Prosecution Insights
Last updated: October 02, 2026
Application No. 18/750,923

DATA LOSS PREVENTION OF ENTERPRISE INFORMATION STORED ON A CLOUD COMPUTING SERVICE (CCS)

Final Rejection §103§DOUBLEPATENT
Filed
Jun 21, 2024
Priority
Mar 19, 2015 — provisional 62/135,656 +2 more
Examiner
DOAN, TRANG T
Art Unit
2431
Tech Center
2400 — Computer Networks
Assignee
NetSkope Inc.
OA Round
2 (Final)
83%
Grant Probability
Favorable
3-4
OA Rounds
1y 0m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 83% — above average
83%
Career Allowance Rate
526 granted / 634 resolved
+25.0% vs TC avg
Strong +17% interview lift
Without
With
+16.8%
Interview Lift
resolved cases with interview
Typical timeline
3y 4m
Avg Prosecution
16 currently pending
Career history
658
Total Applications
across all art units

Statute-Specific Performance

§101
15.2%
-24.8% vs TC avg
§103
35.6%
-4.4% vs TC avg
§102
19.7%
-20.3% vs TC avg
§112
19.7%
-20.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 634 resolved cases

Office Action

§103 §DOUBLEPATENT
DETAILED ACTION In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. This Office Action is in response to the communication filed on 5/4/2026. Claims 1-2 and 12-13 have been amended. Claims 1-20 are pending for consideration. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Arguments Regarding the 112(a) rejection of claims 2 and 13, the claims have been amended. Therefore, the rejection has been withdrawn. Regarding the double patenting rejection, the pending claims are still rejectable under non-statutory double patenting over claims 1 - 19 of U.S. Patent No. 9,928,377 and claims 1 - 16 of U.S. Patent No. 12,056,235. Therefore, the rejections have been maintained. Applicant’s arguments with respect to claim(s) 1-20 have been considered but are moot. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer. Claims 1-20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-19 of U.S. Patent No. 9928377. Although the claims at issue are not identical, they are not patentably distinct from each other because both applications disclose a common subject matter such as applying a content inspection rule to find strings and interrelated strings in the content that are subject to content control and triggering a security action responsive to finding the strings and interrelated strings subject to content control in the parsed stream (see Claims Comparison Table below). Instant application 18750923 Patent application 9928377 Claim 1: A computer-implemented method of data loss prevention for data owned by an enterprise, the computer-implemented method comprising: intermediating, with a cloud-hosted network security system, traffic between an endpoint of the enterprise and a cloud computing service (CCS);detecting activity associated with content on the CCS from the traffic; analyzing the activity to determine the activity comprises content-level activity; selecting, in response to determining that the activity comprises content-level activity, one or more portions of a content inspection policy to apply to the content, wherein: the content inspection policy comprises a plurality of content inspection profiles, each of the plurality of content inspection profiles comprises one or more content inspection rules, the one or more portions are selected based on the CCS, a user of the endpoint, a type of the activity, or a combination thereof, and the one or more content inspection rules each comprise custom inspection rules that include custom regular expressions defined by the enterprise, predefined data identifiers, or a combination thereof; applying the one or more portions to the content to identify one or more matches in the content by comparing the content and the one or more content inspection rules of each of a subset of the plurality of content inspection profiles, wherein the subset is associated with the one or more portions; and in response to identifying the one or more matches; identifying a content type based on the one or more matches, selecting a security action to control the content based at least in part on the content type and the content-level activity, and triggering the security action. Claim 1: A computer-implemented method of monitoring and controlling enterprise information stored on a cloud computing service (CCS), the method including: using a cross-application monitor to detect: a cloud computing service (CCS) application programming interface (API) in use by a client; and a function or an activity being requested by the client via the CCS API; determining the function or the activity to be performed by parsing API data exchanged via the CCS API, the parsing based on the detected CCS API, and identifying content being transmitted between the client and the CCS; selectively applying a content inspection rule with a multi-part string search pattern, based on at least the determined function or activity, to the content being transmitted between the client and the CCS to find two or more non-contiguous strings that are within a proximity specified in the content inspection rule and that, based on the finding, are therefore subject