Prosecution Insights
Last updated: October 02, 2026
Application No. 19/030,800

CONTENT INSPECTION OF ENTERPRISE DATA

Non-Final OA §103§DOUBLEPATENT
Filed
Jan 17, 2025
Priority
Mar 19, 2015 — provisional 62/135,656 +3 more
Examiner
DOAN, TRANG T
Art Unit
Tech Center
Assignee
NetSkope Inc.
OA Round
1 (Non-Final)
83%
Grant Probability
Favorable
1-2
OA Rounds
1y 7m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 83% — above average
83%
Career Allowance Rate
526 granted / 634 resolved
+23.0% vs TC avg
Strong +17% interview lift
Without
With
+16.8%
Interview Lift
resolved cases with interview
Typical timeline
3y 4m
Avg Prosecution
16 currently pending
Career history
658
Total Applications
across all art units

Statute-Specific Performance

§101
15.2%
-24.8% vs TC avg
§103
35.6%
-4.4% vs TC avg
§102
19.7%
-20.3% vs TC avg
§112
19.7%
-20.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 634 resolved cases

Office Action

§103 §DOUBLEPATENT
DETAILED ACTION In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. This Office Action is in response to the communication filed on 10/22/2025. Claim 1 has been canceled. Claims 2-21 have been added. Claims 2-21 are pending for consideration. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Specification The lengthy specification has not been checked to the extent necessary to determine the presence of all possible minor errors. Applicant’s cooperation is requested in correcting any errors of which applicant may become aware in the specification. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer. Claims 2-21 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-20 of U.S. Patent No. 9928377. Although the claims at issue are not identical, they are not patentably distinct from each other because both applications disclose the same subject matter such as providing visibility, control and data security for network delivered services, and more particularly relates to security and regulatory compliance of cloud services transactions and traffic. Furthermore, Examiner notes that each and every limitation of the instant claims appear to be substantially anticipated by the corresponding claims of the patent application. Therefore, Examiner respectfully submits that the instant claims and the claims of the patent application are not directed to patentably distinct inventions; thus, properly rejected on the grounds of nonstatutory double patenting, as further outlined below. Instant Application 19030800 Patent Application 9928377 Claim 2: A computer-implemented method, comprising: providing, by a network security system, a graphical user interface comprising a plurality of selectable elements for entering parameters of fine-grained content policies; receiving, via the graphical user interface, a content policy, wherein the content policy comprises: a search pattern, account identifiers to which the content policy applies, and a security action; detecting, with a cross-application monitor of the network security system, an activity being performed on a file by an endpoint accessing an application programming interface (API) of a cloud computing service (CCS);determining, by the network security system, that the content policy is violated based at least in part on determining the activity is being performed by an account having at least one of the account identifiers and the search pattern is identified in a content of the file; and in response to the determining the content policy is violated, perform the security action. Claim 1: A computer-implemented method of monitoring and controlling enterprise information stored on a cloud computing service (CCS), the method including: using a cross-application monitor to detect: a cloud computing service (CCS) application programming interface (API) in use by a client; and a function or an activity being requested by the client via the CCS API; determining the function or the activity to be performed by parsing API data exchanged via the CCS API, the parsing based on the detected CCS API, and identifying content being transmitted between the client and the CCS; selectively applying a content inspection rule with a multi-part string search pattern, based on at least the determined function or activity, to the content being transmitted between the client and the CCS to find two or more non-contiguous strings that are within a proximity specified in the content inspection rule and that, based on the finding, are therefore subject to content control; and triggering a security action responsive to finding the two or more non-contiguous strings subject to content control. Claim 12: A network security system, comprising: a processing system; and a memory having stored thereon instructions that, upon execution by the processing system, cause the processing system to: provide a graphical user interface comprising a plurality of selectable elements for entering parameters of fine-grained content policies; receive, via the graphical user interface, a content policy, wherein the content policy comprises: a search pattern, account identifiers to which the content policy applies, and a security action; detect, with a cross-application monitor of the network security system, an activity being performed on a file by an endpoint accessing an application programming interface (API) of a cloud computing service (CCS); determine that the content policy is violated based at least in part on determining the activity is being performed by an account having at least one of the account identifiers and the search pattern is identified in a content of the file; and in response to the determining the content policy is violated, perform the security action. Claim 15: A system of monitoring and controlling enterprise information stored on a cloud computing service (CCS), the system including: a processor and a computer readable storage medium storing computer instructions configured to cause the processor to: use