Prosecution Insights
Last updated: August 18, 2026
Application No. 19/070,792

Cloud-Based Data Security Posture Management (DSPM)

Non-Final OA §101§103§112
Filed
Mar 05, 2025
Priority
Apr 21, 2020 — CIP of 11/671,433 +4 more
Examiner
ABYANEH, ALI S
Art Unit
Tech Center
Assignee
Zscaler Inc.
OA Round
1 (Non-Final)
78%
Grant Probability
Favorable
1-2
OA Rounds
1y 10m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 78% — above average
78%
Career Allowance Rate
489 granted / 629 resolved
+17.7% vs TC avg
Strong +56% interview lift
Without
With
+56.0%
Interview Lift
resolved cases with interview
Typical timeline
3y 3m
Avg Prosecution
20 currently pending
Career history
654
Total Applications
across all art units

Statute-Specific Performance

§101
18.1%
-21.9% vs TC avg
§103
50.2%
+10.2% vs TC avg
§102
9.4%
-30.6% vs TC avg
§112
13.2%
-26.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 629 resolved cases

Office Action

§101 §103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. Claims 1-20 are pending. Information Disclosure Statement PTO-1449 The Information Disclosure Statement submitted by applicant on 03-05-2025 has been considered. Please see attached PTO-1449. Claim Rejections - 35 USC § 112 Claim 1 rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being incomplete for omitting essential steps, such omission amounting to a gap between the steps. See MPEP § 2172.01. Claim 1 recites “discovering and classifying any of data discovered by inline cloud inspection…”. However, claim does not recite the step of discovering data by inline cloud inspection. Because the claim relies on “data discovered by inline cloud inspection” without positively reciting how the inline cloud inspection discovers the data, an essential claim step has been omitted. Consequently, it is unclear what data is discovered by the inline cloud inspection, how the data is discovered by the inline cloud inspection, or whether any data is discovered by the inline cloud inspection, rendering the scope of the claim indefinite. Claim 11 recites limitations similar to the limitations of claim 1 and is rejected under 35 U.S.C. 112(b) for omitting essential steps and being indefinite for the same reasons. Dependent claims 2-10 and 12 -20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ) based on their dependency from the rejected independent claims. Claim Rejections - 35 USC § 101 835 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. The claims when analyzed under 2019 Revised Patent Subject Matter Eligibility Guidance, are directed to abstract idea. Claim 1 for example, recites a method and, therefore, is a process. The claim recites the limitation of “…discovering and classifying any of data discovered by inline cloud inspection, data stored across one or more cloud services, and data stored across one or more endpoints; continuously monitoring access to and usage of classified data… evaluating a security posture of the classified data by identifying misconfigurations, compliance violations, excessive permissions, and vulnerabilities; and enforcing one or more security policies based on the evaluated security posture”. These limitations, under broadest reasonable interpretation are directed performance of the limitations by human. That is, nothing in the claim element precludes the step from practically being performed by human. For example, the claim encompasses a human simply discovering and classifying data, monitoring and analyzing access to usage of classified data, evaluating a security posture of the classified data, and enforcing one or more security policy bast on the evaluation. Thus, the claim recites abstract idea when analyzed under step 2A prong 1. Claim 1 is further analyzed in step 2A prong 2, to evaluate whether the claim as a whole integrates the recited judicial exception into a practical application of the exception. This evaluation is performed by identifying whether there are any additional elements recited in the claim beyond the judicial exception, and evaluating those additional elements individually and in combination to determine whether the claim as a whole integrates the exception into a practical application. However, each of the remaining limitation (i.e., cloud-based system, cloud services) is recited at a high level of generality, and is no more than mere instruction to apply the exception using a generic computer component. The combination of these additional element is no more than generic computer functions. Thus, even in combination, these additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limitations on practicing the abstract idea. Claim 1 is additionally analyzed under Step 2B to evaluates whether the claim as a whole amount to significantly more than the recited exception, whether any additional element, or combination of additional elements, adds an inventive concept to the claim. When claims evaluated under step 2B, it is no more than what is well-understood, routine, conventional activity in the field. The specification does not provide any indication anything other than a generic computer component. The mere discovering and classifying any of data discovered… continuously monitoring access to and usage of classified data…evaluating a security posture of the classified data… and enforcing one or more security policies based on the evaluated security posture is a well-understood, routing and conventional function when it is claimed in a merely generic manner as it is here. Independent claim 11 include limitations similar to the limitations of claim 1 and is rejected under 35 U.S.C. 101 as being directed to abstract idea for the same reasons discussed above with respect to claim 1. In claims 2 and 12, generating compliance reports and audit logs reflecting data handling practices and security policy enforcement, could be performed by a human. A human could simply write/generate on a piece of paper compliance report and audit logs reflecting data handling practices and security policy enforcement. The claims do not recite additional elements that amounts to more than the judicial exception. In claims 3 and 13, the compliance reports of claim 2 and 12 is narrowed to include dashboards and visual analytics tools for reviewing detected anomalies, remediation actions taken, and overall compliance posture over time, which could be performed by a human with use of pen and paper. The claims do not recite additional elements that amounts to more than the judicial exception. In claims 4 and 14, the discovering and classifying include identifying sensitive data based on predefined or customizable classification policies, could be performed by human. A human could simply identify sensitive data written on a piece of paper based on classification policy. The claims do not recite additional elements that amounts to more than the judicial exception. In claims 5 and 15, wherein the policies include at least one of restricting access, encrypting data, or alerting security personnel, is considered as insignificant extra-solution activity. Insignificant extra-solution activity does not amount to an inventive concept, particularly when the activity is well-understood or conventional. In claims 6 and 16, wherein the discovering and classifying further include scanning data assets in one or more of Software as a Service (SaaS) platforms, Infrastructure as a Service (IaaS) platforms, on-premises data stores, databases, object stores, or private applications