to content control; and triggering a security action responsive to finding the two or more non-contiguous strings subject to content control. Claim 3: The computer-implemented method of claim 1, further including: applying the content inspection rule to find strings and interrelated strings in metadata associated with content that is subject to content control. Claim 12: A system for data loss prevention of data owned by an enterprise, the system comprising: one or more processors; and one or more memories having stored thereon instructions that, upon execution by the one or more processors, cause the one or more processors to: intermediate traffic between an endpoint of the enterprise and a cloud computing service (CCS),detect activity associated with content on the CCS from the traffic, analyze the activity to determine the activity comprises content-level activity, select, in response to a determination that the activity comprises content-level activity, one or more portions of a content inspection policy to apply to the content, wherein: the content inspection policy comprises a plurality of content inspection profiles; each of the plurality of content inspection profiles comprises one or more content inspection rules; the one or more portions are selected based on the CCS, a user of the endpoint, a type of the activity, or a combination thereof; and the one or more content inspection rules each comprise custom inspection rules that include custom regular expressions defined by the enterprise, predefined data identifiers, or a combination thereof, apply the one or more portions to the content to identify one or more matches in the content by comparing the content and the one or more content inspection rules of each of a subset of the plurality of content inspection profiles, wherein the subset is associated with the one or more portions; and in response to identifying the one or more matches; identify a content type based on the one or more matches; select a security action to control the content based at least in part on the content type and the content-level activity; and trigger the security action. Claim 15: A system of monitoring and controlling enterprise information stored on a cloud computing service (CCS), the system including: a processor and a computer readable storage medium storing computer instructions configured to cause the processor to: use a cross-application monitor to detect: a cloud computing service (CCS) application programming interface (API) in use by a client; and a function or an activity being requested by the client via the CCS API; determine the function or the activity to be performed by parsing API data exchanged via the CCS API, the parsing based on the detected CCS API, and identifying content being transmitted between the client and the CCS; selectively apply a content inspection rule with a multi-part string search pattern, based on at least the determined function or activity, to the content being transmitted between the client and the CCS to find two or more non-contiguous strings that are within a proximity specified in the content inspection rule and that, based on the finding, are therefore subject to content control; and trigger a security action responsive to finding the two or more non-contiguous strings subject to content control. Claim 16: The system of claim 15, wherein: the content inspection rule further includes at least one multi-part string search pattern that matches two or more non-contiguous strings that collectively identify content that is subject to content control. The dependent claims of the instant application recite language similar to the dependent claims of the patent application and are covered by the patent application. Claims 1-20 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-16 of U.S. Patent No. 12056235. Although the claims at issue are not identical, they are not patentably distinct from each other because both applications disclose a common subject matter such as applying a content inspection rule to find strings and interrelated strings in the content that are subject to content control and triggering a security action responsive to finding the strings and interrelated strings subject to content control in the parsed stream (see Claims Comparison Table below). Instant application 18750923 Patent application 12056235 Claim 1: A computer-implemented method of data loss prevention for data owned by an enterprise, the computer-implemented method comprising: intermediating, with a cloud-hosted network security system, traffic between an endpoint of the enterprise and a cloud computing service (CCS);detecting activity associated with content on the CCS from the traffic; analyzing the activity to determine the activity comprises content-level activity; selecting, in response to determining that the activity comprises content-level activity, one or more portions of a content inspection policy to apply to the content, wherein: the content inspection policy comprises a plurality of content inspection profiles, each of the plurality of content inspection profiles comprises one or more