of the source volume and the secured free capacity (Q2) is found (S82)….a new volume (LDEV) having the same capacity as the source volume is created, using the free capacity in this VDEV and the free capacity secured in the previous VDEV (S85) Col 23 lines 15-31). With regards to claim 6, Takahashi teaches wherein the one or more related volumes are identified using any combination of volume group details, volume copy information, pool membership, mapping information, and tiering correlations. (It is possible to extract a group of mutually related volumes, by searching the corresponding host management table T4…The migration group management table T5 may associate, for example, a group number, a group name, the logical ID identifying the volume belonging to that group, and the name of the storage layer to which that group currently belongs Col 15 lines 16-23). With regards to claim 7, Bhagi teaches wherein the compute capabilities monitor the one or more initial volumes, the one or more additional volumes, and the one or more related volumes on the computational storage for threats. (the entropy driver 304 monitors data volumes of the client computing device 102 based on one or more of the entropy driver policies 420. For example, one or more of the entropy driver policies 420 may specify the data volumes the entropy driver 304 is to monitor, the frequency at which the entropy driver 304 is to monitor the specified data volumes, the actions the entropy driver 304 is supposed to take based on detected ransomware and/or malware, and any other such policies or combinations thereof Col 55 lines 7-15) With regards to claim 8, Yim teaches A computer system, comprising: one or more processors, one or more computer-readable memories and one or more computer-readable, tangible storage devices; and program instructions, stored on at least one of the one or more computer-readable, tangible storage devices for execution by at least one of the one or more processors via at least one of the one or more computer-readable memories, to perform operations comprising:receiving a notification of a compromised workload from a threat detecting computational storage that identified a threat, wherein the threat detecting computational storage comprises compute capabilities on computational storage, (The ransomware protection engine may also implement ransomware detection in the domain of the storage device by implementing inline ransomware attack detection, and/or implementing near-line ransomware attack detection, using periodic snapshots and evaluating probability of a ransomware attack based, at least in part, on a delta change set in consecutive snapshots. [0009]An administrator, or administrative function, may, in accordance with various embodiments of the present systems and methods, be alerted to this event to take appropriate actions while the end-point device (IHS) continues to operate fully using the secure alternate boot device [0070])and wherein one or more initial volumes of the compromised workload are stored on the computational storage; (there are many types of ransomware attacks. Some focus on encrypting the data and others on encrypting the boot device by either encrypting the entire device, critical portions of the device [0005]. Fig 2-4 show a possible embodiment of initial volumes as NAND blocks. Eventually, the SSD may need space and its garbage collection firmware reclaims the space in NAND blocks with invalid data. To that end, (the) garbage collection function(s) copies the data still valid to a new NAND block and erases the old NAND block. FTL is updated to point to new NAND block for corresponding moved data. [0064]).).Yim does not teach identifying or migrating compromised and uncompromised workloads. However, in analogous art, Pabón teaches identifying one or more additional volumes of the compromised workload stored on one or more storage devices; identifying one or more related volumes of the compromised workload stored on the one or more storage devices; (Based on a mapping of such dependencies between volumes, the storage management system may determine whether a request to perform an operation on a particular volume may affect other volumes in the storage system. Based on such a determination, the storage management system may determine that the request to perform the operation may be a security threat [0274]).It would have been obvious to a person have ordinary skill in the art prior to the effective filing date of the claimed invention to combine identifying additional and related volumes of Pabón with the identifying and notifying the system of a compromised workload on a computational storage of Yim in order to provide a complete detection of all initial, additional and related volumes of compromised workloads. A person having ordinary skill in the art would have motivated to make this combination, with a reasonable expectation of success for the purpose of identifying all additional and related volumes of the compromised initial volumes in order to perform remedial actions. (Remedial action 510 may include any suitable action that may counteract and/or mitigate potential effects of the possible security threat. [0288])Yim and Pabón do not teach identifying volumes for the purpose of migrating them to other storage locations. However, in analogous art, Takahashi teaches identifying one or more additional volumes of the compromised workload stored on one or more storage devices; identifying one or more related volumes of the compromised workload stored on the one or more storage devices; (a migration group is constituted by a plurality of mutually related volumes, in such a manner that data can be relocated with respect to a group unit, in a single operation. It is possible to extract a group