appears to be generic computer functions and is well-understood, routine, and conventional. These additional elements do not constitute meaningful limitations that would amount to significantly more than the abstract idea. In claims 7 and 17, wherein the monitoring includes utilizing machine learning to establish baseline data access patterns and detect anomalous behavior that indicates insider threats, unauthorized access, or data exfiltration attempts, could be performed by human. A human could establish baseline data access patterns and detect anomalous behavior. Other than reciting generic machine learning, nothing in the claim elements precludes the step from practically being performed by a human. In claims 8 and 18, wherein enforcing one or more security policies further comprises applying Data Loss Prevention (DLP) to block or redact sensitive information, and automatically implementing encryption or revocation of access privileges in response to detected anomalies, could be performed by human. The claims do not recite additional elements that amounts to more than the judicial exception. In claims 9 and 19, wherein the discovering and classifying includes integrating with Cloud Service Provider (CSP) Application Programing Interfaces (APIs) and native connectors to scan storage services, databases, containers, and virtual machines for data, could be performed by human. Other than reciting generic Cloud Service Provider (CSP) Application Programing Interfaces (APIs) and native connectors, nothing in the claim elements precludes the step from practically being performed by a human. In claims 10 and 20, wherein evaluating the security posture includes identifying misconfigurations in cloud storage buckets, improper Identity and Access Management (IAM) settings, or ineffective encryption measures could be performed by human. A human could identify misconfiguration by looking at a report or log on a computer display or piece of paper. The claims do not recite additional elements that amounts to more than the judicial exception Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1, 2, 5, 6, 8, 10-12, 15, 16, 18 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Parthasarathy (US Publication No. 2020/0311304 ), hereinafter Parthasarathy, in view of Narayan et al. (US Publication No. 2024/0039927), hereinafter Narayan, further in view of Narayanaswamy et al. (US Publication No. 2019/0268379), hereinafter Narayanaswamy. As per claims 1 and 11, Parthasarathy discloses a method implemented by a cloud-based system, the method comprising steps of: discovering and classifying any of data discovered by inline cloud inspection, data stored across one or more cloud services, and data stored across one or more endpoints (paragraph [0112],[0114]“The sensitive data discovery engine 102…performs sensitive data discovery 901 to find and classify sensitive data”); continuously monitoring access to and usage of classified data, wherein the monitoring is performed [in real-time] and includes analyzing data access patterns, user behaviors, and application interactions (paragraph [0109], “continuous monitoring of access of sensitive data by the data monitoring module 104 of the integrated platform 101 shown in FIG. 1, through an agent 106 deployed at a data source 116, according to an embodiment herein…the data monitoring module 104 monitors connections to the sensitive data in terms of who and what connects to the data sources and the applications having the sensitive data, to what sensitive data a user connects, where and how connections are made to the data sources and the applications having the sensitive data, etc. The data monitoring module 104 monitors the connections and statements, that is, the programs executed”). Parthasarathy does not disclose inline cloud inspection, real-time monitoring; evaluating a security posture of the classified data by identifying misconfigurations, compliance violations, excessive permissions, and vulnerabilities; and enforcing one or more security policies based on the evaluated security posture. However, in an analogous art, Narayan disclose, evaluating a security posture of the classified data by identifying misconfigurations, compliance violations, excessive permissions, and vulnerabilities; and enforcing one or more security policies based on the evaluated security posture (paragraph [0043], “the resource security manager identifies misconfigured cloud resources for remediation and performs remediation on the identified resource for current attack chain”, and paragraph [0016], “The term "misconfiguration" as used herein refers to a configuration that exposes corresponding resource(s) to security risk. Misconfigurations can include overprivileged access, access to certain resource functionality, access to sensitive data, resource vulnerabilities, etc.”). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Parthasarathy with Narayan. This would have been obvious because one of ordinary skill in the art would have been motivated to do so in order to detect attack chains. Parthasarathy in view of Narayan does not explicitly disclose, but in an analogous art, Narayanaswamy discloses, inline cloud inspection (paragraph [0066], “Inspection service 155 accomplishes this by acting as an inline proxy…”) and real-time monitoring (paragraph [0068], scanner performs monitoring in real-time ). It would have been obvious to one of ordinary skill in the art to combine Parthasarathy and Narayan with Narayanaswamy. This would have been obvious because one of ordinary skill in the art would have been motivated to provide continues visibility into data usage, enable timely detection of security risks and improve data loss prevention. As per claims 2 and 12, Parthasarathy furthermore discloses, wherein the steps include generating compliance reports and audit logs reflecting data handling practices and security policy enforcement (paragraph [0134], audit logs, [0147], compliance report) As per claims 5 and 15, Narayanaswamy furthermore discloses, wherein the policies include at least one of restricting access, encrypting data, or alerting security personnel (paragraph [0076], security policies specifies what security actions to take when a data egress request involves exfiltration of sensitive data. Some examples of security actions are blocking the data egress request, document encryption). The motivation is similar to the motivation provided in claim 1. As per claims 6 and 16, Parthasarathy furthermore discloses, wherein the discovering and classifying further include scanning data assets in one or more of Software as a Service (SaaS) platforms, Infrastructure as a Service (IaaS) platforms, on-premises data stores, databases, object stores, or private applications (paragraph [0067], “in the cloud data sources 113, the modules of the integrated platform 101 are implemented, for example, in a software agent 106 on a hosted application 113a in communication with a software as a system (SaaS) component 113b”). As per claims 8 and 18, Narayanaswamy furthermore discloses, wherein enforcing one or more security policies further comprises applying Data Loss Prevention (DLP) to block or redact sensitive information, automatically implementing encryption or revocation of access privileges in response to detected anomalies (paragraph [0048], [0076], “executing security actions like blocking the data egress request, seeking user justification, encrypting the docun1ent, quarantining