content inspection rules, the one or more portions are selected based on the CCS, a user of the endpoint, a type of the activity, or a combination thereof, and the one or more content inspection rules each comprise custom inspection rules that include custom regular expressions defined by the enterprise, predefined data identifiers, or a combination thereof; applying the one or more portions to the content to identify one or more matches in the content by comparing the content and the one or more content inspection rules of each of a subset of the plurality of content inspection profiles, wherein the subset is associated with the one or more portions; and in response to identifying the one or more matches; identifying a content type based on the one or more matches, selecting a security action to control the content based at least in part on the content type and the content-level activity, and triggering the security action. Claim 1: A computer-implemented method of monitoring and controlling enterprise information stored on a cloud computing service (CCS), the method including: detecting, with a cross-application monitor, a data stream between a client of an enterprise and an application programming interface (API) of the CCS; parsing the data stream to identify an activity; analyzing the activity to determine the activity comprises content level activity based on the activity comprising manipulation of content; in response to determining that the activity comprises content level activity, applying a content inspection rule to the parsed data stream, wherein applying the content inspection rule comprises applying a multi-part string search pattern to the parsed data stream to match two or more non-contiguous strings that collectively identify content subject to content control associated with the activity; selecting a security action based on a type of the content subject to the content control; and triggering the security action to control the content. Claim 2: The computer-implemented method of claim 1, further including: using the cross-application monitor to determine a file type of a file for which the activity is being requested; and selectively applying a profile comprising a plurality of content inspection rules to content in the file based on at least the determined file type. Claim 12: A system for data loss prevention of data owned by an enterprise, the system comprising: one or more processors; and one or more memories having stored thereon instructions that, upon execution by the one or more processors, cause the one or more processors to: intermediate traffic between an endpoint of the enterprise and a cloud computing service (CCS),detect activity associated with content on the CCS from the traffic, analyze the activity to determine the activity comprises content-level activity, select, in response to a determination that the activity comprises content-level activity, one or more portions of a content inspection policy to apply to the content, wherein: the content inspection policy comprises a plurality of content inspection profiles; each of the plurality of content inspection profiles comprises one or more content inspection rules; the one or more portions are selected based on the CCS, a user of the endpoint, a type of the activity, or a combination thereof; and the one or more content inspection rules each comprise custom inspection rules that include custom regular expressions defined by the enterprise, predefined data identifiers, or a combination thereof, apply the one or more portions to the content to identify one or more matches in the content by comparing the content and the one or more content inspection rules of each of a subset of the plurality of content inspection profiles, wherein the subset is associated with the one or more portions; and in response to identifying the one or more matches; identify a content type based on the one or more matches; select a security action to control the content based at least in part on the content type and the content-level activity; and trigger the security action. Claim 9: A system for monitoring and controlling enterprise information stored on cloud computing services (CCSs), the system comprising: one or more processors; and one or more memories having stored thereon instructions that, upon execution by the one or more processors, cause the one or more processors to: detect, with a cross-application monitor of the system, a data stream between a client of an enterprise and an application programming interface (API) of a cloud computing service (CCS); parse the data stream to identify an activity; analyze the activity to determine the activity comprises content level activity based on the activity comprising manipulation of content; in response to determining that the activity comprises content level activity, applying a content inspection rule to the parsed data stream, wherein applying the content inspection rule comprises applying a multi-part string a search pattern to the parsed data stream to match two or more non-contiguous strings that collectively identify content subject to content