Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
This is in response to the restriction requirement filed on 04/10/2026. Species I associated with claims 1-9 has been elected without traverse. Claims 10-20 have been withdrawn. Claims 1-9 are pending and have been considered below.
Priority
Acknowledgment is made of no claim of foreign priority.
Drawings
The drawings filed on 11/18/2024 are accepted.
Specification
The amendment to the specification filed on 11/18/2024 is accepted.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 11/18/2024 and 05/14/2026 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claim 1 is rejected under 35 U.S.C. 102(a)1 as being anticipated by Gottipati et al U.S. 2020/0259636 A1.
Claim 1: Gottipati et al teaches a computer system (Gottipati et al teaches at par.16, “a data storage system allows data to be encrypted and de-duplicated at the same system”) comprising:
first memory for file storage (Fig.7, item720);
second memory storing a first mapping table and a second mapping table, the first mapping table associating user addresses with fingerprints and the second mapping table associating the fingerprints with storage locations of the first memory, wherein each user address associated with an encrypted data file (Gottipati et al teaches at par.16, par.27-30, “The index entry may include other information such as the clients that are associated with the entry (i.e., clients that should have access to the data blocks), the location of the data block in the data store 130, and other namespace metadata. “Gottipati et al further teaches at par.34 -35“The client identifier is used in the data index 125 to identify data to which the client has access. In some embodiments, each client profile in the client profile store 210 may also store the index entry identifiers of data blocks to which the client has access. For example, fingerprints of the data blocks or other forms of index entry identifiers may be stored in the client profile. [0035]. “ the data index 125 may be implemented as a look-up table. In another embodiment, the data index 125 may be implemented as key-value pairs. The data index 125 also may include mapping information of a file. For example, a file from a client device 110 can be split into multiple partitions, and each partition can be stored at different storage machines of the data store 130 (e.g., the data store 130 may be a distributed storage system). ” The examiner’s interpretation is that the claim requires a two-tier indirection: first mapping (Client identifier to fingerprint) and second mapping(fingerprint to storage location). Gottipati et al teaches at par.16, ”the server may also manage and maintain a data index that includes records of data locations, clients' authority to access data, and data de-duplication”);
one or more processors(Gottipati et al teaches at par.67, Fig. 7, processor); and
a non-transitory computer-readable medium storing instructions that, when executed by the one or more processors (Gottipati et al teaches at Fig.7, par.67, form of a computer system 700 within which instructions 724 (e.g., software, program code, or machine code), which may be stored in a non-transitory computer-readable medium for causing the machine to perform any one or more of the processes discussed herein, e.g., with FIGS. 1-6, may be executed), cause the one or more processors to:
receive a received encrypted data file that is associated with a received user address (Gottipati et al teaches at par.15-16, 52, the client device 110 may perform the encryption and transmit the encrypted data block directly to data store 130);
receive a received fingerprint associated with the received encrypted data file (Gottipati et al teaches at par.27,30, 15-16, the server may receive the second checksum from the client device ));
determine, based on the received fingerprint, whether or not the received encrypted data file is a duplicate of a previously stored encrypted data file (Gottipati et al teaches at par.27,15-16, 36, “When a client device 110 requests to store a data block (or a file that includes one or more data blocks) to the data store 130, the index engine 230 determines whether the data block has a duplicative copy in the data store 130.”);
store the received encrypted data file in the first memory and update the first and second mapping tables in response to determining that the received encrypted data file is not a duplicate of any previously stored encrypted data file (Gottipati et al teaches at par.35-36,27-28, “when a client device 110 requests to store a data block to the data store 130, the index engine 230 determines whether the data block has a duplicative copy in the data store 130. If the data block does not exist in the data store 130, the index engine 230 may create a new data entry in the data index 125 indicating an association between the client identifier of the current client and the newly added data block”); and
update the first mapping table to associate the received user address with an existing fingerprint in response to determining that the received encrypted data file is a duplicate of a previously stored encrypted data file(Gottipati et al teaches at par.35-36,27-28, “When a client device 110 requests to store a data block to the data store 130, the index engine 230 determines whether the data block has a duplicative copy in the data store 130. If the data block already exists in the data store 130, the index engine 230 may add the client identifier associated with the current client to the index entry of the data block so that the client may retrieve the data block in the future.”).
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 2, 4-5 and 9 arerejected under 35 U.S.C. 103 as being unpatentable over Gottipati et al U.S. 2020/0259636 A1 in view of Wong U.S. 2020/0210595 A1.
Claim 2: Gottipati et al teaches
wherein the received encrypted data file comprises a received Gottipati et al teaches at par.15-16, 52, the client device 110 may perform the encryption and transmit the encrypted data block directly to data store 130).
Gottipati et al fails to specify, however Wong in the same field of endeavor teaches
the encrypted file is a non-deterministic (par.25-27, accessing a record of a record set that includes a corresponding non-deterministically encrypted ciphertext item of the encrypted attribute of the record).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the disclosure of Gottipatti et al with the additional features of Wong in order to provide the ability to perform to access an entry in an indexing structure to obtain a corresponding CryptoJSON record which includes a non-deterministically encrypted ciphertext item, as suggested by Wong abstract.