of mutually related volumes by searching the corresponding host management table T4. Col 15 lines 12-18. Each migration group may be constituted by grouping together volumes storing data groups used by the same application program, or volumes storing data groups forming the same file system. Col 15 lines 25-28)migrating the one or more additional volumes and the one or more related volumes from the one or more storage devices to the computational storage; (the user investigates relocation of the data stored in the plurality of mutually related volumes V1, V2, and decides, for example, to move the data from storage layer 1 to storage layer 3…The user issues a single instruction indicating relocation of the source volumes V1, V2, and instructs that they be moved to storage layer 3. Col 6 lines 57-63).It would have been obvious to a person have ordinary skill in the art prior to the effective filing date of the claimed invention to combine identifying and migrating additional and related volumes of Takahashi with the identifying and notifying the system of a compromised workload on a computational storage of Yim and Pabón in order to provide a complete detection and migration of all initial, additional and related volumes of compromised workloads. A person having ordinary skill in the art would have motivated to make this combination, with a reasonable expectation of success to provide a storage system and a data relocation control device having improved usability, by allowing the data stored respectively in a plurality of mutually related volumes to be relocated together, in one operation (in at least Takahashi Col 2 lines 3-6)Yim, Pabón and Takahashi do not teach migrating or relocating uncompromised volumes.However, in analogous art, Bhagi teaches and migrating one or more uncompromised volumes on the computational storage to the one or more storage devices. (when potential malware and/or ransomware is detected, and after locking one or more data volumes, the volume driver 306 may instruct the one or more data agent(s) 142 to back up unaffected file(s) 416 to the secure cloud storage 310 in an attempt to preserve files that have yet to be affected by the ransomware and/or malware, and to ensure that such files will not be subject to other ransomware and/or malware. Col 54 lines 36 - 43). It would have been obvious to a person having ordinary skill in the art prior to the effective filing date of the claimed invention to combine the migration of uncompromised volumes of Bhagi with the threat monitoring detection of Yim and Pabón who also illustrates volume dependencies with the relocating of related/additional volumes of Takahashi to provide a storage-security system that detects a compromised workload, its associated volumes, and consolidates them for effective threat handling, while moving uncompromised volumes away from the affected storage. A person having ordinary skill in the art would have motivated to make this combination, with a reasonable expectation of success, to back up unaffected files to secure cloud storage, where the unaffected files in the secure cloud storage are protected from potential modification and/or corruption by the detected ransomware and/or malware. (in at least Bhagi Col 2 lines 24-28). With regards to claim 9, Yim teaches wherein the compute capabilities comprise hardware for performing operations on data stored on the computational storage. (The ransomware protection logic is implemented as part of NVMe controller 405, in a computational storage approach. In such an implementation, the ransomware protection logic...and, in some embodiments, ransomware detection engine 240...run on the integrated CPU complex 410, such as a set of ARM® processor cores, or the like in the controller 405, working on local memory 415 [0050]). With regards to claim 11, Takahashi teaches wherein the program instructions further perform operations comprising: in response to identifying the one or more additional volumes and the one or more related volumes, allocating additional capacity for the one or more additional volumes and the one or more related volumes on the computational storage. (It is possible to extract a group of mutually related volumes, by searching the corresponding host management table T4 Col 15 lines 16-18. If, at step S45, there is not free capacity equal to or greater than the capacity of the source volume, then the free capacity (Q2) in that VDEV is secured (S81), and the differential capacity (Q3) between the capacity (Q1) of the source volume and the secured free capacity (Q2) is found (S82)….a new volume (LDEV) having the same capacity as the source volume is created, using the free capacity in this VDEV and the free capacity secured in the previous VDEV (S85) Col 23 lines 15-31). With regards to claim 13, Takahashi teaches wherein the one or more related volumes are identified using any combination of volume group details, volume copy information, pool membership, mapping information, and tiering correlations. (It is possible to extract a group of mutually related volumes, by searching the corresponding host management table T4…The migration group management table T5 may associate, for example, a group number, a group name, the logical ID identifying the volume belonging to that group, and the name of the storage layer to which that group currently belongs Col 15 lines 16-23). With regards to claim 14, Bhagi teaches wherein the compute capabilities monitor the one or more initial volumes, the one or more additional volumes, and the one or more related volumes on the computational storage for threats. (the entropy driver 304 monitors data volumes of the client computing device 102 based on one or more of the entropy driver policies 420. For example, one or more of the