Prosecution Insights
Last updated: October 02, 2026
Application No. 18/977,895

SECURITY FOR COMPUTER SYSTEMS

Non-Final OA §103
Filed
Dec 11, 2024
Priority
Jul 29, 2022 — continuation of 12/244,564
Examiner
NGUYEN, ANH
Art Unit
2458
Tech Center
2400 — Computer Networks
Assignee
Microsoft Technology Licensing, LLC
OA Round
2 (Non-Final)
79%
Grant Probability
Favorable
2-3
OA Rounds
11m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 79% — above average
79%
Career Allowance Rate
297 granted / 376 resolved
+21.0% vs TC avg
Strong +25% interview lift
Without
With
+25.0%
Interview Lift
resolved cases with interview
Typical timeline
2y 9m
Avg Prosecution
21 currently pending
Career history
400
Total Applications
across all art units

Statute-Specific Performance

§101
14.4%
-25.6% vs TC avg
§103
61.9%
+21.9% vs TC avg
§102
7.8%
-32.2% vs TC avg
§112
10.2%
-29.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 376 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This communication is in response to the argument filed on 07/09/2026. Claims 2-21 are rejected. Claim 1 has been canceled. Information Disclosure Statement The information disclosure statement (IDS) submitted on 06/15/2026 was filed. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Terminal Disclaimer The terminal disclaimer filed on 07/09/2026 has been recorded. Response to Arguments Applicant’s arguments, with respect to the rejection under Claim Rejections - 35 USC § 103 have been fully considered and are persuasive. Therefore, the rejection has been withdrawn. However, upon further consideration, a new ground of rejection is made in view of Little (US 20200302074 A2). Applicant's arguments , with respect to claim 3 rejection have been fully considered but they are not persuasive. Applicant argued that Tamada does not teach state information. However, Tamada [0012], [0016] teaches a file access control unit relying on network state data maintained by network control component. Furthermore, Little teaches network security filter drivers passing network status/threat state information across system drivers to files system component to regulate access. The other arguments regarding claims 5-6, 10, 12-14, and 16-19 are taught by the combination of Tamada and Little. Regarding claims 4 and 11, the arguments are also not persuasive. Goldschlag expressly teaches a distributed policy-enforcement architecture in which multiple policy enforces operate as components of an operating system, file system, firewall, or other device elements, and in which those enforcers coordinate to enforce information management policies (co. 29, lines 36-47). This disclosure teaches that policy enforcers is implemented as distinct aspects of the operating system and that they function together within unified policy enforcement framework. The ordinary artisan would understand that the separate enforcers must exchange relevant state or decision information in order to enforce coherent, multi-component policies. The exchange of state between a file system enforcer and a network /firewall enforcer necessarily occurs via a communication path or channel within the operating system. Goldschalag’s teaching or coordinated, multi-layer policy enforcers therefore supplies the claimed communication channel for sharing state information between filesystem software and network filter software. Goldsshlag teaches the communication channel and state sharing limitation of claims 4 and 11, the rejection is maintained. Regarding to the arguments of claims 7 and 20, Paragraphs [63] and [67] of Lai discloses an I/O driver stack architecture in which multiple drivers operate in sequence and perform differentiated function with respect to the same IO or connection request. This discloses teaches a multi-driver stack in which one driver can pass a request to downstream filter driver, and a separate filter component performs a verification function that can result in the request being dropped. The combination of Tamada and Lai teaches the argument. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 2-3, 5-6 and 9-10, 12-19are rejected under 35 U.S.C. 103 as being unpatentable over Tamada (JP 2009 026022 A) in view of Little (US 20200302074 A2). Regarding claim 2, Tamada teaches a computer system comprising: a processor; and a memory storing software arranged to execute on the processor ([0008], fig. 2 CPU 201, memory 202), the software comprising instructions operative upon execution by the processor to: receive a file access request indicating that an application process executing on the processor is requesting to access a target file in the memory ([0009] As shown in FIG. 3, the file access control unit 302 hooks the file access requested by the application 301, and the network access control unit 303 hooks the network access request requested by the application 301. The access management unit 304 cooperates with the file access control unit 302 and the network access control unit 303 to integrate and process file access information and network access information. The access management unit 304 also has a function of detecting the end of the application 301. The file access request permitted by the file access control unit 302 is processed by the lower-level file system driver 305 and storage device driver 306 via the OS I / O management unit); determine that the target file is designated as sensitive ([0013] The contents of the file access request are interpreted to obtain the file name to be accessed, and it is checked whether or not the file access request is an access to the object defined in the protection target definition table (designated as sensitive)); and based on the determination, deny the file access request ([0013] if access is prohibited, an error code indicating access prohibition (deny the file access request) is given to the file access request and returned to the application via the OS I / O management unit). Tamada does not explicitly teach determine that an active