a cross-application monitor to detect: a cloud computing service (CCS) application programming interface (API) in use by a client; and a function or an activity being requested by the client via the CCS API; determine the function or the activity to be performed by parsing API data exchanged via the CCS API, the parsing based on the detected CCS API, and identifying content being transmitted between the client and the CCS; selectively apply a content inspection rule with a multi-part string search pattern, based on at least the determined function or activity, to the content being transmitted between the client and the CCS to find two or more non-contiguous strings that are within a proximity specified in the content inspection rule and that, based on the finding, are therefore subject to content control; and trigger a security action responsive to finding the two or more non-contiguous strings subject to content control. The dependent claims of the instant application recite language similar to the dependent claims of the Patent application and are covered by the Patent application. Claims 2-21 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-14 of U.S. Patent No. 11238153. Although the claims at issue are not identical, they are not patentably distinct from each other because both applications disclose the same subject matter such as providing visibility, control and data security for network delivered services, and more particularly relates to security and regulatory compliance of cloud services transactions and traffic. Furthermore, Examiner notes that each and every limitation of the instant claims appear to be substantially anticipated by the corresponding claims of the patent application. Therefore, Examiner respectfully submits that the instant claims and the claims of the patent application are not directed to patentably distinct inventions; thus, properly rejected on the grounds of nonstatutory double patenting, as further outlined below. Instant Application 19030800 Patent Application 11238153 Claim 2: A computer-implemented method, comprising: providing, by a network security system, a graphical user interface comprising a plurality of selectable elements for entering parameters of fine-grained content policies; receiving, via the graphical user interface, a content policy, wherein the content policy comprises: a search pattern, account identifiers to which the content policy applies, and a security action; detecting, with a cross-application monitor of the network security system, an activity being performed on a file by an endpoint accessing an application programming interface (API) of a cloud computing service (CCS);determining, by the network security system, that the content policy is violated based at least in part on determining the activity is being performed by an account having at least one of the account identifiers and the search pattern is identified in a content of the file; and in response to the determining the content policy is violated, perform the security action. Claim 1: A computer-implemented method of monitoring and controlling exfiltration of documents stored on a cloud computing service (CCS), the method including: using a cross-application monitor to detect a cloud computing service (CCS) application programming interface (API) in use; and a function or an activity being performed via the CCS API on a document; determining the function or the activity being performed via the CCS API by parsing a data stream based on the CCS API and identifying content in the document being transmitted to the CCS; applying a content inspection rule to find strings and interrelated strings in the content that are subject to content control; providing a triplet of an organization ID of an organization that uses the CCS, a CCS ID, and a region ID as input to a first key-manager, and in response to the input, the first key-manager generating a triplet-key; and encrypting the document, using a per-document key derived by applying a key derivation function (KDF) to the triplet-key, a document identifier (ID), and a salt, responsive to finding the strings and interrelated strings subject to content control in the parsed stream. Claim 12: A network security system, comprising: a processing system; and a memory having stored thereon instructions that, upon execution by the processing system, cause the processing system to: provide a graphical user interface comprising a plurality of selectable elements for entering parameters of fine-grained content policies; receive, via the graphical user interface, a content policy, wherein the content policy comprises: a search pattern, account identifiers to which the content policy applies, and a security action; detect, with a cross-application monitor of the network security system, an activity being performed on a file by an endpoint accessing an application programming interface (API) of a cloud computing service (CCS); determine that the content policy is violated based at least in part on determining the activity is being performed by an account having at least one of the account identifiers and the search pattern is identified in a content of the file; and in response to the determining the content policy is violated, perform the security action. Claim 6: A computer-implemented system that monitors and controls exfiltration of documents stored on a cloud computing service (CCS), the system comprising: a processor and a non-transitory computer readable storage medium storing computer instructions configured to cause the processor to: use a cross-application monitor to detect a cloud computing service (CCS) application programming interface (API) in use; and a function or an activity being performed via the CCS API on a document; determine the function or the activity being performed via the CCS API by parsing a data stream based on the CCS API and identify content in the document being transmitted to the