entropy driver policies 420 may specify the data volumes the entropy driver 304 is to monitor, the frequency at which the entropy driver 304 is to monitor the specified data volumes, the actions the entropy driver 304 is supposed to take based on detected ransomware and/or malware, and any other such policies or combinations thereof Col 55 lines 7-15). With regards to claim 15, Yim teaches A computer-implemented method, comprising operations for: receiving a notification of a compromised workload from a threat detecting computational storage that identified a threat, wherein the threat detecting computational storage comprises compute capabilities on computational storage, and wherein one or more initial volumes of the compromised workload are stored on the computational storage; (The ransomware protection engine may also implement ransomware detection in the domain of the storage device by implementing inline ransomware attack detection, and/or implementing near-line ransomware attack detection, using periodic snapshots and evaluating probability of a ransomware attack based, at least in part, on a delta change set in consecutive snapshots. [0009]An administrator, or administrative function, may, in accordance with various embodiments of the present systems and methods, be alerted to this event to take appropriate actions while the end-point device (IHS) continues to operate fully using the secure alternate boot device [0070])and wherein one or more initial volumes of the compromised workload are stored on the computational storage; (there are many types of ransomware attacks. Some focus on encrypting the data and others on encrypting the boot device by either encrypting the entire device, critical portions of the device [0005]. Fig 2-4 show a possible embodiment of initial volumes as NAND blocks. Eventually, the SSD may need space and its garbage collection firmware reclaims the space in NAND blocks with invalid data. To that end, (the) garbage collection function(s) copies the data still valid to a new NAND block and erases the old NAND block. FTL is updated to point to new NAND block for corresponding moved data. [0064]).).Yim does not teach identifying or migrating compromised and uncompromised workloads. However, in analogous art, Pabón teaches identifying one or more additional volumes of the compromised workload stored on one or more storage devices; identifying one or more related volumes of the compromised workload stored on the one or more storage devices; (Based on a mapping of such dependencies between volumes, the storage management system may determine whether a request to perform an operation on a particular volume may affect other volumes in the storage system. Based on such a determination, the storage management system may determine that the request to perform the operation may be a security threat [0274]).It would have been obvious to a person have ordinary skill in the art prior to the effective filing date of the claimed invention to combine identifying additional and related volumes of Pabón with the identifying and notifying the system of a compromised workload on a computational storage of Yim in order to provide a complete detection of all initial, additional and related volumes of compromised workloads. A person having ordinary skill in the art would have motivated to make this combination, with a reasonable expectation of success for the purpose of identifying all additional and related volumes of the compromised initial volumes in order to perform remedial actions. (Remedial action 510 may include any suitable action that may counteract and/or mitigate potential effects of the possible security threat. [0288])Yim and Pabón do not teach identifying volumes for the purpose of migrating them to other storage locations. However, in analogous art, Takahashi teaches identifying one or more additional volumes of the compromised workload stored on one or more storage devices; identifying one or more related volumes of the compromised workload stored on the one or more storage devices; (a migration group is constituted by a plurality of mutually related volumes, in such a manner that data can be relocated with respect to a group unit, in a single operation. It is possible to extract a group of mutually related volumes by searching the corresponding host management table T4. Col 15 lines 12-18. Each migration group may be constituted by grouping together volumes storing data groups used by the same application program, or volumes storing data groups forming the same file system. Col 15 lines 25-28)migrating the one or more additional volumes and the one or more related volumes from the one or more storage devices to the computational storage; (the user investigates relocation of the data stored in the plurality of mutually related volumes V1, V2, and decides, for example, to move the data from storage layer 1 to storage layer 3…The user issues a single instruction indicating relocation of the source volumes V1, V2, and instructs that they be moved to storage layer 3. Col 6 lines 57-63).It would have been obvious to a person have ordinary skill in the art prior to the effective filing date of the claimed invention to combine identifying and migrating additional and related volumes of Takahashi with the identifying and notifying the system of a compromised workload on a computational storage of Yim and Pabón in order to provide a complete detection and migration of all initial, additional and related volumes of compromised workloads. A person having ordinary skill in the art would have motivated to make this combination, with a reasonable expectation of success to provide a storage system and a data relocation control device having improved usability, by allowing the data stored respectively