Prosecution Insights
Last updated: October 02, 2026
Application No. 18/915,395

File operation policy enforcement

Final Rejection §103
Filed
Oct 15, 2024
Examiner
ANKRUM, ALEC CHRISTOPHER
Art Unit
2434
Tech Center
2400 — Computer Networks
Assignee
Sailpoint Technologies Inc.
OA Round
2 (Final)
Grant Probability
Favorable
3-4
OA Rounds

Examiner Intelligence

Grants only 0% of cases
0%
Career Allowance Rate
0 granted / 0 resolved
-58.0% vs TC avg
Minimal +0% lift
Without
With
+0.0%
Interview Lift
resolved cases with interview
Typical timeline
Avg Prosecution
8 currently pending
Career history
17
Total Applications
across all art units
This examiner has no resolved cases yet (career too new); statute-level performance unavailable. The Grant Probability card shows Tech Center averages instead.

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Status Claims 1, 3-4, 11, 18, and 19 are amended. Claim 20 is a new pending claim. Claims 1-20 are under examination. Response to Arguments Applicant’s Remarks filed on 6/11/2026 have been considered. Regarding Applicant’s remarks and amendments addressing the 35 U.S.C. 112(b) rejection, these have been considered and are persuasive. The 35 U.S.C. 112(b) rejections of claims 3-4, 11-12, and 18 have been withdrawn. Regarding Applicant’s remarks to Greenblatt’s anticipation of the amended claim 1, these have been considered and are persuasive. Therefore, the 102 rejection has been withdrawn. However, upon further consideration, a new ground of rejection is made in view of Greenblatt. Regarding Applicant’s remarks to Greenblatt failing to teach retrieving the file metadata, these have been considered and are not persuasive. Greenblatt’s collected additional information, which is provided in response to the server’s request, includes at least the file size which is metadata from the given file. Regarding Applicant’s remarks to Greenblatt’s anticipation of the new pending claim 20, these have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claims 1-5 and 15-19 are rejected under 35 U.S.C. 103 as being unpatentable over Greenblatt et al. (US Patent 11,295,029), hereinafter Greenblatt. Regarding claim 1, Greenblatt teaches A method for protecting a client computer, which includes a processor configured to access a set of files, the method comprising (Col 1 lines: 42-44 “The present application relates generally to securing electronic files on digital systems, including data loss prevention techniques involving encryption and request auditing.”): detecting, by the processor, a first request to access a given file in the set (Col 5 lines: 25-29: “Through a series of background processes, invisible to the user, a client-based application for securing electronic files has intercepted the access request and prevented the native application from contacting the file system of the client device.”); in response to the first request, conveying, by the processor prior to executing the first request, a notification of the first request over a network to a security server (Col 16 lines 22-29: “The message generated by the network request formation process may be encrypted and encoded into a network request (e.g., by the network request message encoding process), to be sent to a server (e.g., server 140 of FIG. 1) over the network 214. The server may receive and decode the message (e.g., by operation 216), and may implement a remote action determination process (e.g., operation 218).”); in response to receiving the notification, conveying, by the security server to the client computer over the network, a second request to retrieve metadata from the given file (Col 10 line 36 – Col 11 line 5: “…the server may generate a payload 120 in response to processing the information 111. The payload 120 may include a command dispositive of the access request, as described in more detail below, and may be encrypted before transmission from the server 140 to the computer system 102…the payload 120 may also include additional and/or alternative commands for the client-based application 108 to execute kernel mode 106 processes including, but not limited to, gathering additional information about the computer system 102 automatically (e.g., without user interaction), packaging the additional information, and sending an exfiltration message from the computer system 102 to the server 140, as described in more detail in reference to FIG. 4”); retrieving, by the processor in response to receiving the second request (Col 25 Claim 7: “The method of claim 6 further comprising: gathering additional information about the computer system per the command”), the requested metadata from the given file (Col. 6 Lines 64-66: “The metadata about files managed by the file system 110 may include filenames, location information (e.g., the location of the file in memory and in a file directory), and length of the contents of the file (e.g., file size).”); conveying, by the client computer, the retrieved metadata to the security server over the network (Col 25 Claim 7: “The method of claim 6 further comprising: gathering additional information about the computer system per the command; packaging the additional information into an exfiltration message; and sending the exfiltration message from the computer system to the server.”); conveying, from the security server to the client computer over the network (Col 11 lines 10-17: “In some embodiments, the additional message may be processed in a manner similar to the encrypted message 116, such that the additional information is used by the server 140 to generate