Claim 4: the combination teaches further comprising a client side component comprising:
one or more client side processors (Gottipati et al teaches at Fig.7, par.67); and
a client side non-transitory computer-readable medium storing client side instructions that, when executed by the one or more client side processors (Gottipati et al teaches at Fig.7, par.67 ), cause the one or more client side processors to:
receive raw data (Gottipati et al teaches at par.49, Fig. 2A, “the client device 110 uses the encryption key to encrypt 332 the data block from plaintext to ciphertext”);
generate the received fingerprint from the raw data(Gottipati et al teaches at par.47, the client device 110 derives the first fingerprint of the plaintext of the data block.);
the raw data using non-deterministic encryption to produce the received non-deterministically encrypted data file (Wong teaches at par.25-27, accessing a record of a record set that includes a corresponding non-deterministically encrypted ciphertext item of the encrypted attribute of the record).
The same motivation to modify Gottipati et al in view of Wong applied to claim 2 above applies here.
Claim 5: the combination teaches
wherein the client side instructions further cause the one or more client side processors to generate the received fingerprint from the raw data using a hashing function(Gottipati et al teaches at par.49, 44 “the fingerprint generator 270 may include a variety of fingerprint algorithm such as one-way functions include hash functions, checksum functions, and other different types of fingerprint algorithm”).
Claim 9: the combination teaches wherein the instructions further cause the one or more processors to:
receive a read request specifying a user address(Gottipati et al teaches at par.16, par.27-30,
use the first mapping table to identify a fingerprint associated with the user address(Gottipati et al teaches at par.16, par.27-30,,);
use the second mapping table to identify a storage location associated with the identified fingerprint(Gottipati et al teaches at par.16, par.27-30,,); and
retrieve a non-deterministically encrypted data associated with the identified fingerprint from the identified storage location (Wong teaches at par.25-27, accessing a record of a record set that includes a corresponding non-deterministically encrypted ciphertext item of the encrypted attribute of the record).
The same motivation to modify Gottipati et al in view of Wong applied to claim 2 above applies here.
Claim 3 is rejected under 35 U.S.C. 103 as being unpatentable over Gottipati et al U.S. 2020/0259636 A1 in view of Wong U.S. 2020/0210595 A1 in further view of Adam et al U.S. 2021/0279326 A1.
Claim 3: the combination fails to teach , however Adam et al in the same field of endeavor teaches
wherein the received fingerprint is received in an encrypted fingerprint file and wherein the instructions further cause the one or more processors to decrypt the encrypted fingerprint file (Adam et al teaches at par .5 “decrypts , using a first key , an encrypted file fingerprint, the decrypting result in a decrypted file fingerprint.” ).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the disclosure of Gottipatti et al with the additional features of Adam et al in order to provide the ability to control file integrity, as suggested by Adam et al par.1.
Claim 6 : the combination fails to teach , however Adam et al in the same field of endeavor teaches
wherein the client side instructions further cause the one or more client side processors to encrypt the received fingerprint file and wherein the instructions further cause the one or more processors to decrypt the received fingerprint file(Adam et al teaches at par .5 “decrypts , using a first key , an encrypted file fingerprint, the decrypting result in a decrypted file fingerprint.” ).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the disclosure of Gottipatti et al with the additional features of Adam et al in order to provide the ability to control file integrity, as suggested by Adam et al par.1.
Claim 7 is rejected under 35 U.S.C. 103 as being unpatentable over Gottipati et al U.S. 2020/0259636 A1 in view of Wong U.S. 2020/0210595 A1 in further view of Ng et al U.S. 2017/0177899 A1.
Claim 7: the combination fails to teach, however in the Ng et al in the same field of endeavor teaches
wherein the client side component further comprises hardware accelerators configured to perform homomorphic encryption to produce the received non-deterministically encrypted data file (Ng et al teaches at par.82-84, the file identifier is protected using a homomorphic encryption technique, and preferably, a somewhat homomorphic encryption (SWHE) over the integers technique.) .
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the disclosure of Gottipatti et al with the additional features of Ng et al in order to provide encrypted data deduplication in cloud storage, and more particularly, to a system of storing data in a cloud storage system, and associated client device and cloud storage system, as suggested by Ng et al par.2.
Claim 8 is rejected under 35 U.S.C. 103 as being unpatentable over Gottipati et al U.S. 2020/0259636 A1 in view of Wong U.S. 2020/0210595 A1 in further view of Chang et al U.S. 2023/0291797 A1.
Claim 8: the combination fails to teach, however Chang et al in the same field of endeavor teaches
wherein the client side component is configured to implement data compression in a bump-in-the-wire fashion (Chang et al teaches at par.48 “the ability to inspect incoming/outgoing raw RDMA packets in a bump-in-the-wire fashion.”).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to modify the disclosure of Gottipatti et al with the additional features of Adam et al in order to provide the ability for supporting zero-trust policy enforcement in a communication system, as suggested by Chang et al abstract.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Lumb U.S. 8,401,181 B2 Segment Deduplication System With Encryption Of Segments.
Perlman et al U.S. 11,128460 B2 Client-side Encryption Supporting Deduplication Across Single Or Multiple Tenants In A Storage System.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to FATOUMATA TRAORE whose telephone number is (571)270-1685. The examiner can normally be reached 6:30-3:00.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, SHEWAYE GELAGAY can be reached at 5712724219. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
Friday, June 26, 2026
/FATOUMATA TRAORE/Primary Examiner, Art Unit 2436