in a plurality of mutually related volumes to be relocated together, in one operation (in at least Takahashi Col 2 lines 3-6)Yim, Pabón and Takahashi do not teach migrating or relocating uncompromised volumes.However, in analogous art, Bhagi teaches and migrating one or more uncompromised volumes on the computational storage to the one or more storage devices. (when potential malware and/or ransomware is detected, and after locking one or more data volumes, the volume driver 306 may instruct the one or more data agent(s) 142 to back up unaffected file(s) 416 to the secure cloud storage 310 in an attempt to preserve files that have yet to be affected by the ransomware and/or malware, and to ensure that such files will not be subject to other ransomware and/or malware. Col 54 lines 36 - 43).It would have been obvious to a person having ordinary skill in the art prior to the effective filing date of the claimed invention to combine the migration of uncompromised volumes of Bhagi with the threat monitoring detection of Yim and Pabón who also illustrates volume dependencies with the relocating of related/additional volumes of Takahashi to provide a storage-security system that detects a compromised workload, its associated volumes, and consolidates them for effective threat handling, while moving uncompromised volumes away from the affected storage.A person having ordinary skill in the art would have motivated to make this combination, with a reasonable expectation of success, to back up unaffected files to secure cloud storage, where the unaffected files in the secure cloud storage are protected from potential modification and/or corruption by the detected ransomware and/or malware. (in at least Bhagi Col 2 lines 24-28). With regards to claim 16, Yim teaches wherein the compute capabilities comprise hardware for performing operations on data stored on the computational storage. (The ransomware protection logic is implemented as part of NVMe controller 405, in a computational storage approach. In such an implementation, the ransomware protection logic...and, in some embodiments, ransomware detection engine 240...run on the integrated CPU complex 410, such as a set of ARM® processor cores, or the like in the controller 405, working on local memory 415 [0050]). With regards to claim 18, Takahashi teaches further comprising operations for: in response to identifying the one or more additional volumes and the one or more related volumes, allocating additional capacity for the one or more additional volumes and the one or more related volumes on the computational storage. (It is possible to extract a group of mutually related volumes, by searching the corresponding host management table T4 Col 15 lines 16-18. If, at step S45, there is not free capacity equal to or greater than the capacity of the source volume, then the free capacity (Q2) in that VDEV is secured (S81), and the differential capacity (Q3) between the capacity (Q1) of the source volume and the secured free capacity (Q2) is found (S82)….a new volume (LDEV) having the same capacity as the source volume is created, using the free capacity in this VDEV and the free capacity secured in the previous VDEV (S85) Col 23 lines 15-31). With regards to claim 20, Takahashi teaches wherein the one or more related volumes are identified using any combination of volume group details, volume copy information, pool membership, mapping information, and tiering correlations. (It is possible to extract a group of mutually related volumes, by searching the corresponding host management table T4…The migration group management table T5 may associate, for example, a group number, a group name, the logical ID identifying the volume belonging to that group, and the name of the storage layer to which that group currently belongs Col 15 lines 16-23). Claims 3, 10, and 17 are rejected under 35 U.S.C. 103 as being unpatentable over Yim et al Pub. No. US 20240143764 A1 (hereafter Yim) in view of Takahashi et al Pub. No. US 8799600 B2 (hereafter Takahashi) and in further view of Pabón et al Pub. No. US 20240037259 A1 (here after Pabón) and in further view of Bhagi et al Pub. No. US 12259977 B2 (hereafter Bhagi) as applied to claims 1, 2, 4, 6-9, 11, 13-16, 18, 20 above and in further view of Rokade et al Pub. No. US 20220050898 A1 (hereafter Rokade) With regards to claim 3, Pabón teaches wherein the program instructions are executable by the processor to cause the processor to perform further operations for: in response to identifying the one or more additional volumes of the compromised workload and the one or more related volumes, (based on the dependency mapping that specifies that volumes 504-2 and volume 504-3 depend on volume 504-1, the storage management system may determine that performing operation 508 on volume 504-1 would affect the dependencies of volume 504-2 and volume 504-3 on volume 504-1. Based on such a determination, the storage management system may determine that the request to perform operation 508 is possibly associated with a security threat against data stored by the storage system (e.g., on volume 504-1, volume 504-2, and/or volume 504-3 [0285]).Pabón does not teach turning tiering on or off with respect to a security threat.However in analogous art, Rokade teaches selectively turning off tiering for the one or more initial volumes, the one or more additional volumes, and the one or more related volumes; and in response to determining that the threat is addressed, selectively turning on the tiering for the one or more initial volumes of the compromised workload, the one or more additional volumes of the compromised workload, and for the one or more related volumes. (If, while performing the monitoring, system 400 detects a possible security threat