DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claims 1-20 have been examined.
Response to Arguments
Applicant’s arguments with respect to claims 1-20 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. Specifically, Vaikar et al. U.S. 9,069,992 is relied upon for the newly recited limitations.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Narayanaswamy et al. U.S. 2019/0268379 (hereinafter Narayanaswamy) in view of Vaikar et al. U.S. 9,069,992 (hereinafter Vaikar).
As per claim 1 and 11, Narayanaswamy discloses a method implemented by a cloud-based system, the method comprising steps of:
monitoring user traffic associated with one or more tenants of the cloud-based system, the traffic including actions performed in association with a file sharing and storage service (Narayanaswamy: [0034]: DLP solutions for file access, saving or sharing in the cloud; [0065]-[0070]: cloud based network security system inspects network traffic and classifies data stored in the cloud);
responsive to a user accessing a file within the file sharing and storage service, performing a Data Loss Prevention (DLP) scan requirement analysis (Narayanaswamy: Fig. 4 and [0088]-[0089]: determine if sensitivity scanner is required based on metadata);
based on a result of the DLP scan requirement analysis, (i) performing a DLP scan of the file or (ii) bypassing a DLP scan of the file (Narayanaswamy: [0089]: if there’s no metadata regarding the file, transmit the data to cloud-based sensitivity scanner, otherwise bypass the scanning and process according to DLP policy); and
performing one or more actions based on policy associated with the user and the file (Narayanaswamy: [0088]-[0089]: enforce DLP policy based on metadata).
Narayanaswamy discloses the central concept of determining whether scanning is required based on file metadata dynamically based on changes or update to files or policies are well known in the art (Narayanaswamy: [0068]; [0110]). Naryanaswamy does not explicitly disclose, but Vaikar discloses, responsive to creation of a file in the file sharing and storage service, performing a DLP scan of the file and storing original metadata of the file (Vaikar: col. 12 lines 38-66: generating metadata for new file when it’s received or created by the computing device that enforces DLP policies); responsive to subsequent access of the file, perform DLP scan requirement analysis by comparing the original metadata to current metadata of the file to determine whether DLP scan is required (Vaikar: col. 4 lines 35-54: determine if there’s match between current metadata that contains fingerprint of the file with previously generated metadata; if there’s a match, no new scan is required). It would have been obvious to one having ordinary skill in the art to generate metadata containing fingerprint or hash of the scanned file for future reference because they are analogous art involving cloud-based DLP. The motivation to combine would be to prevent redundant DLP scans to conserve network resources.
As per claim 2 and 12, Narayanaswamy as modified discloses the limitations of claims 1 and 11 respectively. Narayanaswamy further discloses performing the DLP scan requirement analysis includes a correlation engine of the cloud-based system retrieving the original metadata from a data store of the cloud-based system and correlating the original metadata and an action performed by the user on the file (Narayanaswamy: [0088]; Vaikar: col. 4 lines 35-54). Same rationale applies here as above in rejecting claim 1.
As per claim 3 and 13, Narayanaswamy as modified discloses the limitations of claims 1 and 11 respectively. Narayanaswamy further discloses wherein the DLP scan requirement analysis is based on stored file metadata, the file metadata including any of a hash of the file, a name of the file, an owner of the file, a label of the file, a classification of the file, dictionaries of the file, a policy time stamp, and file sharing information (Narayanaswamy: [0088]-[0089]: determine sensitivity of the document based on stored metadata).
As per claim 4 and 14, Narayanaswamy as modified discloses the limitations of claims 1 and 11 respectively. Narayanaswamy further discloses wherein the original metadata includes a hash of the file, the current metadata includes a current hash of the file and a DLP scan is bypassed on the file responsive to the current hash matching the hash and a file sharing action having been performed on the file (Narayanaswamy: [0110]: detect changes or revisions to the file and update metadata; Vaikar: col. 4 lines 35-54). Same rationale applies here as above in rejecting claim 1.
As per claim 5 and 15, Narayanaswamy discloses the limitations of claims 3 and 13 respectively. Narayanaswamy further discloses wherein a DLP scan is performed on the file responsive to determining that policy associated with the file has been changed (Narayanaswamy: [0111]).
As per claim 6 and 16, Narayanaswamy discloses the limitations of claims 3 and 13 respectively. Narayanaswamy further discloses wherein a DLP scan is performed on the file responsive to determining that an owner of the file has changed (Narayanaswamy: [0069]; [0075]: monitors various types of egress requests including saving, editing, revising, copying, or deleting, etc.).
As per claim 7 and 17, Narayanaswamy discloses the limitations of claims 3 and 13 respectively. Narayanaswamy further discloses wherein a DLP scan is performed on the file responsive to determining that file sharing information of the file has changed (Narayanaswamy: [0068];[0087]).
As per claim 8 and 18, Narayanaswamy discloses the limitations of claims 1 and 11 respectively. Narayanaswamy further discloses wherein responsive to the user creating a new file in the file sharing and storage service, the steps comprise: performing a DLP scan of the file; and storing original metadata of the file (Naranyanaswamy: [0086]-[0087]: perform scan and classification for newly discovered files).
As per claim 9 and 19, Narayanaswamy discloses the limitations of claims 8 and 18 respectively. Narayanaswamy further discloses wherein the DLP scan requirement analysis is based on the original metadata of the file and current metadata of the file (Narayanaswamy: [0110]).
As per claim 10 and 20, Narayanaswamy discloses the limitations of claims 1 and 11 respectively. Narayanaswamy further discloses wherein the one or more actions are performed based on the DLP scan of the file (Narayanaswamy: [0087]).
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Paul et al. U.S. 2023/0037489 discloses data loss prevention via dual mode indexed document matching.
Paul et al. U.S. 2021/0326461 discloses data loss prevention on images.
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SHIN HON (ERIC) CHEN whose telephone number is (571)272-3789. The examiner can normally be reached Monday to Thursday 9am- 7pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn Feild can be reached at 571-272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/SHIN-HON (ERIC) CHEN/Primary Examiner, Art Unit 2431