CCS; apply a content inspection rule to find strings and interrelated strings in the content that are subject to content control; provide a triplet of an organization ID of an organization that uses the CCS, a CCS ID, and a region ID as input to a first key-manager, and in response to the input, the first key-manager generating a triplet-key; and encrypt the document, using a per-document key derived by applying a key derivation function (KDF) to the triplet-key, a document identifier (ID), and a salt, responsive to finding the strings and interrelated strings subject to content control in the parsed stream. The dependent claims of the instant application recite language similar to the dependent claims of the Patent application and are covered by the Patent application. Claims 2-21 are rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-15 of U.S. Patent No. 12299117. Although the claims at issue are not identical, they are not patentably distinct from each other because both applications disclose the same subject matter such as providing visibility, control and data security for network delivered services, and more particularly relates to security and regulatory compliance of cloud services transactions and traffic. Furthermore, Examiner notes that each and every limitation of the instant claims appear to be substantially anticipated by the corresponding claims of the patent application. Therefore, Examiner respectfully submits that the instant claims and the claims of the patent application are not directed to patentably distinct inventions; thus, properly rejected on the grounds of nonstatutory double patenting, as further outlined below. Instant Application 19030800 Patent Application 12299117 Claim 2: A computer-implemented method, comprising: providing, by a network security system, a graphical user interface comprising a plurality of selectable elements for entering parameters of fine-grained content policies; receiving, via the graphical user interface, a content policy, wherein the content policy comprises: a search pattern, account identifiers to which the content policy applies, and a security action; detecting, with a cross-application monitor of the network security system, an activity being performed on a file by an endpoint accessing an application programming interface (API) of a cloud computing service (CCS);determining, by the network security system, that the content policy is violated based at least in part on determining the activity is being performed by an account having at least one of the account identifiers and the search pattern is identified in a content of the file; and in response to the determining the content policy is violated, perform the security action. Claim 1: A computer-implemented method of monitoring and controlling exfiltration of enterprise data, the method comprising: using a cross-application monitor to detect: a cloud computing service (CCS) application programming interface (API) in use, and a function or an activity being performed via the CCS API on a file, wherein the cross-application monitor is hosted from a computing system communicatively coupled to a network to which the CCS and an endpoint requesting the function or the activity are communicatively coupled; determining, by the cross-application monitor, the function or the activity being performed by parsing a data stream based on the CCS API and identifying content in the file; applying, by the cross-application monitor, a content inspection rule to find strings and interrelated strings in the content that are subject to content control, wherein the content inspection rule comprises a multi-part string search pattern that matches two or more non-contiguous strings; in response to finding a threshold number of strings and interrelated strings in the content, classifying, by the cross-application monitor, the content into a content type of a plurality of content types based on the threshold number of strings and interrelated strings, wherein the content type indicates a specific type of confidential data; selecting, by the cross-application monitor, a security action from a plurality of security actions based on the content type of the content; and performing, by the cross-application monitor, the security action on the file. Claim 12: A network security system, comprising: a processing system; and a memory having stored thereon instructions that, upon execution by the processing system, cause the processing system to: provide a graphical user interface comprising a plurality of selectable elements for entering parameters of fine-grained content policies; receive, via the graphical user interface, a content policy, wherein the content policy comprises: a search pattern, account identifiers to which the content policy applies, and a security action; detect, with a cross-application monitor of the network security system, an activity being performed on a file by an endpoint accessing an application programming interface (API) of a cloud computing service (CCS); determine that the content policy is violated based at least in part on determining the activity is being performed by an account having at least one of the account identifiers and the search pattern is identified in a content of the file; and in response to the determining the content policy is violated, perform the security action. Claim 9: A system that monitors and controls exfiltration of enterprise data, the system comprising: a processor and a non-transitory computer readable storage medium storing computer instructions configured to cause the processor to execute a method including: using a cross-application monitor to detect: a cloud computing service (CCS) application programming interface (API) in use, and a function or an activity being performed via the CCS API on a file, wherein the system is communicatively coupled to a network to which the CCS and an endpoint requesting the function or the