against the dataset (Yes, decision 3204), system 400 may disable the data synchronization setting at operation 3206. As described herein, this may prevent the dataset stored by the first storage system from being synchronously replicated to the second storage system. Alternatively, if system 400 does not detect a possible security threat against the dataset (No, decision 3204), system 400 may keep the data synchronization setting for the first storage system enabled and continue monitoring at operation 3202. [0558] System 400 (and/or personnel associated with system 400) may, once the data synchronization setting for the first storage system has been disabled, verify that the dataset is actually being targeted by the security threat. Based on this verification, system 400 may perform any suitable data recovery operation with respect to the dataset as may serve a particular implementation system 400 may determine that the dataset stored by the first storage system is no longer possibly being targeted by the security threat. [0560] Based on this determination, system 400 may re-enable the data synchronization setting [0561] Examiner notes that disabling and re-enabling the data synchronization setting is equivalent to turning tiering off and back on.) It would have been obvious to a person having ordinary skill in the art prior to the effective filing date of the claimed invention to combine the disabling and reenabling of automated storage movement based on the presence of a threat of Rokade with identifying dependent volumes associated with a security threat of Yim, Takahashi, Pabón, and Bhagi. A person having ordinary skill in the art would have been motivated to make this combination, with a reasonable expectation of success, to further protect the storage system during remediation of a detected threat and to prevent the dataset stored by the first storage system from being synchronously replicated to the second storage system. (in at least Rokade [0205]) With regards to claim 10, Pabón teaches wherein the program instructions further perform operations comprising: in response to identifying the one or more additional volumes of the compromised workload and the one or more related volumes, selectively turning off tiering for the one or more initial volumes, the one or more additional volumes, and the one or more related volumes; (based on the dependency mapping that specifies that volumes 504-2 and volume 504-3 depend on volume 504-1, the storage management system may determine that performing operation 508 on volume 504-1 would affect the dependencies of volume 504-2 and volume 504-3 on volume 504-1. Based on such a determination, the storage management system may determine that the request to perform operation 508 is possibly associated with a security threat against data stored by the storage system (e.g., on volume 504-1, volume 504-2, and/or volume 504-3 [0285]).Pabón does not teach turning tiering on or off with respect to a security threat.However in analogous art, Rokade teaches and in response to determining that the threat is addressed, selectively turning on the tiering for the one or more initial volumes of the compromised workload, the one or more additional volumes of the compromised workload, and for the one or more related volumes. (If, while performing the monitoring, system 400 detects a possible security threat against the dataset (Yes, decision 3204), system 400 may disable the data synchronization setting at operation 3206. As described herein, this may prevent the dataset stored by the first storage system from being synchronously replicated to the second storage system. Alternatively, if system 400 does not detect a possible security threat against the dataset (No, decision 3204), system 400 may keep the data synchronization setting for the first storage system enabled and continue monitoring at operation 3202. [0558] System 400 (and/or personnel associated with system 400) may, once the data synchronization setting for the first storage system has been disabled, verify that the dataset is actually being targeted by the security threat. Based on this verification, system 400 may perform any suitable data recovery operation with respect to the dataset as may serve a particular implementation system 400 may determine that the dataset stored by the first storage system is no longer possibly being targeted by the security threat. [0560] Based on this determination, system 400 may re-enable the data synchronization setting [0561]. Examiner notes that disabling and re-enabling the data synchronization setting is equivalent to turning tiering off and on.) It would have been obvious to a person having ordinary skill in the art prior to the effective filing date of the claimed invention to combine the disabling and reenabling of automated storage movement based on the presence of a threat of Rokade with identifying dependent volumes associated with a security threat of Yim, Takahashi, Pabón, and Bhagi. A person having ordinary skill in the art would have been motivated to make this combination, with a reasonable expectation of success, to further protect the storage system during remediation of a detected threat and to prevent the dataset stored by the first storage system from being synchronously replicated to the second storage system. (in at least Rokade [0205]) With regards to claim 17, Pabón teaches further comprising operations for: in response to identifying the one or more additional volumes of the compromised workload and the one or more related volumes, (based on the dependency mapping that specifies that volumes 504-2 and volume 504-3 depend on volume 504-1, the storage management system may determine that performing operation 508 on volume 504-1 would affect the dependencies of