network connection to an untrusted endpoint exists. Little teaches determine that an active network connection to an untrusted endpoint exists ([0048] The observed data can include a current location of user as determined based on a source IP address contained in the file access request and a status indicative of whether the connection through which the user initiated the file access request is trusted or untrusted). It would have been obvious to a person of ordinary skill in the art before the effective filling date of the claimed invention made to include in the Tamada disclosure, determine an untrusted location of a user and a server, as taught by Little. One would be motivated to do so to allows to an improved file access approach that provides access to an electronic file. Regarding claim 3, Tamada and Little teaches the computer system of claim 2, wherein Tamada further teaches: the software comprises filesystem software and network filter software ([0009] The file access request permitted by the file access control unit 302 is processed by the lower-level file system driver; [0012] When communication is performed with the network access request permitted, “connection” is described. When the network access request is prohibited and communication is not performed, “not connected” is described (filter software)); the file access request is received by the filesystem software; and the determining comprises receiving, by the filesystem software, network filter software state information from the network filter software, the network filter software state information including an indication of whether there is any active network connection with an untrusted endpoint ([0012], fig. 6, column 604 indicates the time at which network access is requested. For example, if a process assigned with a process ID of “100” requests network access at the time “2007/06/15 15: 31: 000” and permits it, [process ID] The column 601 is “100”, the “status” column 602 is “connected”, the “judgment” column 603 is “permitted”, and the “time” column 604 is “2007/06/15 15: 31: 000 ”Is recorded; [0020] when there is no corresponding record in step S1104 will be described. The initial value of the variable J representing the connection state is set to “not connected”). Regarding claim 5, Tamada and Little teach the computer system of claim 2, wherein Tamada further taches the software comprises further instructions operative upon execution by the processor to: receive a connection establishment request indicating that a second application process executing on the processor is requesting to establish a network connection to a target network endpoint ([0009], fig. 3, the network access control unit 303 hooks the network access request requested by the application 301. The network access request permitted by the network access control unit 303 is passed to the lower protocol driver 307 and the network device driver 308 via the OS I/O management unit and processed; [0013] The process returns to waiting for access request); responsive to the receiving of the connection establishment request, determining whether the target network endpoint is trusted and whether the second application process has ever accessed a file designated as sensitive ([0013] The contents of the file access request are interpreted to obtain the file name to be accessed, and it is checked whether or not the file access request is an access to the object defined in the protection target definition table (designated as sensitive)); and deny the connection establishment request in response to determining that the target network endpoint is untrusted and the second application has previously accessed the file designated as sensitive ([0013] if access is prohibited, an error code indicating access prohibition (deny the file access request) is given to the file access request and returned to the application via the OS I / O management unit). Regarding claim 6, Tamada and Little the computer system of claim 5, wherein Tamada further teaches the software comprises filesystem software and network filter software ([0009] The file access request permitted by the file access control unit 302 is processed by the lower-level file system driver; [0012] When communication is performed with the network access request permitted, “connection” is described. When the network access request is prohibited and communication is not performed, “not connected” is described (filter software)); the connection establishment request is received by the network filter software, and the determining whether the second application has ever accessed a file designated as sensitive comprises receiving, by the network filter software, filesystem software state information from the filesystem software, the filesystem software state information including an indication whether the second application process has ever accessed a file designated as sensitive ([0012], fig. 6, column 604 indicates the time at which network access is requested; [0019] the display field 1401 displays the path of the program file of the application that is the file access request source, and the display field 1402 displays a list of protected files that have been accessed since the application was started). Regarding claim 9, Tamada and Little teach a computerized method for applying a security policy to a computer system, the method comprising: receiving a connection establishment request indicating that an application process is requesting to establish a connection over a network with a target network endpoint via a network interface of the computer system ([0009] As shown in FIG. 3, the file access control unit 302 hooks the file access requested by the application 301, and the network access control unit 303 hooks the network access request requested by the application 301. The access management unit 304 cooperates with the file access control unit 302 and the network access control unit 303 to integrate and process file access information