Prosecution Insights
Last updated: October 02, 2026
Application No. 19/079,219

DISALLOWING READS ON FILES ENCRYPTED WITH A COMPROMISED KEY USING A HYBRID SEGMENT REFERENCE FILTER SYSTEM

Non-Final OA §103§DOUBLEPATENT
Filed
Mar 13, 2025
Priority
Feb 28, 2022 — CIP of 12/254,108
Examiner
MOLES, JAMES P
Art Unit
Tech Center
Assignee
Dell Products L.P.
OA Round
1 (Non-Final)
67%
Grant Probability
Favorable
1-2
OA Rounds
1y 3m
Est. Remaining
95%
With Interview

Examiner Intelligence

Grants 67% — above average
67%
Career Allowance Rate
32 granted / 48 resolved
+6.7% vs TC avg
Strong +29% interview lift
Without
With
+28.6%
Interview Lift
resolved cases with interview
Typical timeline
2y 9m
Avg Prosecution
14 currently pending
Career history
57
Total Applications
across all art units

Statute-Specific Performance

§101
7.6%
-32.4% vs TC avg
§103
67.0%
+27.0% vs TC avg
§102
7.1%
-32.9% vs TC avg
§112
15.2%
-24.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 48 resolved cases

Office Action

§103 §DOUBLEPATENT
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This office action is in response to the applicant’s filing on 03/13/2025. Claims 1-20 are pending. Claims 1, 10, and 18 are independent. Priority Acknowledgement is made of applicant’s claiming of priority, as a continuation-in-part, to application 17/682,174 filed on 02/28/2022. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer. Claims 1-3, 10-11, and 17 rejected on the ground of nonstatutory double patenting as being unpatentable over claims 4 and 13 of U.S. Patent No. 12254108. Although the claims at issue are not identical, they are not patentably distinct from each other because the claims of the patent anticipate the claims of the instant application. For the mapping of claims, see the table below. 19/079,219 Patent No. 12254108 1. A computer-implemented method of blocking access to files encrypted with a compromised encryption key, comprising: maintaining a map of encryption keys and ranges of containers encrypted by respective encryption keys; receiving an indication that an encryption key is compromised as a compromised key; identifying a container range containing data encrypted by the compromised key as impacted data, the container range having containers comprising data segments and metadata segments; maintaining a probabilistic segment reference filter to enumerate segments from the impacted container range for the data segments; and building a deterministic segment reference filter to enumerate segments from the impacted container range for the metadata segments. 1. A computer-implemented method of blocking access to files encrypted with a compromised encryption key, comprising: maintaining a map of encryption keys and ranges of containers encrypted by respective encryption keys; receiving an indication that an encryption key is compromised as a compromised key; fencing a container range corresponding to data segments encrypted by the compromised key to prevent deduplication operations on the data segments; making a point-in-time copy of the filesystem managing the data segments, wherein each file of the file system is represented as a Merkle tree storing fingerprints of data using a hashing method and having a root level and one or more hierarchical lower levels; iteratively inspecting, from the lowest level to a highest level, each container in each level of the file trees of the files to identify containers having segments encrypted by the compromised key for a corresponding level; and marking files corresponding to the identified containers as not readable to block the access to the files encrypted with the compromised key, wherein data is processed as part of a deduplication backup process executed by a data storage server, and wherein the backup process looks up the fingerprints in a hash table constituting an index to determine if the fingerprints exist or do not exist within the hash table, and if not, compressing and encrypting corresponding data segments into compression regions for storing in the containers, and further wherein a bitmap correlates a container identifier (ID) with a respective encryption key ID, and fingerprints contained in each container referenced by a container ID to tabulate all the fingerprints of the containers as the bitmap, and further comprising marking an entry in the bitmap for each fingerprint of an identified container having segments encrypted by the compromised key, as an impacted fingerprint. (claim 2) The method of claim 1 further comprising storing references to the identified containers in a segment reference filter as the bitmap. (claim 3) The method of claim 2 wherein the segment reference filter comprises one of a deterministic data structure or a probabilistic data structure. (claim 4) The method of claim 3 wherein the deterministic data structure comprises a perfect hash vector (PHVEC), and the probabilistic data structure comprises one of: a quotient filter, a Bloom filter, or a cuckoo filter. 