volume 504-2 and volume 504-3 on volume 504-1. Based on such a determination, the storage management system may determine that the request to perform operation 508 is possibly associated with a security threat against data stored by the storage system (e.g., on volume 504-1, volume 504-2, and/or volume 504-3 [0285]).Pabón does not teach turning tiering on or off with respect to a security threat.However in analogous art, Rokade teaches selectively turning off tiering for the one or more initial volumes, the one or more additional volumes, and the one or more related volumes; and in response to determining that the threat is addressed, selectively turning on the tiering for the one or more initial volumes of the compromised workload, the one or more additional volumes of the compromised workload, and for the one or more related volumes. (If, while performing the monitoring, system 400 detects a possible security threat against the dataset (Yes, decision 3204), system 400 may disable the data synchronization setting at operation 3206. As described herein, this may prevent the dataset stored by the first storage system from being synchronously replicated to the second storage system. Alternatively, if system 400 does not detect a possible security threat against the dataset (No, decision 3204), system 400 may keep the data synchronization setting for the first storage system enabled and continue monitoring at operation 3202. [0558] System 400 (and/or personnel associated with system 400) may, once the data synchronization setting for the first storage system has been disabled, verify that the dataset is actually being targeted by the security threat. Based on this verification, system 400 may perform any suitable data recovery operation with respect to the dataset as may serve a particular implementation system 400 may determine that the dataset stored by the first storage system is no longer possibly being targeted by the security threat. [0560] Based on this determination, system 400 may re-enable the data synchronization setting [0561]. Examiner notes that disabling and re-enabling the data synchronization setting is equivalent to turning tiering off and on.) It would have been obvious to a person having ordinary skill in the art prior to the effective filing date of the claimed invention to combine the disabling and reenabling of automated storage movement based on the presence of a threat of Rokade with identifying dependent volumes associated with a security threat of Yim, Takahashi, Pabón, and Bhagi. A person having ordinary skill in the art would have been motivated to make this combination, with a reasonable expectation of success, to further protect the storage system during remediation of a detected threat and to prevent the dataset stored by the first storage system from being synchronously replicated to the second storage system. (in at least Rokade [0205]) Claims 5, 12, and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Yim et al Pub. No. US 20240143764 A1 (hereafter Yim) in view of Takahashi et al Pub. No. US 8799600 B2 (hereafter Takahashi) and in further view of Pabón et al Pub. No. US 20240037259 A1 (here after Pabón) and in further view of Bhagi et al Pub. No. US 12259977 B2 (hereafter Bhagi) as applied to claims 1, 2, 4, 6-9, 11, 13-16, 18, 20 above and in further view of Venkataramani Pub. No. US 12602473 B1 (hereafter Venkataramani) With regards to claim 5, Pabón teaches wherein the program instructions are executable by the processor to cause the processor to perform further operations for: placing a capacity limit for the one or more initial volumes, the one or more additional volumes, and the one or more related volumes on the computational storage; and in response to determining that the threat is addressed, removing the capacity limit for the one or more initial volumes, the one or more additional volumes, and the one or more related volumes on the computational storage. (the dependency mapping that specifies that volumes 504-2 and volume 504-3 depend on volume 504-1, the storage management system may determine that performing operation 508 on volume 504-1 would affect the dependencies of volume 504-2 and volume 504-3 on volume 504-1. Based on such a determination, the storage management system may determine that the request to perform operation 508 is possibly associated with a security threat against data stored by the storage system [0285])Pabón does not teach placing a capacity limit for the volumes or removing the capacity limit for the volumes.However, in analogous art, Venkataramani teaches placing a capacity limit for the one or more initial volumes, the one or more additional volumes, and the one or more related volumes on the computational storage; and removing the capacity limit for the one or more initial volumes, the one or more additional volumes, and the one or more related volumes on the computational storage. (the user may set...a threshold amount of the storage space being used as temporary storage of data for requests that have not yet been committed Col 5 lines 20-23. The storage driver may also free up (e.g., make available) temporary storage space Col 12 lines 47-48. May prevent data loss from ransomware attacks Col 2 lines 41-42).It would have been obvious to a person having ordinary skill in the art prior to the effective filing date of the claimed invention to combine the storage-space threshold while evaluating the potentially malicious data of Venkataramani with the security threat on initial, related, and additional volumes of Yim, Takahashi, Pabón, and Bhagi in order to limit capacity of the identified volumes during the threat and removing the limitation after the threat is addressed.A person having ordinary skill in the art would have been motivated