a second payload, which may be sent back to the computer system 102. As with the payload 120, the second payload may include one or more commands, a decryption key, additional information, etc.”), in response to receiving the conveyed metadata, a decision as to whether to authorize the first request (Col 15 lines 38-53“…the information gathered by the network request formation processes in the case of the file open request 304 may cause the server to determine that the client-based application should inhibit decryption of the encrypted electronic file subject to the file open request 304. In such cases, the server may define the remote action as a “do not open file” remote action (e.g., operation 320), which may include a command to inhibit decryption of the encrypted electronic file. Upon determining the remote action as a “do not open file” remote action, the server may package a command to inhibit decryption in a payload (e.g., payload 120 of FIG. 1) via the network request message encoding process (e.g., operation 222), and may send the payload via the network 214.”), wherein the decision is generated by the security server (Greenblatt Col. 11 Lines 50-55: “The server may implement one or more processes and/or approaches to determine an action in response to receiving the encrypted message 116. In some embodiments, the server 140 may implement an artificial intelligence (AI) engine 142 configured to determine whether to grant the access request.”) comparing the retrieved metadata to a specified policy (Greenblatt Col. 12 Lines 9-17: “The AI engine 142 may be configured to include one or more procedural and/or rules-based determination techniques (e.g., without AI features) including classifying the file access request based on a lookup table. The lookup table may include blacklisted and/or whitelisted access request features including, but not limited to, the types of information described above (e.g., file types, file locations, destination addresses, transformation operations, user names, device locations, network security parameters, etc.).”); and responding by the processor to the first request in accordance with the decision (Col 14 lines 62-Col 15 line 56: “In reference to the file opening remote action, executing the payload may include sending a command to the file system of the computer system to decrypt the encrypted electronic file. As such, the computer system may implement a data decryption process (e.g., operation 226), which may include opening file data by decrypting file data in RAM using a server-supplied key (e.g., key 144 of FIG. 1) … Upon receipt, the client-based application decodes and executes the payload (e.g., operation 224). The command, encoded in the payload as part of the payload contents (e.g., payload contents 126 of FIG. 1), may cause the client-based application to inhibit decryption of the encrypted application file.”). Greenblatt does not disclose all the above in the same embodiment, however it would have been obvious to a person having ordinary skill in the art before the effective filing date of the invention to combine the embodiments of Greenblatt since it is suggested by Greenblatt Col. 24 Lines 30-32: “One or more features from any embodiment may be combined with one or more features of any other embodiment without departing from the scope of the invention.”. This motivation to combine the embodiments of Greenblatt applies to the dependent claims as well. Claim 18 is substantially similar to claim 1 and is rejected under the same rationale. In addition, Greenblatt teaches A security server, comprising: a network interface controller coupled to a network; and a processor configured (Fig 1.): Claim 19 is substantially similar to claim 1 and is rejected under the same rationale. In addition, Greenblatt teaches A computer software product for protecting a client computer configured to access a set of files, the computer software product comprising a non-transitory computer-readable medium, in which program instructions are stored, which instructions, when read by the client computer and a security server, cause (Col 20 line 17-21: “The operations of the flow can be implemented as hardware circuitry and/or stored as computer-readable instructions on a non-transitory computer-readable medium of a computer system, such as the computer system 102 and/or the server 140 of FIG. 1.”) Regarding claim 2, Greenblatt teaches the method according to claim 1, wherein the first request comprises a file identifier (ID) for the file, wherein the access comprises a specific operation on the file, and further comprising generating, prior to conveying the decision, the decision based on the file ID and the specific operation (Col 1 lines 3-65: “In a first aspect, a method of securing electronic files includes intercepting, within a computer system, a file access request for an encrypted electronic file having a filename, looking up a globally unique file identifier associated with the file, gathering, from within the computer system, information about the computer system, the information including a name of a process that sent the file access request and a username running the process, packaging the 60 globally unique file identifier along with the information into a message, sending the message from the computer system to a server, receiving a payload from the server in response to the sent message, and decrypting, or inhibiting decryption of, the encrypted electronic file based on the payload.”). Regarding claim 3, Greenblatt teaches the method according to claim 