activity are communicatively coupled; determining the function or the activity being performed by parsing a data stream based on the CCS API and identifying content in the file; applying a content inspection rule to find strings and interrelated strings in the content that are subject to content control, wherein the content inspection rule comprises a multi-part string search pattern that matches two or more non-contiguous strings; in response to finding a threshold number of strings and interrelated strings in the content, classifying the content into a content type of a plurality of content types based on the threshold number of strings and interrelated strings, wherein the content type indicates a specific type of confidential data; selecting a security action from a plurality of security actions based on the content type of the content; and performing the security action on the file. The dependent claims of the instant application recite language similar to the dependent claims of the Patent application and are covered by the Patent application. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-7, 10-17 and 20-21 are rejected under 35 U.S.C. 103 as being unpatentable over Pearl et al. (US 20140026182) (hereinafter Pearl) in view of Claudatos et al. (US 20060004818) (hereinafter Claudatos). Regarding claim 2, Pearl discloses a computer-implemented method, comprising: providing, by a network security system, a graphical user interface comprising a plurality of selectable elements for entering parameters of fine-grained content policies (Pearl: figures 6 and 20-22 and paragraph 111, 130-131 and 207, “The interface 2000 may include a policy type selection field 2001. If-then-conditional blocks may also be present as illustrated.”… “the user can generate an upload request by activating the upload feature in a tab on a user interface and initiate uploading by selecting (e.g., clicking on or otherwise activating) a button/tab”); receiving, via the graphical user interface, a content policy, wherein the content policy comprises: a search pattern, account identifiers to which the content policy applies, and a security action (Pearl: paragraphs 70, 127 and 200-201, “if an administrator is adding a new upload policy, the administrator may choose from the following options (in some embodiments the administrator can select multiple in some embodiments) for the system to detect upon upload of a file: a. Social Security Number; b. Credit Card Number; c. Keyword (e.g., confidential, or privileged); d. HIPAA; e. IBAN; f. bank account numbers (e.g., and/or any additional terms or metadata indicating sensitive information, content from 3rd party providers); etc.” “If an administrator is adding a new upload policy, in some embodiments the administrator may choose from the following options (in some embodiments they can select multiple) if a document contains one of the items selected in #2: Move the file to quarantine; Notify an email or multiple emails”); detecting, with a cross-application monitor of the network security system, an activity being performed on a file by an endpoint accessing an application programming interface (API) of a cloud computing service (CCS) (Pearl: paragraphs 60-63, 70 and 127, “in order to support data loss prevention in the cloud system for users (e.g., customers) across multiple platforms and multiple and/or all applications, a data loss system may identify the key user/customer requirements (e.g., application, client, or customer based).”… “a customer, e.g. a system administrator, may be able to set rules that are triggered by the detection of, e.g.: a. known information types such as credit card numbers, SSNs, Tax Ids, etc.; b. Keywords identified by the customer: "confidential", or product specific names.”); determining, by the network security system, that the content policy is violated based at least in part on determining the activity is being performed by an account (Pearl: paragraphs 66, 70, and 131, “the engine may be triggered by the severity associated with an incident, the number of matching terms between a rule and uploaded file, the upload endpoint's current location (on/off corporate network), etc. In some embodiments, various types of responses to detected policy violations may include, for example, email notification, setting incident status, blocking file and pop-up warning to user, copying or moving a file”… “the provider 606 may be an entity that is specialized in sensitive information identification (e.g., a specialized search engine and/or a specialized database), and the host server (e.g., cloud-based host or service provider cloud-based platform/service (e.g., cloud-based collaboration platform) 605 may communicate with the provider 606 upon receipt of a file, and can receive knowledge or verification information from the provider 606 of whether an uploaded file contains sensitive information or otherwise triggers a policy/rule”); and in response to the determining the content policy is violated, perform the security action (Pearl: paragraphs 70 and 225, “the engine may be triggered by the severity associated with an incident, the number of matching terms between a rule and uploaded file, the upload endpoint's current location (on/off corporate network), etc. In some embodiments, various types of responses to detected policy violations may include, for example, email notification, setting incident status, blocking file and pop-up warning to user, copying or moving a file, etc. The responses may be automatically performed or manually instructed, e.g. by the user/customer or administrator”). Pearl does not explicitly disclose the following limitation which is disclosed by Claudatos, determining that the content policy is violated by an account having at least one of the account identifiers and the search pattern is identified in a content of the file (Claudatos: paragraphs 0030, 0084-0085 and 0089, “Pattern matching to known