to make this combination, with a reasonable expectation of success, to prevent data loss from ransomware attacks (in at least Col 2 lines 41-42) With regards to claim 12, Pabón teaches wherein the program instructions further perform operations comprising: placing a capacity limit for the one or more initial volumes, the one or more additional volumes, and the one or more related volumes on the computational storage; and in response to determining that the threat is addressed, removing the capacity limit for the one or more initial volumes, the one or more additional volumes, and the one or more related volumes on the computational storage. (the dependency mapping that specifies that volumes 504-2 and volume 504-3 depend on volume 504-1, the storage management system may determine that performing operation 508 on volume 504-1 would affect the dependencies of volume 504-2 and volume 504-3 on volume 504-1. Based on such a determination, the storage management system may determine that the request to perform operation 508 is possibly associated with a security threat against data stored by the storage system [0285])Pabón does not teach placing a capacity limit for the volumes or removing the capacity limit for the volumes.However, in analogous art, Venkataramani teaches placing a capacity limit for the one or more initial volumes, the one or more additional volumes, and the one or more related volumes on the computational storage; and removing the capacity limit for the one or more initial volumes, the one or more additional volumes, and the one or more related volumes on the computational storage. (the user may set...a threshold amount of the storage space being used as temporary storage of data for requests that have not yet been committed Col 5 lines 20-23. The storage driver may also free up (e.g., make available) temporary storage space Col 12 lines 47-48. May prevent data loss from ransomware attacks Col 2 lines 41-42).It would have been obvious to a person having ordinary skill in the art prior to the effective filing date of the claimed invention to combine the storage-space threshold while evaluating the potentially malicious data of Venkataramani with the security threat on initial, related, and additional volumes of Yim, Takahashi, Pabón, and Bhagi in order to limit capacity of the identified volumes during the threat and removing the limitation after the threat is addressed.A person having ordinary skill in the art would have been motivated to make this combination, with a reasonable expectation of success, to prevent data loss from ransomware attacks (in at least Col 2 lines 41-42) With regards to claim 19, Pabón teaches further comprising operations for: placing a capacity limit for the one or more initial volumes, the one or more additional volumes, and the one or more related volumes on the computational storage; and in response to determining that the threat is addressed, removing the capacity limit for the one or more initial volumes, the one or more additional volumes, and the one or more related volumes on the computational storage. (the dependency mapping that specifies that volumes 504-2 and volume 504-3 depend on volume 504-1, the storage management system may determine that performing operation 508 on volume 504-1 would affect the dependencies of volume 504-2 and volume 504-3 on volume 504-1. Based on such a determination, the storage management system may determine that the request to perform operation 508 is possibly associated with a security threat against data stored by the storage system [0285])Pabón does not teach placing a capacity limit for the volumes or removing the capacity limit for the volumes.However, in analogous art, Venkataramani teaches placing a capacity limit for the one or more initial volumes, the one or more additional volumes, and the one or more related volumes on the computational storage; and removing the capacity limit for the one or more initial volumes, the one or more additional volumes, and the one or more related volumes on the computational storage. (the user may set...a threshold amount of the storage space being used as temporary storage of data for requests that have not yet been committed Col 5 lines 20-23. The storage driver may also free up (e.g., make available) temporary storage space Col 12 lines 47-48. May prevent data loss from ransomware attacks Col 2 lines 41-42).It would have been obvious to a person having ordinary skill in the art prior to the effective filing date of the claimed invention to combine the storage-space threshold while evaluating the potentially malicious data of Venkataramani with the security threat on initial, related, and additional volumes of Yim, Takahashi, Pabón, and Bhagi in order to limit capacity of the identified volumes during the threat and removing the limitation after the threat is addressed.A person having ordinary skill in the art would have been motivated to make this combination, with a reasonable expectation of success, to prevent data loss from ransomware attacks (in at least Col 2 lines 41-42) Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to Todd Jeffrey Johnson whose telephone number is (571)270-0929. The examiner can normally be reached M-F, 7:30am to 5pm ET. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Bradley Teets can be reached at (571) 272-3338. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /T.J.J./ Examiner, Art Unit 2197 /BRADLEY A TEETS/Supervisory Patent Examiner, Art Unit 2197
Read full office action

Prosecution Timeline

Mar 27, 2024
Application Filed
Sep 01, 2026
Non-Final Rejection mailed — §103 (current)

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
Grant Probability
Low
PTA Risk
Based on 0 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month