2, wherein the request comprises information about the client computer, and wherein generating the decision comprises generating the decision based on file ID, the specific operation, and the information about the client computer (Col 1 lines 3-65: “In a first aspect, a method of securing electronic files includes intercepting, within a computer system, a file access request for an encrypted electronic file having a filename, looking up a globally unique file identifier asso-ciated with the file, gathering, from within the computer system, information about the computer system, the information including a name of a process that sent the file access request and a username running the process, packaging the 60 globally unique file identifier along with the information into a message, sending the message from the computer system to a server, receiving a payload from the server in response to the sent message, and decrypting, or inhibiting decryption of, the encrypted electronic file based on the payload.”). Regarding claim 4, Greenblatt teaches the method according to claim 3, wherein the information about the client computer comprises information about a user of the computer (Col 8 lines 34-40: “In some embodiments, the information 111 may also include user information that may include, but is similarly not limited to, a shell type running the process, a time logged in of the username, whether the username is logged in locally or remotely, whether there exists a printer redirection for the username, whether there exists a clipboard redirection for the username, a group membership of the username,…”). Regarding claim 5, Greenblatt teaches the method according to claim 1, wherein the metadata comprises labels for the given file. (Col 7 lines 59-67: “In some cases, the file system 110 may be a kernel mode 106 process that manages access to both the content of files, and the metadata about those files, stored on one or more storage media (e.g., hard disk drives, SSDs, magnetic tapes, optical discs, etc.) accessed by the computer system 102. The metadata about files managed by the file system 110 may include filenames, location information (e.g., the location of the file in memory and in a file directory), and length of the contents of the file (e.g., file size).”). Regarding claim 15, Greenblatt teaches the method according to claim 1, wherein the first request comprises a request to delete the given file. (Col 5 lines 11-15: “While a file access request is described, the data loss prevention techniques also apply to CRUD operations in general (e.g., creation, insertion, retrieval, query, search, read or find, update, edit, deletion, removal, etc.).”) Regarding claim 16, Greenblatt teaches the method according to claim 1, wherein the first request comprises a request to read data from the given file. (Col 5 lines 11-15: “While a file access request is described, the data loss prevention techniques also apply to CRUD operations in general (e.g., creation, insertion, retrieval, query, search, read or find, update, edit, deletion, removal, etc.).”) Regarding claim 17, Greenblatt teaches the method according to claim 1, wherein the first request comprises a request to write data to the given file. (Col 5 lines 11-15: “While a file access request is described, the data loss prevention techniques also apply to CRUD operations in general (e.g., creation, insertion, retrieval, query, search, read or find, update, edit, deletion, removal, etc.).”) Claims 6, 7, 9, and 11 are rejected under 35 U.S.C. 103 as being unpatentable over Greenblatt in view of McCanne et al. (US Patent Publication 2008/0320151), hereinafter McCanne. Regarding claim 6, Greenblatt teaches the method according to claim 1, but fails to explicitly teach and further comprising opening a communication channel between the client computer and the security server in response to detecting the first request. However, McCanne teaches and further comprising opening a communication channel between the client computer and the security server in response to detecting the first request (McCanne ¶19: “As explained above, a transaction over a network involves bidirectional communication between two computing entities, where one entity is the client and initiates a transaction by opening a network channel to another entity (the server). Typically, the client sends a request or set of requests via a set of networking protocols over that network channel, and the request or requests are processed by the server, returning responses. Many protocols are connection-based, whereby the two cooperating entities (sometimes known as ‘hosts’) negotiate a communication session to begin the information exchange. In setting up a communication session, the client and the server might each maintain state information for the session, which may include information about the capabilities of each other.”). It would have been obvious for one of ordinary skill in the art before the effective filing date of the invention to modify Greenblatt in view of McCanne to only open and use communication channels in response to a request to reduce bandwidth usage (McCanne ¶8: “The present invention relates generally to systems for moving data through limited channels efficiently where the channels might be limited by bandwidth and/or latency, and more particularly to having data available in response to a request for data over a limited channel faster than if the data were sent unprocessed in response to the request, possibly taking into account varying applications, systems and protocols of