file patterns may also be used to determine the file type. The information about the type of data contained by the object can be used to analyze its contents, thereby deriving information to set an appropriate ILM policy”… “documents and files can be inspected for the presence of private patient data such as the patient's name, social security number, patient ID, diagnostic code, treatment code, name of the patient's condition(s), etc. By inspecting the files for any or specific combinations of these data elements it can be determined which ILM policy is appropriate. In an embodiment, a keyword-driven search or natural language analysis may be utilized. Thus, multiple documents/files/objects may be associated to a patient healthcare policy or other policy.”). Pearl and Claudatos are analogous art because they are from the same field of endeavor, access protection. Before the effective filing date of the claimed invention, it would have been obvious to one of ordinary skill in the art, having the teachings of Pearl and Claudatos before him or her, to modify the system of Pearl to include determining that a content policy is violated by an account having at least one of an account identifiers and a search pattern is identified in a content of a file of Claudatos. The suggestion/motivation for doing so would have for an improved method, article of manufacture, and apparatus for managing lifecycle of files and other objects in a storage system (Claudatos: paragraph 0005). Regarding claim 12, claim 12 discloses a system claim that is substantially equivalent to the method of claim 2. Therefore, the arguments set forth above with respect to claim 1 are equally applicable to claim 12 and rejected for the same reasons. Regarding claims 3 and 13, Pearl as modified discloses receiving, via the graphical user interface, a plurality of content policies, including the content policy, wherein: at least one of the plurality of content policies comprise a service category into which CCSs are classified to which the at least one of the plurality of content policies applies (Pearl: paragraphs 0064, 0104 and 0127-0131, “in some native solution in the cloud service described in certain embodiments, the system may scan for certain types of data that have a consistent formats, e.g., Social Security Numbers, Credit Card Numbers, bank account numbers and ABA bank routing numbers, etc. This can be performed in a manner that is transparent to administrators or end users in some embodiments. Policy management can be performed natively by the cloud service or deferred to a third party, or performed by a combination of the cloud service and third party, depending upon the embodiment”… “the rules may be active once set for all modifications, updates, deletions of files. In some embodiments, the rule may be active within a certain service level agreement (SLA) between the client's organization and the cloud-based platform/service (e.g., cloud-based collaboration platform) organization for all files within an enterprise.”). Regarding claims 4 and 14, Pearl as modified discloses wherein: the at least one of the plurality of content policies comprise a cloud confidence score applied to the CCSs to which the at least one of the plurality of content policies applies (Pearl: paragraphs 0068, 0079, 0133 and 0244, “the data loss prevention system may implement, enforce, or update Service Level Agreements for rules”… “Success Criteria may be specified. Some examples of criteria may include: 20% of enterprise admins create at least 1 security-related rule in the 1st quarter of admin deployment--potentially to high; 15% of admins create at least 1 automation in the 1st quarter of deployment.”… “An administrator may provide the metadata 701 to the host server (e.g., cloud-based host or service provider) cloud-based platform/service (e.g., cloud-based collaboration platform) 605 to ensure that confidential material is not prematurely disclosed to the public via the collaboration and file uploading processes.”). Regarding claims 5 and 15, Pearl as modified discloses further comprising: receiving, via the graphical user interface, a plurality of content policies, including the content policy, wherein: at least one of the plurality of content policies comprise an activity type to which the at least one of the plurality of content policies applies (Pearl: paragraphs 0078 and 0093, “The collaboration platform or environment hosts workspaces with work items that one or more users can access (e.g., view, edit, update, revise, comment, add to discussions, download, preview, tag, or otherwise manipulate, etc.)”… “a first type of permission level, e.g. an editor, can allow a user to have full read and write access to a workspace such that the user can view and download contents of the workspace as well as upload new content to the workspace. A second type of permission level, e.g. a viewer, can allow a user to have full read access to a workspace such that the user can view and download contents of the workspace but not upload or edit contents of the workspace. A third type of permission level, e.g. an uploader, can allow a user to have limited write access to contents of a workspace such that the user can see items in the workspace but not download or view the items, while being permitted to upload new content to the workspace.”). Regarding claims 6 and 16, Pearl as modified discloses wherein the activity type comprises one or more of upload, download, and share (Pearl: paragraphs 0078, 0093 and 0096-0097, “The activity can be performed in relation to a discussion topic in the work space, for example, adding a response to a discussion topic, deleting a response, or editing a response in the work space. In addition, the activity is performed on a work item in the work space by the user, including, by way of example but not limitation, download or upload of a work item, deletion of editing of the work