2. The method of claim 1 wherein the deterministic data segment reference filter comprises a perfect hash vector (PHVEC), and the probabilistic segment reference filter comprises one of: a quotient filter, a Bloom filter, or a cuckoo filter. 4. The method of claim 3 wherein the deterministic data structure comprises a perfect hash vector (PHVEC), and the probabilistic data structure comprises one of: a quotient filter, a Bloom filter, or a cuckoo filter. 3. The method of claim 2 further comprising: making a point-in-time copy of a filesystem managing the containers, wherein each file of the filesystem is represented as a directory tree storing fingerprints of data using a hashing method and having a root level and one or more hierarchical lower levels; iteratively inspecting, using one of the deterministic or probabilistic segment reference filter, each container in each level of the file trees from the lowest level to a highest level of the files to identify containers having segments encrypted by the compromised key for a corresponding level; and marking files corresponding to the identified containers as not readable to block the access to the files encrypted with the compromised key. (claim 1) making a point-in-time copy of the filesystem managing the data segments, wherein each file of the file system is represented as a Merkle tree storing fingerprints of data using a hashing method and having a root level and one or more hierarchical lower levels; (claim 1) iteratively inspecting, from the lowest level to a highest level, each container in each level of the file trees of the files to identify containers having segments encrypted by the compromised key for a corresponding level; and marking files corresponding to the identified containers as not readable to block the access to the files encrypted with the compromised key (claim 3) the segment reference filter comprises one of a deterministic data structure or a probabilistic data structure. 10. A computer-implemented method of blocking access to files encrypted with a compromised encryption key, comprising: defining tree structures for each file of the set of files processed by a deduplication backup system, and storing compression region fingerprints in a plurality of levels with a root level, and encrypted with a key; reading a container header of containers impacted by a compromised key to identify a list of segments referred to by the impacted containers; first scanning, using a probabilistic segment reference filter, data containers in a data level of the directory tree to find containers with data segments encrypted with a compromised key; second scanning, using a deterministic segment reference filter, metadata containers in metadata levels of the directory tree to find containers with metadata segments encrypted with a compromised key by going up from a lowest to the root level using parent-child references of the directory tree; and marking files having data or metadata segments encrypted with the compromised key as not readable to block accesses to the files. 8. A computer-implemented method of blocking access to files encrypted with a compromised encryption key, comprising: defining Merkle tree structures for each file of the set of files processed by a deduplication backup system, the Merkle structure storing compression region fingerprints in a plurality of levels with a root level, and encrypted with a key; reading a container header of containers impacted by a compromised key to identify a list of segments referred to by the impacted containers; scanning, in a level-wise manner, containers in each Merkle tree level to find containers with segments encrypted with a compromised key by going up from a lowest to the root level using parent-child references of the Merkle tree; marking files having segments encrypted with the compromised key as not readable to block accesses to the files; temporarily fencing the files having segments encrypted with the compromised key from deduplication operations of the deduplication backup system; storing the list of segments in a segment reference filter data structure as a bitmap tabulating the containers as a horizontal array; scanning all containers in a demarcated range to enumerate all leaf metadata segments of the files; looking up, in the segment reference filter, every enumerated child segment to determine a positive or negative lookup; and referring, for a positive lookup, the parent segment as an impacted segment by adding the parent segment to the segment reference filter. (Claim 11) The method of claim 8 wherein the segment reference filter is a probabilistic data structure, and comprises one of a quotient filter, a Bloom filter, or a Cuckoo filter. (Claim 12) The method of claim 11 wherein the data comprises data segments and metadata segments, and wherein the segment reference filter comprises both a PHVEC data structure and a probabilistic data structure. (Claim 13) The method of claim 12 further comprising using the PHVEC data structure to enumerate segments from an impacted container range for data segments and using the probabilistic data structure to enumerate segments from the impacted container range for metadata segments. 