and for the requested data.”). Greenblatt further teaches wherein the second request, the retrieved metadata and the decision are conveyed over the communication channel (Col 17 lines 5-10: “The data exfiltration process may include reading the decrypted file data (e.g., operation 432) and/or other data from data storage, and sending the read data to the other system over a network 434, which may be the same as the network 214”). Regarding claim 7, Greenblatt fails to teach wherein the communication channel comprises a synchronous communication protocol. However, McCanne teaches wherein the communication channel comprises a synchronous communication protocol. (McCanne ¶332: “Some versions might support a limited set of commonly used protocols (i.e., CIFS, NFS, HTTP, FTP…”) Examiner Note: FTP is being mapped to a synchronous communication protocol. It would have been obvious for one of ordinary skill in the art before the effective filing date of the invention to modify Greenblatt in view of McCanne to use a synchronous communication protocol to allow for a more flexible bidirectional communication channel (McCanne ¶19: “As explained above, a transaction over a network involves bidirectional communication between two computing entities…”). Regarding claim 9, Greenblatt fails to teach wherein opening the communication channel comprises the client computer opening the communication channel. However, McCanne teaches wherein opening the communication channel comprises the client computer opening the communication channel (McCanne ¶19: “As explained above, a transaction over a network involves bidirectional communication between two computing entities, where one entity is the client and initiates a transaction by opening a network channel to another entity (the server). Typically, the client sends a request or set of requests via a set of networking protocols over that network channel, and the request or requests are processed by the server, returning responses.”). It would have been obvious for one of ordinary skill in the art before the effective filing date of the invention to modify Greenblatt in view of McCanne to have the client computer open the communication channel in response to requesting a file to reduce bandwidth usage (McCanne ¶8: “The present invention relates generally to systems for moving data through limited channels efficiently where the channels might be limited by bandwidth and/or latency, and more particularly to having data available in response to a request for data over a limited channel faster than if the data were sent unprocessed in response to the request, possibly taking into account varying applications, systems and protocols of and for the requested data.”). Regarding claim 11, Greenblatt teaches wherein the processor comprises a client processor executing an endpoint agent, (Greenblatt Col 4 lines 4-6: “In an example, a client-based application may run as a background process on a computer system with a kernel extension and can communicate over a network to a server.”) wherein the security server comprises a server processor executing a file information library (Greenblatt Col 14 lines 38-46: “Following decoding, the server may implement one or more remote action determination processes (e.g., operation 218), whereby the server processes file and classifier information to determine a remote action. The remote action can be an example of the command, described in more detail above, and determination of the remote action by the remote action determination process may include the techniques described above (e.g., classification techniques including AI models, procedures, object-models, etc.).”), wherein conveying the second request comprises the server processor conveying the second request to the file information library, (Greenblatt Col 16 lines 30-35: “The remote action determination process may determine that the client-based application should exfiltrate the file data from the encrypted electronic file. Exfiltration may describe a kernel mode (e.g., kernel mode 106 of FIG. 1) process whereby file data is extracted from an encrypted electronic file and transferred to another system”) …………….and wherein conveying the decision comprises the server processor conveying the decision to the endpoint agent over the communication channel. (Greenblatt Col 14 lines 38-56: “Following decoding, the server may implement one or more remote action determination processes (e.g., operation 218), whereby the server processes file and classifier information to determine a remote action. The remote action can be an example of the command, described in more detail above, and determination of the remote action by the remote action determination process may include the techniques described above (e.g., classification techniques including AI models, procedures, object-models, etc.). For example, when the information collected by the fingerprint module 210 and the user and file information gathered by the network request formation process indicate the file open request 204 should be authorized (e.g., the encrypted file should be decrypted), the server may determine a file opening remote action (e.g., operation 220). The file opening remote action may be packaged into a payload, as described above, by a server-side network request message encoding process (e.g., operation 222). The server may send the payload to the client-based application via the network”) but fails to teach the file information library forwarding the second request to the endpoint agent over the communication channel and