item, selecting, adding, deleting, and modifying a tag in the work item, preview of the work item or comment of the work item, setting or changing permissions of the work item, sharing a work item, emailing a link to the work item, and/or embedding a link to the work item on another website.”). Regarding claims 7 and 17, Pearl as modified discloses wherein the security action comprises one of: encrypting the file; blocking the activity; requesting justification; quarantining the file; and coaching a user of the endpoint on allowed activities (Pearl: paragraphs 0131 and 0150, “in case that the host server (e.g., cloud-based host or service providercloud-based platform/service (e.g., cloud-based collaboration platform) 605 determines (e.g., by itself, such as explained in FIG. 7 below) or is informed (e.g., by the provider 606) that an file contains sensitive information, actions (e.g., quarantine) can be taken with respect to such file (as explained in more detail below).”). Regarding claims 10 and 20, Pearl as modified discloses further comprising: receiving, via the graphical user interface, a plurality of content policies, including the content policy, wherein: at least one of the plurality of content policies comprise a domain of CCSs to which the at least one of the plurality of content policies applies (Pearl: paragraphs 0183 and 0206, “With regard to policies Sharing, the corresponding rules may indicate that if a file/folder is shared with [specified domains], then send an email alert to [specified people] following the detection.”… “If an administrator is adding a sharing policy, in some embodiments the administrator may specify the following: one or more domains, separated by commas, for the system to watch for sending a notification email to one or more email addresses, separated by commas. In some embodiments, once an administrator clicks "Start Policy," if a user sends a shared link or adds a collaborator to a file/folder from one of the listed domains, an email alert may be sent to the emails listed. In some embodiments, the sharing policy may specify email alert templates. The interface may permit the administrator to tailor the contents of the interface.”). Regarding claims 11 and 21, Pearl as modified discloses further comprising: receiving, via the graphical user interface, a plurality of content policies, including the content policy, wherein: at least one of the plurality of content policies comprise a search string and a threshold number of times the search string is found to trigger the at least one of the plurality of content policies (Claudatos: paragraphs 0030, 0036, 0084-0085 and 0089, “Pattern matching to known file patterns may also be used to determine the file type. The information about the type of data contained by the object can be used to analyze its contents, thereby deriving information to set an appropriate ILM policy”… “By inspecting the files for any or specific combinations of these data elements it can be determined which ILM policy is appropriate. In an embodiment, a keyword-driven search or natural language analysis may be utilized. Thus, multiple documents/files/objects may be associated to a patient healthcare policy or other policy.”.. “Upon detection of content that matches lexicon content, metadata may be generated and associated with the content. Such metadata may be the text equivalent of the auditory content or it may be a pointer to other data held within the lexicon. The search for keywords and sound matches could specify: [0037] The order of the appearance/sequence (e.g., "Buy" followed by "Stock") [0038] Specific inter-keyword distance ("Buy" followed by "Stock" as the next word) [0039] The number of repetitions within a timeframe or communication session [0040] The inverse of the above: [0041] Keywords are present but not in the specific sequence [0042] Keywords are present but not within the inter-keyword distance [0043] Keywords are present but not repeated within specification [0044] The absence of the keyword(s); i.e. a non-match or negative match [0045] Groups of keywords”). The same motivation to modify Pearl in view of Claudatos, as applied in claim 2 above, applies here. Allowable Subject Matter Claims 8-9 and 18-19 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. The following is a statement of reasons for the indication of allowable subject matter: As to claims 8-9 and 18-19, none of the art of reference, discloses, individually or in reasonable combination, the features recited in claims 8-9 and 18-19 if written in independent form including all of the limitations of the base claim and any intervening claims. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to TRANG T DOAN whose telephone number is (571)272-0740. The examiner can normally be reached Monday-Friday 7-4 ET. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn D Feild can be reached on (571)272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /TRANG T DOAN/Primary Examiner, Art Unit 2431
Read full office action

Prosecution Timeline

Jan 17, 2025
Application Filed
Sep 01, 2026
Non-Final Rejection mailed — §103, §DOUBLEPATENT (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12726827
METHOD FOR EXTERNAL AUTHENTICATION AND AUTHORIZATION
3y 2m to grant Granted Sep 01, 2026
Patent 12726277
SINGLE-PHOTON TRANSMISSION DETERMINATION
2y 2m to grant Granted Sep 01, 2026
Patent 12719884
System and Method for Intrusion Detection of Malware Traffic based on Feature Information
4y 8m to grant Granted Aug 25, 2026
Patent 12712714
Transmission of a message by quantum communication with eavesdropping detection
2y 6m to grant Granted Aug 18, 2026
Patent 12711261
SOVEREIGN DATA CENTER STAGING AREA
2y 3m to grant Granted Aug 18, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
83%
Grant Probability
99%
With Interview (+16.8%)
3y 4m (~1y 7m remaining)
Median Time to Grant
Low
PTA Risk
Based on 634 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month