and network access information. The access management unit 304 also has a function of detecting the end of the application 301. The file access request permitted by the file access control unit 302 is processed by the lower-level file system driver 305 and storage device driver 306 via the OS I / O management unit); based on the determination, denying the connection establishment request ([0013] if access is prohibited, an error code indicating access prohibition (deny the file access request) is given to the file access request and returned to the application via the OS I / O management unit). Tamada does not explicitly teach determining that the target network endpoint is untrusted and that the application process has previously accessed a file designated as sensitive; and Little teaches determining that the target network endpoint is untrusted and that the application process has previously accessed a file designated as sensitive ([0033] Exemplary factors can include, but are not limited to, history of general file access by the user, current location of the user, history of location of the user, time of access request, time when the user typically accesses a file, whether the user is accessing form a trusted location or an untrusted location; [0048] The observed data can include a current location of user as determined based on a source IP address contained in the file access request and a status indicative of whether the connection through which the user initiated the file access request is trusted or untrusted). It would have been obvious to a person of ordinary skill in the art before the effective filling date of the claimed invention made to include in the Tamada disclosure, determine an untrusted location of a user and a server, as taught by Little. One would be motivated to do so to allows to an improved file access approach that provides access to an electronic file. Regarding claim 10, Tamada and Little the method of claim 9, wherein Tamada further teaches the connection establishment request is received by network filter software, and the network filter software performs the determining of whether the application process has previously accessed a file designated as sensitive by receiving an indication from filesystem software indicating whether the application process has previously accessed a file designated as sensitive [0005] The file access is controlled using the history information of the network access information according to the above, ([0013] The contents of the file access request are interpreted to obtain the file name to be accessed, and it is checked whether or not the file access request is an access to the object defined in the protection target definition table (designated as sensitive)). Regarding claim 12, Tamada and Little the method of claim 9 teach the method of claim 9, Tamada further teaches: receiving a file access request from a second application, the file access request indicating that the second application is requesting access to a target file ([0009], fig. 3, the network access control unit 303 hooks the network access request requested by the application 301. The network access request permitted by the network access control unit 303 is passed to the lower protocol driver 307 and the network device driver 308 via the OS I/O management unit and processed; [0013] The process returns to waiting for access request); determining whether the target file is designated as sensitive and whether an active network connection to an untrusted target network endpoint exists ([0013] The contents of the file access request are interpreted to obtain the file name to be accessed, and it is checked whether or not the file access request is an access to the object defined in the protection target definition table (designated as sensitive)); and denying the file access request in response to determining that the target file is designated as sensitive ([0013] if access is prohibited, an error code indicating access prohibition (deny the file access request) is given to the file access request and returned to the application via the OS I / O management unit). Tamada does not explicitly teach the active network connection to an untrusted endpoint exists; Little teaches the active network connection to an untrusted endpoint exists ([0048] The observed data can include a current location of user as determined based on a source IP address contained in the file access request and a status indicative of whether the connection through which the user initiated the file access request is trusted or untrusted). It would have been obvious to a person of ordinary skill in the art before the effective filling date of the claimed invention made to include in the Tamada disclosure, determine an untrusted location of a user and a server, as taught by Little. One would be motivated to do so to allows to an improved file access approach that provides access to an electronic file. Regarding claim 13, Tamada and Little the method of claim 9 teach the method of claim 9, wherein Tamada further teaches the denying of the connection establishment request further comprises blocking establishment of a network connection with the target network endpoint ([0020] If the user determination is not “permitted” in step S1119, the record is added while the access control information H remains “prohibited” and the connection state J remains “not connected”). Regarding claim 14, Tamada and Little the method of claim 9 teach the method of claim 9, wherein Tamada further teaches the determining whether the application process has previously accessed a file designated as sensitive further comprises detecting that a flag is set, the flag indicating that the application process has previously accessed a file designated as sensitive ([0005] When the application requests the network access, the network access is controlled using the history information of the file access information by the application, and when the application