the document, or coaching the user on the security policies”). The motivation is to enable timely detection of security risks and improve data loss prevention. As per claims 10 and 20, Narayan furthermore discloses, wherein evaluating the security posture includes identifying misconfigurations in cloud storage buckets, improper Identity and Access Management (IAM) settings, or ineffective encryption measures (paragraph [0016], “Misconfigurations can include overprivileged access, access to certain resource functionality, access to sensitive data, resource vulnerabilities, etc.”). The motivation is similar to the motivation provided in claim 1. Claims 3 and 13 are rejected under 35 U.S.C. 103 as being unpatentable over Parthasarathy in view of Narayan and Narayanaswamy, further in view of Varadan et al. (US Publication No. 2016/0098655), hereinafter Varadan. As per claims 3 and 13, While Parthasarathy discloses a dashboard and visual analysis tool (figures 13A-13P), and Nayara discloses dashboard for reviewing detected anomalies (paragraph [0034], presenting attack chain diagnostics to graphical user interface for inspection by export), Parthasarathy as modified does not explicitly disclose, the compliance reports include dashboards and visual analytics tools for remediation actions taken, and overall compliance posture over time. However, in an analogous art, Varadan discloses the compliance reports include dashboards and visual analytics tools for remediation actions taken, and overall compliance posture over time (paragraph [0029], “business governance visual dashboard 170 to provide a view of the compliance posture, risks involved, suggestive remediation plans”). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the modified Parthasarathy with Varadan. This would have been obvious because one of ordinary skill in the art would have been motivated to provides intuitive views of operations and compliance status, for managing operations, risks and compliance in one interactive system. Claims 4 and 14 are rejected under 35 U.S.C. 103 as being unpatentable over Parthasarathy in view of Narayan and Narayanaswamy, further in view of Williamson et al. (US Publication No. 2018/0232528), hereinafter Williamson. As per claims 4 and 14, Parthasarathy as modified does not explicitly disclose, but in an analogous art, Williamson discloses, wherein the discovering and classifying include identifying sensitive data based on predefined or customizable classification policies (abstract, “The processor applies each of the set of classification rules to a data portion to obtain an output of whether the data is sensitive data”). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the modified Parthasarathy with Williamson. This would have been obvious because one of ordinary skill in the art would have been motivated to automatically classifying information into different levels of sensitive data and automatically performing actions based on the level of sensitivity. Claims 7 and 17 are rejected under 35 U.S.C. 103 as being unpatentable over Parthasarathy in view of Narayan and Narayanaswamy, further in view of Mehrotra et al. (US Publication No. 2018/0337936), hereinafter Mehrotra. As per claims 7 and 17, Parthasarathy as modified does not explicitly disclose, but in an analogous art, Mehrotra discloses, wherein the monitoring includes utilizing machine learning to establish baseline data access patterns and detect anomalous behavior that indicates insider threats, unauthorized access, or data exfiltration attempts (paragraph [0008], “generating the baseline traffic patterns may include generating the baseline traffic patterns based upon machine learning”, paragraph [0009], “detect an anomaly therein relative to at least one of the baseline traffic patterns”). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the modified Parthasarathy with Mehrotra. This would have been obvious because one of ordinary skill in the art would have been motivated to implement the well know machine learning in order to automatically learn complex behavioral pattern and accurately detect malicious activity that deviates from the baseline. Claims 9 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Parthasarathy in view of Narayan and Narayanaswamy, further in view of Levin et al. (US Publication No. 20200213357), hereinafter Levin. As per claims 9 and 19, Parthasarathy as modified does not explicitly disclose, but in an analogous art, Levin discloses, wherein the discovering and classifying includes integrating with Cloud Service Provider (CSP) Application Programing Interfaces (APIs) and native connectors to scan storage services, databases, containers, and virtual machines for data (claim 2, “enumerating a plurality of application programming interface (API) endpoints in the cloud native environment using the cloud credentials, wherein the plurality of cloud assets is identified based on the enumerated plurality of API endpoints”). It would have been obvious to one of ordinary skill in the art before the effective32xz filing date of the claimed invention to combine the modified Parthasarathy with Levin. This would have been obvious because one of ordinary skill in the art would have been motivated to provide a cloud native discovery and protection. References Cited, Not Used The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Korthny et al. (US Publication No.2014/0095868) discloses, systems and methods for providing sensitive data protection in a virtual computing environment. The systems and methods utilize a sensitive data control monitor on a virtual appliance machine administering guest virtual machines in a virtual computing environment, wherein each of the guest virtual machines may include a local sensitive data control agent. The sensitive data control monitor generates encryption keys for each guest virtual machine which are sent to the local sensitive data control agents and used to encrypt data locally on a protected guest virtual machine. In this manner the data itself on the virtual (or physical) disc associated with the guest virtual machine is encrypted while access attempts are gated by a combination of the local agent and the environment-based monitor, providing for secure yet administrable sensitive data protection. Sawant et al. (US Patent No. 9,691,027 discloses, Machine-learning based detection (MLD) profiles can be used to identify sensitive information in documents. The MLD profile can be used to generate a confidence value for the document that expresses the degree of confidence with which the MLD profile can classify the document as sensitive or not. In one embodiment, a data loss prevention system provides or suggests a confidence level threshold to a user of the data loss prevention system by providing a confidence level threshold for the MLD profile to the user, the confidence level threshold to be used as the boundary between sensitive data and non-sensitive data. In one embodiment the provided confidence level threshold is determined by scanning a random data set using the MLD profile. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to ALI ABYANEH whose telephone number is (571)272-7961. The examiner can normally be reached Monday - Friday from 8:00 am-5:00pm (EST). Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached at (571)270-5143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /ALI S ABYANEH/Primary Examiner, Art Unit 2437
Read full office action