control associated with the activity; selecting a security action based on a type of the content subject to the content control; and triggering the security action to control the content. Claim 11: The system of claim 9, wherein the instructions comprise further instructions that, upon execution by the one or more processors, cause the one or more processors to: determine, using the cross-application monitor, a file type of a file for which the activity is being requested; and selectively applying a profile comprising a plurality of content inspection rules to content in the file based on at least the determined file type. The dependent claims of the instant application recite language similar to the dependent claims of the patent application and are covered by the patent application. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-4, 9, 12-15, and 17 are rejected under 35 U.S.C. 103 as being unpatentable over Lad et al. (US 9917817) (hereinafter Lad) in view of Claudatos et al. (US 20060004818) (hereinafter Claudatos). Regarding claim 1, Lad discloses a computer-implemented method of data loss prevention for data owned by an enterprise (Lad: paragraph (12), “In at least one embodiment of the invention, the definition of what constitutes sensitive data can be determined by relevant data loss prevention (DLP) policies in the form of content blades.”), the computer-implemented method comprising: intermediating, with a cloud-hosted network security system, traffic between an endpoint of the enterprise and a cloud computing service (CCS) (Lad: paragraphs (11), (18-20) and (24-29), “the interception system 102 can be implemented within a communication device or analogous device or apparatus …system 102 monitors (via data monitoring component 104) data emitted from a user … to forwarding the entire data set, including the encrypted portion, to the intended destination (such as, …a cloud based storage service).”… “for intercepting system-level application programming interface (API) calls made by the application to monitor the applications for actions leading to data being leaked out.”); detecting activity associated with content on the CCS from the traffic (Lad: paragraphs (5), (11-13), (19-21) and (27), “monitoring a set of outgoing data from a first user, identifying one or more items of sensitive information from the set of outgoing data”… “a content blade encapsulates rules and logic dedicated to accurately detecting a specific piece of content, such as, for example, a Social Security number, a credit card number or a driver's license number”); wherein: the content inspection policy comprises a plurality of content inspection profiles (Lad: paragraphs (12-14) and (27-30), “the definition of what constitutes sensitive data can be determined by relevant data loss prevention (DLP) policies in the form of content blades”), each of the plurality of content inspection profiles comprises one or more content inspection rules (Lad: paragraphs (14) and (27-30), “detection rules in a content blade are grouped into inclusion rules and exclusion rules”), the one or more portions are selected based on the CCS, a user of the endpoint, a type of the activity, or a combination thereof (Lad: paragraphs (10) and (27-30), “a mechanism by which sensitive (or potentially sensitive) data within larger data sets or files can be selectively encrypted”…“the policy of the DLP agent can be configured to flag or identify files containing certain content (as described in applicable content blades) as sensitive, to consider movement of such files to outside of the machine as a policy violation,”), and the one or more content inspection rules each comprise custom inspection rules that include custom regular expressions defined by the enterprise, predefined data identifiers, or a combination thereof (Lad: paragraphs (10), (13-14), (27) and (37), “sensitive data might include credit card numbers, social security numbers, account numbers, user-defined data, internal internet protocol (IP) addresses, log-in user-names, passwords, etc”… “a content blade encapsulates rules and logic dedicated to accurately detecting a specific piece of content, such as, for example, a Social Security number, a credit card number or a driver's license number. Additionally, a content blade uses techniques for describing content via linguistic evidence. As described herein, a content blade uses detection rules and contextual rules.”); and in response to identifying the one or more matches, selecting a security action to control the content, and triggering the security action (Lad: paragraphs (14) and (30-31), “the policy of the DLP agent can be configured to flag or identify files containing certain content (as described in applicable content blades) as sensitive, to consider movement of such files to outside of the machine as a policy violation, and to trigger a customized action in response to a policy violation. The customized action can invoke the DPM agent with the file name and location of sensitive data as input. The DPM agent can also use the DPM server to tokenize/encrypt the data as applicable.”). Lad does not explicitly disclose the following limitations which are disclosed by Claudatos, analyzing the activity to determine the activity comprises content-level activity (Claudatos: paragraphs 0004, 0023-0025, 0028 and 0034, “Content evaluation may be performed on various file types, such as video, audio, graphics (e.g. bitmaps), text, and encrypted data.”