requests the file access, the application). Regarding claim 15, Tamada teaches a computer-readable storage medium storing instructions executable by a processing apparatus to perform operations comprising: receiving a file access request indicating that an application process is requesting access to a target file ([0009] As shown in FIG. 3, the file access control unit 302 hooks the file access requested by the application 301, and the network access control unit 303 hooks the network access request requested by the application 301. The access management unit 304 cooperates with the file access control unit 302 and the network access control unit 303 to integrate and process file access information and network access information. The access management unit 304 also has a function of detecting the end of the application 301. The file access request permitted by the file access control unit 302 is processed by the lower-level file system driver 305 and storage device driver 306 via the OS I / O management unit); determining that an active network connection to an untrusted endpoint exists ([0013] The contents of the file access request are interpreted to obtain the file name to be accessed, and it is checked whether or not the file access request is an access to the object defined in the protection target definition table (designated as sensitive)); and based on the determination, denying the file access request ([0013] if access is prohibited, an error code indicating access prohibition (deny the file access request) is given to the file access request and returned to the application via the OS I / O management unit). Tamada does not explicitly teach determining that an active network connection to an untrusted endpoint exists. Little teaches determining that an active network connection to an untrusted endpoint exists ([0048] The observed data can include a current location of user as determined based on a source IP address contained in the file access request and a status indicative of whether the connection through which the user initiated the file access request is trusted or untrusted). It would have been obvious to a person of ordinary skill in the art before the effective filling date of the claimed invention made to include in the Tamada disclosure, determine an untrusted location of a user and a server, as taught by Little. One would be motivated to do so to allows to an improved file access approach that provides access to an electronic file. Regarding claim 16, Tamada and Little teach the computer-readable storage medium of claim 15, wherein Tamada further teaches the instructions include filesystem software and network filter software, the operations further comprise: receiving the file access request using the filesystem software ([0009] the file access control unit hooks the file access requested by the application, and the network access control unit hooks the network access request requested by the application); and determining whether an active network connection to an untrusted endpoint exists by receiving, by the filesystem software, network filter software state information from the network filter software ([0012], fig. 6, column 604 indicates the time at which network access is requested. For example, if a process assigned with a process ID of “100” requests network access at the time “2007/06/15 15: 31: 000” and permits it, [process ID] The column 601 is “100”, the “status” column 602 is “connected”, the “judgment” column 603 is “permitted”, and the “time” column 604 is “2007/06/15 15: 31: 000 ”Is recorded; [0020] when there is no corresponding record in step S1104 will be described. The initial value of the variable J representing the connection state is set to “not connected”). Regarding claim 17, Tamada and Little teach the computer-readable storage medium of claim 16, wherein Tamada further teaches the filesystem software and the network filter software are components of an operating system, and the oprations further comprises sharing state information between the filesystem software and the network filter software via a communication channel. Regarding claim 18, Tamada and Little teaches the computer-readable storage medium of claim 15, wherein Tamada further teaches the operations further comprise: receiving a connection establishment request indicating that a second application process is requesting to establish a network connection to a target network endpoint ([0009], fig. 3, the network access control unit 303 hooks the network access request requested by the application 301. The network access request permitted by the network access control unit 303 is passed to the lower protocol driver 307 and the network device driver 308 via the OS I/O management unit and processed; [0013] The process returns to waiting for access request); determining whether the target network endpoint is untrusted and whether the second application process has previously accessed a file designated as sensitive ([0013] The contents of the file access request are interpreted to obtain the file name to be accessed, and it is checked whether or not the file access request is an access to the object defined in the protection target definition table (designated as sensitive)); and denying the connection establishment request in response to determining that the target network endpoint is untrusted and that the second application process has previously accessed a file designated as sensitive ([0013] if access is prohibited, an error code indicating access prohibition (deny the file access request) is given to the file access request and returned to the application via the OS I / O management unit). Regarding claim 19, Tamada and Little the computer-readable storage medium of claim 18, wherein Tamada further teaches the instructions include network filter software and filesystem software, and the determination of whether the second application process has previously accessed a file designated as sensitive is