wherein conveying the retrieved metadata comprises the endpoint agent conveying the retrieved metadata to the file information library over the communication channel. However, McCanne teaches the file information library forwarding the second request to the endpoint agent over the communication channel (McCanne ¶ 292: “When a response arrives, predictor module 2208 intercepts the response and queries transaction ID mapping table 2210 using the transaction ID from the response to determine if the response was the result of a predicted transaction or of a normal client request. In the latter case, the response is simply forwarded to the client.”) and wherein conveying the retrieved metadata comprises the endpoint agent conveying the retrieved metadata to the file information library over the communication channel (McCanne ¶290: “…when a client transmits a request, observer module 802 receives the request and updates learning module 2206 with whatever information is required for the particular learning algorithm that is in effect.”). It would have been obvious for one of ordinary skill in the art before the effective filing date of the invention to modify Greenblatt in view of McCanne to maintain normal client-server communication and function while speeding up the operation of the file information library (McCanne ¶259: “An accelerator can pass all transaction requests through to the server, just as if it were not deployed at all, so that applications and protocols can work normally without modification, just faster”). Claim 8 is rejected under 35 U.S.C. 103 as being unpatentable over Greenblatt in view of McCanne in view of Liu et al. (US Patent Publication 2023/0013371), hereinafter Liu. Regarding claim 8, Greenblatt in view of McCanne teaches the method according to claim 7 but fail to explicitly teach wherein the synchronous communication protocol comprises WebSocket. However, Liu teaches wherein the synchronous communication protocol comprises WebSocket (Liu ¶37: “WebSocket is a protocol for full-duplex communication over a single TCP connection, which causes data exchange between a client and a server to be simpler and allows the server to actively push data to the client.”). It would have been obvious for one of ordinary skill in the art before the effective filing date of the invention to modify Greenblatt in view of McCanne to use WebSocket protocol to enable data exchange that is bidirectional and only needs one handshake to form (Liu ¶37: “In a WebSocket Application Programming Interface (API), the browser and the server only need to complete handshake once, and a persistent connection can be directly created between the browser and the server, and two-way data communication can be performed.”) Claim 10 and 12 are rejected under 35 U.S.C. 103 as being unpatentable over Greenblatt in view of McCanne in view of Ancin et al. (US Patent 9,251,114), hereinafter Ancin. Regarding claim 10, Greenblatt and McCanne teach the method according to claim 6 but fail to teach wherein opening the communication channel comprises the client computer conveying, over the network, an additional request to open the communication channel, and the security server opening the communication channel in response to receiving the additional request. However, Ancin teaches wherein opening the communication channel comprises the client computer conveying, over the network, an additional request to open the communication channel, and the security server opening the communication channel in response to receiving the additional request. (Ancin Col 3 49-54: “…the cloud storage system can function as a communications conduit by establishing a second connection with the private storage system, requesting access to the object on behalf of the user, gaining access to the requested object, and providing access to the requested object to the user.”) It would have been obvious for one of ordinary skill in the art before the effective filing date of the invention to modify Greenblatt and McCanne in view of Ancin to increase the flexibility and responsiveness of client access requests (Col 2 lines 27-30: “Private cloud solutions provide IT with software that can be run and hosted within the customer data center, allowing the customer to store data on-premises and deliver public cloud like capabilities to users.”) Regarding claim 12, Greenblatt and McCanne teach the method according to claim 11, but fail to explicitly teach wherein the endpoint agent comprises an extension for a web browser. However, Ancin teaches wherein the endpoint agent comprises an extension for a web browser (Ancin Col 17 54-59: “Federated identity service 606 facilitates access to remote cloud 102 from multiple devices and form factors by extending the trust fabric across devices of the hybrid cloud storage system 200, including to local clouds and mobile devices via browser plug-in or via native applications.”) It would have been obvious for one of ordinary skill in the art before the effective filing date of the invention to modify Greenblatt and McCanne in view of Ancin to increase the flexibility of secure file exchange programs by making the endpoint agent available in web extension form (Ancin Col 17 59-63: “Services 606 and 608 can employ popular security and authentication standards (e.g. SAML, OAuth, OpenID, etc.), thus making the exchanges secure and interoperable, while maintaining the ability to provide flexible access to the elements of hybrid cloud storage system 200.”). Claims 13-14 are rejected under 35 U.S.C. 103 as being unpatentable over