… “analyzing the content of the object in step 70, and based on the content analysis, determining the ILM (or simply IM, for "information management") policy or policies to be applied to the object., step 72. The type of the object (which may be determined from metadata associated with the object) and/or the metadata may be used in determining the ILM policy to be applied”); selecting, in response to determining that the activity comprises content-level activity, one or more portions of a content inspection policy to apply to the content (Claudatos: paragraphs 0024-0025, 0028 and 0031-0032, “determining the ILM (or simply IM, for "information management") policy or policies to be applied to the object”… “The type of the object (which may be determined from metadata associated with the object) and/or the metadata may be used in determining the ILM policy to be applied. The ILM policy is associated with the object, step 74, and in step 76, the ILM policy is implemented for that object (which may involve moving the object, quarantining the object, making multiple copies, scheduling backups, etc.).”); applying the one or more portions to the content to identify one or more matches in the content by comparing the content and the one or more content inspection rules of each of a subset of the plurality of content inspection profiles, wherein the subset is associated with the one or more portions (Claudatos: paragraphs 0084-0085 and 0089, “By inspecting the files for any or specific combinations of these data elements it can be determined which ILM policy is appropriate. In an embodiment, a keyword-driven search or natural language analysis may be utilized. Thus, multiple documents/files/objects may be associated to a patient healthcare policy or other policy”… “Multiple documents/files/objects may contain information related to the same topic but have filenames, titles, subject headers, etc. that do not reflect this relationship. By examining and analyzing these objects, it is possible to group them and apply appropriate policies based on this analysis. Policies may be used to help determine which keywords merit forming an information group.”); identifying a content type based on the one or more matches, selecting a security action based at least in part on the content type and the content-level activity (Claudatos: paragraphs 0024-0032, 0036-0047 and 0092-0099, “if an object contains certain keywords/phrases relating to a patient's diagnosis and/or contains personal health information, then the object may need to be retained as long as the patient's medical records. On the other hand, if the object does not contain such content, it may be found not to require long term retention, and an appropriate ILM policy can be set, such as deletion in a short time period. By evaluating the object's content directly, the correct retention period may be programmatically determined with more accuracy.”… “Pattern matching to known file patterns may also be used to determine the file type. The information about the type of data contained by the object can be used to analyze its contents, thereby deriving information to set an appropriate ILM policy.”), and triggering the security action (Claudatos: paragraphs 0025-0026, 0031, 0047 and 0092-0099, “Several DPS policies may be applied in order to trigger an IM policy or policies to be applied to the object or objects.”… “ILM policies may include quarantine of particular subject matter (such as prohibited material or material relevant to an ongoing investigation) for further review or limited access”… “if an object contains certain keywords/phrases relating to a patient's diagnosis and/or contains personal health information, then the object may need to be retained as long as the patient's medical records. On the other hand, if the object does not contain such content, it may be found not to require long term retention, and an appropriate ILM policy can be set, such as deletion in a short time period”). Lad and Claudatos are analogous art because they are from the same field of endeavor, data protection. Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art, having the teachings of Lad and Claudatos before him or her, to modify the system of Lad to include analyzing the activity, selecting one or more portions of a content inspection policy and applying the one or more portions to the content to identify one or more matches in the content by comparing the content and the one or more content inspection rules of each of a subset of the plurality of content inspection profiles of Claudatos. The suggestion/motivation for doing so would have been for an improved method, article of manufacture, and apparatus for managing the lifecycle of files and other objects in a storage system (Claudatos: paragraph 0005). Regarding claim 12, the claim 12 discloses a system claim that is substantially equivalent to the method of claim 1. Therefore, the arguments set forth above with respect to claim 1 are equally applicable to claim 12 and rejected for the same reasons. Regarding claims 2 and 13, Lad as modified discloses wherein the content comprises a file, the method further comprising: determining a file type of the file (Claudatos: paragraphs 0026, 0028 and 0030-0034, “Other information may be used in order to characterize the data, such as the file's owner, date of creation, file type, file size, and so on.”); and selectively applying one or more of the plurality of content inspection profiles based at least in part on the file type, wherein the subset comprises the one or more of the plurality of content inspection profiles (Claudatos: paragraphs 0026, 0028, 0030, 0034-0035, 0084-0085 and 0089, “By inspecting the files for any or specific combinations of these data elements it can be determined which ILM policy is appropriate. In an embodiment, a keyword-driven search or natural language analysis may be utilized. Thus, multiple documents/files/objects may be associated to a patient healthcare policy or other policy”… “Multiple documents/files/objects may contain information related to the same topic but have filenames, titles, subject headers, etc. that do not reflect this relationship. By examining and analyzing these objects, it is possible to group them and apply appropriate policies based on this analysis. Policies may be used to help determine which keywords merit forming an information group.”). The same motivation to modify Lad in view of Claudatos, as applied in claim 1 above, applies here. Regarding claims 3 and 14, Lad as modified discloses wherein each predefined data identifier of the predefined data identifiers detects a specific data type, and the specific data type comprises one of telephone numbers, social security numbers, vehicle identification numbers, credit card numbers, and driver license numbers (Lad: paragraphs (10), (13-14), (27) and (37), “sensitive data might include credit card numbers, social security numbers, account numbers, user-defined data, internal internet protocol (IP) addresses, log-in user-names, passwords, etc”… “a content blade encapsulates rules and logic dedicated to accurately detecting a specific piece of content, such as, for example, a Social Security number, a credit card number or a driver's license number. Additionally, a content blade uses techniques for describing content via linguistic evidence. As described herein, a content blade uses detection rules and contextual rules.”). Regarding claims 4 and 15, Lad as modified discloses wherein the type of the activity is one of: upload; download; share; view; and delete (Lad: paragraphs (15) and (23), “This can include, as noted herein, a user laptop, a desktop computer, a mobile device etc. By way of illustration, consider an example scenario wherein a customer or user wishes to upload log files”). Regarding claims 9 and 17, Lad as modified discloses wherein the security action comprises: a quarantine security action; a coaching security action; a justification security action; an encrypting security action; or a combination thereof (Lad: paragraphs (10), (14) and (27-31), “a mechanism by which sensitive (or potentially sensitive) data within larger data sets or files can be selectively encrypted”…“the policy of the DLP agent can be configured to flag or identify files containing certain content (as described in applicable content blades) as sensitive, to consider movement of such files to outside of the machine as a policy violation,”). Claim(s) 5-8, 16 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Lad in view of Claudatos, and further in view of Grant (US 20100251369) (hereinafter Grant). Regarding claim 5, Lad in view of Claudatos does not explicitly disclose the following limitation which is disclosed by Grant, wherein at least one of the one or more content inspection rules comprises a multi-part string search pattern (Grant: paragraphs 0066 and 0067, “regular expressions may provide for a concise and flexible way to identify strings of text of interest, such as particular characters, words, patterns of characters and the like, and …then may examine the data 203 by searching for regular expression matches 205 or exact matches from the index 206, where the indexed data may increase accuracy of the detection by detecting actual confidential information 214. In embodiments, the intercepted data 202 may be presented to the content examiner 204 as blocks of data, as a stream of data, examined in real-time, examined from buffer, stored and examined, and the like.”). Lad in view of Claudatos and Grant are analogous art because they are from the same field of endeavor, data protection. Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art, having the teachings of Lad in view of Claudatos and Grant before him or her, to modify the system of Lad in view of Claudatos to include at least one of a one or more content inspection rules comprises a multi-part string search pattern of Grant. The suggestion/motivation for doing so would have been improve the systems used to protect confidential information stored on client computer facilities (Grant: paragraph 0004). Regarding claim 6, Lad as modified discloses wherein the multi-part string search pattern comprises a plurality of multi-part string search patterns and sub-string patterns (Grant: paragraphs 0066 and 0067, “regular expressions may provide for a concise and flexible way to identify strings of text of interest, such as particular characters, words, patterns of characters and the like, and may be interpreted by a regular expression processor. Creating an index 206 of the confidential information on the computing facility may include an indexer 207 that collects the confidential information 214, such as from an address book 212, a registry 211, files 208, and the like …then may examine the data 203 by searching for regular expression matches 205 or exact matches from the index 206, where the indexed data may increase accuracy of the detection by detecting actual confidential information 214. In embodiments, the intercepted data 202 may be presented to the content examiner 204 as blocks of data, as a stream of data, examined in real-time, examined from buffer, stored and examined, and the like.”). The same motivation to modify Lad in view of Claudatos and Grant, as applied in claim 5 above, applies here. Regarding claim 7, Lad as modified discloses wherein the multi-part string search pattern is one of the custom regular expressions (Grant: paragraphs 0066 and 0067, “regular expressions may provide for a concise and flexible way to identify strings of text of interest, such as particular characters, words, patterns of characters and the like, and may be interpreted by a regular expression processor. Creating an index 206 of the confidential information on the computing facility may include an indexer 207 that collects the confidential information 214, such as from an address book 212, a registry 211, files 208, and the like”). The same motivation to modify Lad in view of Claudatos and Grant, as applied in claim 5 above, applies here. Regarding claims 8, and 20 Lad in view of Claudatos does not explicitly disclose the following limitation which is disclosed by Grant, wherein the custom regular expressions support one of string match pattern operators, string match count operators, and metacharacter match pattern operators (Grant: paragraphs 0044 and 0066, “Rule evaluation may include regular expression rule evaluation, or other rule evaluation method for interpreting the network access request and comparing the interpretation to the established rules for network access”… “The content examiner 204 then may examine the data 203 by searching for regular expression matches 205 or exact matches from the index 206, where the indexed data may increase accuracy of the detection by detecting actual confidential information 214. In embodiments, the intercepted data 202 may be presented to the content examiner 204 as blocks of data, as a stream of data, examined in real-time, examined from buffer, stored and examined, and the like.”; // {Examiner notes, the regular expressions support the plurality of metacharacter match pattern operators (see https://en.wikipedia.org/wiki/Regular_expression). Lad in view of Claudatos and Grant are analogous art because they are from the same field of endeavor, data protection. Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art, having the teachings of Lad in view of Claudatos and Grant before him or her, to modify the system of Lad in view of Claudatos to include custom regular expressions support one of string match pattern operators, string match count operators, and metacharacter match pattern operators of Grant. The suggestion/motivation for doing so would have been improve the systems used to protect confidential information stored on client computer facilities (Grant: paragraph 0004). Regarding claim 16, the claim 16 discloses a system claim that is substantially equivalent to the methods of claims 5-7. Therefore, the arguments set forth above with respect to claim 16 are equally applicable to claims 5-7 and rejected for the same reasons. Claim(s) 10-11 and 18-19 are rejected under 35 U.S.C. 103 as being unpatentable over Lad in view of Claudatos, and further in view of Gouget (EP 2544117) (hereinafter Gouget). Regarding claims 10 and 18, Lad in view of Claudatos does not explicitly disclose the following limitation which is disclosed by Gouget, wherein the content comprises a file, and the security action comprises an encrypting security action (Gouget: paragraphs 0061 and 0072), the encrypting security action comprising: receiving a triplet-key and triplet-key identifier from a key-manager (Gouget: paragraphs 0061-0062, 0071-0072, 0081, 0091 and 0090-0093, “The FDF derives those derived keys from the master key and the identity of the document to be protected named DOC-ID. DOC-ID randomly generated by the portable token or terminal. Doc-ID is generated according to a hash function" "(Owner-ID, the Doc-ID and the TSP-ID)", {the