performed by receiving filesystem software state information from the filesystem software ([0012], fig. 6, column 604 indicates the time at which network access is requested; [0019] the display field 1401 displays the path of the program file of the application that is the file access request source, and the display field 1402 displays a list of protected files that have been accessed since the application was started). Claims 4 and 11 are rejected under 35 U.S.C. 103 as being unpatentable over Tamada (JP 2009 026022 A) in view of Little (US 20200302074 A2) and further in view of Goldschlag (US 9171172 B2). Regarding claim 4, Tamada and Little teach the computer system of claim 3, Tamada does not explicitly teach wherein: the filesystem software and the network filter software are driver components of an operating system for the computer system, the operating system further comprises a communication channel for sharing filesystem software state information and the network filter software state information, the network filter software state information being received by the filesystem software via the communication channel. Goldschlag teaches the filesystem software and the network filter software are driver components of an operating system for the computer system, the operating system further comprises a communication channel for sharing filesystem software state information and the network filter software state information, the network filter software state information being received by the filesystem software via the communication channel (col. 29, lines 36-47, A policy enforcement point can comprise one, or a plurality of policy enforcers (10030a-10030n) that are part of the policy enforcement point (10000), such as, for example and not limitation, an information filter that suppresses sharing of particular fields of records being transferred to another process, or policy enforcers can be separate from a policy enforcement point (10040a-10040n), such as an aspect of an operating system, file system, firewall, or other aspect of a device useful for enforcing at least one policy element). It would have been obvious to a person of ordinary skill in the art before the effective filling date of the claimed invention made to include in the Tamada disclosure, sharing file system software state, as taught by Goldschlag. One would be motivated to do so for the multi-level federation, allocation, distribution, and enforcement of information management policies in networks of computing and communications devices to the multi-level federation, allocation, distribution, and enforcement of separately-sourced information management policies over a plurality of disparate sets of information within one or more such devices. Regarding claim 11, Tamada and Little teach the method of claim 10, Tamada does not explicitly teach wherein the network filter software receives the indication via a communication channel for sharing state between the filesystem software and the network filter software. Goldschlag teaches wherein the network filter software receives the indication via a communication channel for sharing state between the filesystem software and the network filter software (col. 29, lines 36-47, A policy enforcement point can comprise one, or a plurality of policy enforcers (10030a-10030n) that are part of the policy enforcement point (10000), such as, for example and not limitation, an information filter that suppresses sharing of particular fields of records being transferred to another process, or policy enforcers can be separate from a policy enforcement point (10040a-10040n), such as an aspect of an operating system, file system, firewall, or other aspect of a device useful for enforcing at least one policy element). It would have been obvious to a person of ordinary skill in the art before the effective filling date of the claimed invention made to include in the Tamada disclosure, sharing file system software state, as taught by Goldschlag. One would be motivated to do so for the multi-level federation, allocation, distribution, and enforcement of information management policies in networks of computing and communications devices to the multi-level federation, allocation, distribution, and enforcement of separately-sourced information management policies over a plurality of disparate sets of information within one or more such devices. Claims 7 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Tamada (JP 2009 026022 A) in view of Little (US 20200302074 A2) and further in view of Lai (US 20170364707 A1). Regarding claim 7, Tamada and Little teach the computer system of claim 6, wherein Tamada further teaches: the filesystem software comprises a first filesystem driver and a second filesystem driver, wherein: the second filesystem driver is operative upon execution by the processor to perform the denying of the file access request, and the first filesystem driver being operative upon execution by the processor to access the memory and thereby execute the file access request when granted ([0020] If the user's determination is “permitted” in step S1119, the process proceeds to step S1120. In step S1120, the content of the access control information H is updated to “permitted”, and in step S1121, the content of the connection state J is updated to “connected”. If the user determination is not “permitted” in step S1119, the record is added in step S1122 while the access control information H remains “prohibited” and the connection state J remains “not connected”); Tamada does not explicitly teach the network filter software comprises a first network filter driver and a second network filter driver, wherein: the second network filter driver being operative upon execution by the processor to perform the denying of the connection establishment request, and the first network filter driver being operative upon execution by the processor to implement one or more other network filter rules for granting or denying the connection