Prosecution Timeline

Mar 05, 2025
Application Filed
Jul 27, 2026
Non-Final Rejection mailed — §101, §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12695789
SYSTEM AND METHOD TO CREATE ZERO TRUST FRAMEWORK FOR SECURITY AS A SERVICE
4y 3m to grant Granted Jul 28, 2026
Patent 12651063
OBTAINING IMMUTABLE SNAPSHOTS IN STORAGE SYSTEMS FOR RECOVERY AFTER CORRUPTED DATA DETECTION
2y 4m to grant Granted Jun 09, 2026
Patent 12645794
METHOD, ELECTRONIC DEVICE, AND COMPUTER PROGRAM PRODUCT FOR SNAPSHOT CLASSIFICATION
3y 2m to grant Granted Jun 02, 2026
Patent 12647462
Systems and methods for intelligent application definition and protection
2y 6m to grant Granted Jun 02, 2026
Patent 12627697
CYBER THREAT INFORMATION PROCESSING APPARATUS, CYBER THREAT INFORMATION PROCESSING METHOD, AND STORAGE MEDIUM STORING CYBER THREAT INFORMATION PROCESSING PROGRAM
3y 1m to grant Granted May 12, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
78%
Grant Probability
99%
With Interview (+56.0%)
3y 3m (~1y 10m remaining)
Median Time to Grant
Low
PTA Risk
Based on 629 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month