master key is linked to the Owner-ID, the Doc-ID and the TSP-ID which is mapped to the triplet-key}”); generating a document key based on an identifier of the file and the triplet-key (Gouget: paragraphs 0061-0062, 0081, 0091 and 0090-0093); encrypting the file with the document key (Gouget: paragraphs 0061-0062, 0081, 0091 and 0090-0093); and adding a crypto-header to the file, the crypto-header comprising the triplet-key identifier (Gouget: paragraphs 0071 and 0072, “a header comprising a document descriptor is generated. The header is a data structure containing a list of references on the encrypted document EncDoc, the owner and the trusted provider 24. This header can be entered by the owner on the terminal 21 or generated automatically by, preferably, the portable token 22. In an embodiment, the headers may include such information as, for example, Owner-ID, Doc-ID, and TSP-ID”). Lad in view of Claudatos and Gouget are analogous art because they are from the same field of endeavor, data protection. Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art, having the teachings of Lad in view of Claudatos and Gouget before him or her, to modify the system of Lad in view of Claudatos to include an encrypting security action comprising: receiving a triplet-key and triplet-key identifier from a key-manager, generating a document key, encrypting a file and adding a crypto-header to the file of Gouget. The suggestion/motivation for doing so would have been to secure that data is kept secure from unauthorized access (Gouget: paragraph 0012). Regarding claims 11 and 19, Lad as modified discloses further comprising: decrypting the file, the decrypting comprising: extracting the identifier of the file and the triplet-key identifier from the crypto-header (Gouget: paragraph 0078, “SP 23 operates to parse the query received at the visitor terminal 27 and extract the header comprising the Owner-ID, the Doc-ID and the TSP-ID. At step 64, the SP 23 transmits the extracted header to the visitor terminal 27 in response to its query.”); obtaining the triplet-key from the key-manager based on the triplet-key identifier (Gouget: paragraphs 0078-0081, “SP 23 operates to parse the query received at the visitor terminal 27 and extract the header comprising the Owner-ID, the Doc-ID and the TSP-ID. At step 64, the SP 23 transmits the extracted header to the visitor terminal 27 in response to its query.”); generating the document key based on the identifier of the file and the triplet-key (Gouget: paragraphs 0105-0106, “the TSP has also the capability to compute the secret key KDocVisitor using Mkshared and Doc-ID. However, the knowledge of KDocVisitoris useless to decrypt the EncDoc. Indeed, the data token C1 does not contain the secret key KDocOwner. Only the Portable token has the capability to compute the secret key KDocOwner using Mkprivate and Doc-ID. Thus, only the portable token has the capability to decrypt EncDoc and to recover the plaintext m.”); and decrypting the file with the document key (Gouget: paragraphs 0105-0106, “the TSP has also the capability to compute the secret key KDocVisitor using Mkshared and Doc-ID. However, the knowledge of KDocVisitoris useless to decrypt the EncDoc. Indeed, the data token C1 does not contain the secret key KDocOwner. Only the Portable token has the capability to compute the secret key KDocOwner using Mkprivate and Doc-ID. Thus, only the portable token has the capability to decrypt EncDoc and to recover the plaintext m.”). The same motivation to modify Lad in view of Claudatos and Gouget, as applied in claim 10 above, applies here. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to TRANG T DOAN whose telephone number is (571)272-0740. The examiner can normally be reached Monday-Friday 7-4 ET. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn D Feild can be reached on (571)272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /TRANG T DOAN/Primary Examiner, Art Unit 2431
Read full office action

Prosecution Timeline

Jun 21, 2024
Application Filed
Feb 03, 2026
Non-Final Rejection mailed — §103, §DOUBLEPATENT
Apr 15, 2026
Interview Requested
Apr 22, 2026
Applicant Interview (Telephonic)
May 04, 2026
Response Filed
May 16, 2026
Examiner Interview Summary
Jul 21, 2026
Final Rejection mailed — §103, §DOUBLEPATENT (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12726827
METHOD FOR EXTERNAL AUTHENTICATION AND AUTHORIZATION
3y 2m to grant Granted Sep 01, 2026
Patent 12726277
SINGLE-PHOTON TRANSMISSION DETERMINATION
2y 2m to grant Granted Sep 01, 2026
Patent 12719884
System and Method for Intrusion Detection of Malware Traffic based on Feature Information
4y 8m to grant Granted Aug 25, 2026
Patent 12712714
Transmission of a message by quantum communication with eavesdropping detection
2y 6m to grant Granted Aug 18, 2026
Patent 12711261
SOVEREIGN DATA CENTER STAGING AREA
2y 3m to grant Granted Aug 18, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
83%
Grant Probability
99%
With Interview (+16.8%)
3y 4m (~1y 0m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 634 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month