establishment request or blocking an existing connection based on information other than a state of the filesystem driver software. Lai teaches the network filter software comprises a first network filter driver and a second network filter driver, wherein: the second network filter driver being operative upon execution by the processor to perform the denying of the connection establishment request, and the first network filter driver being operative upon execution by the processor to implement one or more other network filter rules for granting or denying the connection establishment request or blocking an existing connection based on information other than a state of the filesystem driver software ([0063] certain operating systems such as Microsoft® Windows™ may maintain an I/O driver stack that allows a class driver 308 to pass the I/O request down to the filter driver 310; [0067] the CID filter 136 determines whether the I/O transaction was verified. If not, the I/O transaction is dropped). It would have been obvious to a person of ordinary skill in the art before the effective filling date of the claimed invention made to include in the Tamada disclosure, a first and a second application to determine whether to access a request for data, as taught by Lai. One would be motivated to do so to allows for secure programming channels that allows untrusted software to be in control of the channels that are programmed while still maintaining confidentiality and integrity. Regarding claim 20, Tamada and Little teach the computer-readable storage medium of claim 19, wherein Tamada further teaches: the filesystem software comprises a first filesystem driver and a second filesystem driver, the second filesystem driver being operative upon execution by the processing apparatus to perform the denying of the file access request, and the first filesystem driver being operative upon execution by the processing apparatus to access memory and thereby execute the file access request when granted ([0020] If the user's determination is “permitted” in step S1119, the process proceeds to step S1120. In step S1120, the content of the access control information H is updated to “permitted”, and in step S1121, the content of the connection state J is updated to “connected”. If the user determination is not “permitted” in step S1119, the record is added in step S1122 while the access control information H remains “prohibited” and the connection state J remains “not connected”); Tamada does not explicitly teach the network filter software comprises a first network filter driver and a second network filter driver, the second network filter driver being operative upon execution by the processing apparatus to perform the denying of the connection establishment request, and the first network filter driver being operative upon execution by the processing apparatus to implement one or more other network filter rules for granting or denying the connection establishment request or blocking an existing connection based on information other than a state of the filesystem driver software. Lai teaches the network filter software comprises a first network filter driver and a second network filter driver, the second network filter driver being operative upon execution by the processing apparatus to perform the denying of the connection establishment request, and the first network filter driver being operative upon execution by the processing apparatus to implement one or more other network filter rules for granting or denying the connection establishment request or blocking an existing connection based on information other than a state of the filesystem driver software ([0063] certain operating systems such as Microsoft® Windows™ may maintain an I/O driver stack that allows a class driver 308 to pass the I/O request down to the filter driver 310; [0067] the CID filter 136 determines whether the I/O transaction was verified. If not, the method 600 advances to block 620, in which the I/O transaction is dropped). It would have been obvious to a person of ordinary skill in the art before the effective filling date of the claimed invention made to include in the Tamada disclosure, a first and a second application to determine whether to access a request for data, as taught by Lai. One would be motivated to do so to allows for secure programming channels that allows untrusted software to be in control of the channels that are programmed while still maintaining confidentiality and integrity. Claims 8 and 21 are rejected under 35 U.S.C. 103 as being unpatentable over Tamada (JP 2009 026022 A) in view of Little (US 20200302074 A2) and further in view of in view of Hamlin (US 20200074097 A1). Regarding claim 8, Tamada and Little teach the computer system of claim 5, Tamada does not explicitly teach wherein: the software comprises filesystem software and network filter software, the filesystem software and the network filter software being components of operating system software for the computer system; the operating system software further comprising a filesystem driver manager operative upon execution by the processor to receive the file access request from the application process via a system call layer of the operating system software, the filesystem software being operative upon execution by the processor to receive the file access request by subscribing to have file access requests for the target file forwarded from the filesystem driver manager; and the operating system software further comprises a network filter driver manager operative upon execution by the processor to receive the connection establishment request from the application process via the system call layer, and the network filter software is operative upon execution by the processor to receive the connection establishment request by subscribing to have connection establishment requests for the target network endpoint forwarded from the network filter driver manager. Hamlin teaches the