Greenblatt in view of Ancin. Regarding claim 13, Greenblatt teaches the method according to claim 1 but fails to explicitly teach wherein the first request comprises a request to upload the given file to a remote server. However, Ancin teaches wherein the first request comprises a request to upload the given file to a remote server (Ancin Col 16 line 66 – Col 17 line 6: “However, it should be understood that each of these embodiments and associated methods can also apply to any user that wants remote access to a portion of the distributed file system that the user does not have local access to. Similarly, the above embodiments and methods apply to all types of file access including file uploads, file downloads, file system object moves, etc.”). It would have been obvious for one of ordinary skill in the art before the effective filing date of the invention to modify Greenblatt in view of Ancin to allow users increased access options when securely requesting remote files (Ancin Col 24 line 37-38: “Users can work against the private storage as if they were in the office, reviewing, uploading and sharing files.”). Regarding claim 14, Greenblatt teaches the method according to claim 1 but fails to explicitly teach wherein the first request comprises a request to download the given file to a remote server. However, Ancin teaches wherein the first request comprises a request to download the given file to a remote server (Ancin Col 16 line 66 – Col 17 line 6: “However, it should be understood that each of these embodiments and associated methods can also apply to any user that wants remote access to a portion of the distributed file system that the user does not have local access to. Similarly, the above embodiments and methods apply to all types of file access including file uploads, file downloads, file system object moves, etc.”). It would have been obvious for one of ordinary skill in the art before the effective filing date of the invention to modify Greenblatt in view of Ancin to allow users increased access options when securely requesting remote files (Ancin Col 24 line 37-38: “Users can work against the private storage as if they were in the office, reviewing, uploading and sharing files.”). Claim 20 is rejected under 35 U.S.C. 103 as being unpatentable over Greenblatt in view of Narayanaswamy et al. (United States Patent Publication No. 2020/0177637), hereinafter Narayanaswamy. Regarding claim 20, Greenblatt teaches the method according to claim 1, but fails to teach wherein the retrieved metadata comprises a confidentiality flag indicating if the given file comprises confidential information and wherein the specified policy prohibits uploading the given file to a domain associated with a file hosting service if the confidentiality flag indicates the given file comprises confidential information. However, Narayanaswamy teaches wherein the retrieved metadata comprises a confidentiality flag indicating if the given file comprises confidential information (Narayanaswamy ¶348: “FIG. 13 illustrates object metadata being stored” – attribute_1 (1304) includes a flag for sensitive data) and wherein the specified policy prohibits uploading the given file to a domain associated with a file hosting service (Narayanaswamy ¶133: “a cloud service, sometimes also referred to as a cloud computing service (CCS), or a hosted service or a cloud application refers to a network cloud service or application, web-based (e.g. accessed via a uniform resource locator (URL)) or native, such as sync clients.”) if the confidentiality flag indicates the given file comprises confidential information (Narayanaswamy ¶268: “in FIG. 3C, active analyzer 192 looks up the metadata store 196 to determine whether the object ID 876A0 is associated with a sensitive document. FIG. 3D is one implementation of enforcing 300D a multi-part policy on the sharing data-deficient transaction 300A based on object metadata accessed from a metadata store. When the metadata store 196 confirms that enterprise data file 184 is sensitive, the multi-part policy 300B is enforced and the enterprise data file 184 is not shared and the sharing data-deficient transaction 300A is cancelled at action 304.”). It would have been obvious for one of ordinary skill in the art before the effective filing date of the invention to modify Greenblatt in view of Narayanaswamy to still allow use of cloud services without comprising confidential data (Narayanaswamy ¶22: “Accordingly, it is imperative to facilitate the use of cloud services so people can continue to be productive and use the best tools for the job without compromising sensitive information such as intellectual property, non-public financials, strategic plans, customer lists, personally identifiable information belonging to customers or employees, and the like.). Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to ALEC ANKRUM whose telephone number is (571)272-9209. The examiner can normally be reached M-F 7:30am-3:30pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Ali Shayanfar can be reached at 571-270-1050. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /A.C.A./Examiner, Art Unit 2434 /NOURA ZOUBAIR/Primary Examiner, Art Unit 2434
Read full office action

Prosecution Timeline

Oct 15, 2024
Application Filed
Mar 17, 2026
Non-Final Rejection mailed — §103
Jun 11, 2026
Response Filed
Jul 28, 2026
Final Rejection mailed — §103 (current)

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
Grant Probability
Moderate
PTA Risk
Based on 0 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month