software comprises filesystem software and network filter software, the filesystem software and the network filter software being components of operating system software for the computer system ([0009] The file access request permitted by the file access control unit 302 is processed by the lower-level file system driver; [0012] When communication is performed with the network access request permitted, “connection” is described. When the network access request is prohibited and communication is not performed, “not connected” is described (filter software)); the operating system software further comprising a filesystem driver manager operative upon execution by the processor to receive the file access request from the application process via a system call layer of the operating system software, the filesystem software being operative upon execution by the processor to receive the file access request by subscribing to have file access requests for the target file forwarded from the filesystem driver manager ([0038] the kernel 210 may include a security policy layer 220 that may be configured to broker data access requests by applications 205 and to enforce the access conditions 245 associated with data 250 that is provided to the user via the applications 205; [0040] the filesystem 230 may be configured to query the access conditions 245 for a data file 240 in response to a request for accessing the data 250 stored in the data file 240); and the operating system software further comprises a network filter driver manager operative upon execution by the processor to receive the connection establishment request from the application process via the system call layer, and the network filter software is operative upon execution by the processor to receive the connection establishment request by subscribing to have connection establishment requests for the target network endpoint forwarded from the network filter driver manager ([0038] upon receipt and authentication of a data access request received from an application 205, the security policy layer 220 may request access to the stored location of the requested data via a virtual filesystem 225 that provides the operating system and the applications 205 running therein with a logical file structure that abstracts the actual storage of the data 250 on the data storage device 235). It would have been obvious to a person of ordinary skill in the art before the effective filling date of the claimed invention made to include in the Tamada disclosure, determine a connection for requesting an access to the file system, as taught by Hamlin. One would be motivated to do so to support data security based on environmental properties and provide access to the data stored in the data file if the IHS satisfies the environmental conditions. Regarding claim 21, Tamada and Little teach the computer-readable storage medium of claim 15, Tamada does not explicitly teach wherein the denying of the file access request is performed according to a rule that if the target file designated as sensitive, the file access request is denied unless network filter software state information indicates that there is no active connection to any untrusted endpoint. Hamlin teaches wherein the denying of the file access request is performed according to a rule that if the target file designated as sensitive, the file access request is denied unless network filter software state information indicates that there is no active connection to any untrusted endpoint ([0055] If the IHS satisfies each of the environmental conditions required for accessing a requested data file, the user is granted access to the file data according to the access conditions for that file. If, however the IHS does not satisfy each of the environmental conditions, the IHS may be directed to remediation procedures that may allow IHS to become eligible for access to the file data). It would have been obvious to a person of ordinary skill in the art before the effective filling date of the claimed invention made to include in the Tamada disclosure, determine whether to allow or to deny the request based the status of the request, as taught by Hamlin. One would be motivated to do so to support data security based on environmental properties and provide access to the data stored in the data file if the IHS satisfies the environmental conditions. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Any inquiry concerning this communication or earlier communications from the examiner should be directed to ANH NGUYEN whose telephone number is (571)270-0657. The examiner can normally be reached M-F. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Umar Cheema can be reached at 5712703037. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /ANH NGUYEN/Primary Examiner, Art Unit 2458
Read full office action

Prosecution Timeline

Dec 11, 2024
Application Filed
Apr 09, 2026
Non-Final Rejection mailed — §103
Apr 30, 2026
Interview Requested
May 11, 2026
Applicant Interview (Telephonic)
May 11, 2026
Examiner Interview Summary
Jul 09, 2026
Response Filed
Aug 27, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750237
METHOD AND SYSTEM FOR PROTECTING DIGITAL SIGNATURES
2y 5m to grant Granted Sep 29, 2026
Patent 12750353
DISPOSABLE BROWSERS AND AUTHENTICATION TECHNIQUES FOR A SECURE ONLINE USER ENVIRONMENT
1y 9m to grant Granted Sep 29, 2026
Patent 12744805
SYSTEMS AND METHODS FOR MONITORING NETWORK TRAFFIC TO IDENTIFY CYBERATTACKS
2y 3m to grant Granted Sep 22, 2026
Patent 12744754
SYSTEM AND METHOD FOR MULTIVARIATE TESTING OF MESSAGES TO SUBGROUP IN A ONE-TO-MANY MESSAGING PLATFORM
2y 2m to grant Granted Sep 22, 2026
Patent 12739229
ONE-TIME VIRTUAL PRIVATE NETWORK
2y 2m to grant Granted Sep 15, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

2-3
Expected OA Rounds
79%
Grant Probability
99%
With Interview (+25.0%)
2y 9m (~11m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 376 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month