11. The method of claim 10 wherein the probabilistic data segment reference filter comprises one of: a quotient filter, a Bloom filter, or a cuckoo filter, and further wherein the deterministic segment reference filter comprises a perfect hash vector (PHVEC). (Claim 10) The method of claim 8 wherein the segment reference filter is a deterministic data structure, and comprises a perfect hash vector (PHVEC). (Claim 11) The method of claim 8 wherein the segment reference filter is a probabilistic data structure, and comprises one of a quotient filter, a Bloom filter, or a Cuckoo filter. 17. The method of claim 10 further comprising: storing a list of data or metadata segments encrypted with the compromised key as a bitmap tabulating the containers as a horizontal array; scanning all containers in a demarcated range to enumerate all leaf metadata segments of the files; looking up, in the probabilistic or deterministic segment reference filter, every enumerated child segment to determine a positive or negative lookup; and referring, for a positive lookup, the parent segment as an impacted segment by adding the parent segment to the respective probabilistic or deterministic segment reference filter. (Claim 8) storing the list of segments in a segment reference filter data structure as a bitmap tabulating the containers as a horizontal array; scanning all containers in a demarcated range to enumerate all leaf metadata segments of the files; looking up, in the segment reference filter, every enumerated child segment to determine a positive or negative lookup; and referring, for a positive lookup, the parent segment as an impacted segment by adding the parent segment to the segment reference filter. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention. Claims 1-2 and 18-20 are rejected under 35 U.S.C. 103 as being unpatentable over Pogde et al. (U.S. Patent No. 9432192; hereinafter “Pogde”), in view of in view of Kumar et al. (U.S. PGPub No. 2016/0154963; hereinafter “Kumar”), further in view of Samuels (U.S. PGPub No. 2010/0274772; hereinafter “Samuels”), further in view of Mondal (US Patent No. 9715505; hereinafter “Mondal”). As per claim 1: Pogde discloses a computer-implemented method of blocking access to files encrypted with a compromised encryption key, comprising: maintaining a map of encryption keys and ranges of containers encrypted by respective encryption keys (Index 204 includes information mapping a fingerprint to a storage location that stores a segment represented by the fingerprint… index 204 may be a fingerprint-to-container (FP/CID) index that maps a particular fingerprint to a container that contains the corresponding segment or a compression region (CR) having the segment stored therein [Column 6, lines 25-37; Examiner Note: the fingerprint represents the key as content hash keying is used to generate the keys]; each of the nodes in the hierarchical tree is encrypted by security manager 160 using an encryption key that is generated based on content of the corresponding node [Column 5, lines 28-32; Fig. 2, Fig. 3]; each of the nodes in the hierarchical tree is encrypted using an encryption key that is generated based on the content of the corresponding node [Column 3, lines 3-16]; content hash keying … the keys are computed dynamically from the content of the leaf nodes themselves using a secure hash algorithm [Column 8, lines 4-16]; determine storage locations of nodes 231 and 233 based on keys K10 and K12 (which are also the fingerprints of nodes D10 and D12)… decrypts nodes D10 and D12 using keys K10 and K12 [Column 9, lines 49-55]); [receiving an indication that] an encryption key is compromised [as a compromised key]; [identifying] a container range containing data encrypted [by the compromised key as impacted data], the container range having containers comprising data segments and metadata segments (A storage system hierarchy can be considered as a tree structure where data blocks get pointed to by the metadata blocks which themselves are pointed to by one or more parent levels of additional metadata block in a tree structure [Column 2, lines 53-56]; the hierarchical file system tree of a deduplicated storage system, leaf nodes represent content of deduplicated data chunks or segments [Column 2, lines 62-65]; each of the nodes in the hierarchical tree is encrypted using an encryption key [Column 3, lines 3-6]; a container may contain metadata or fingerprints of all segments therein, where segments are compressed into a compression region [Column 6, lines 38-51; Fig. 2, Fig. 3]; a file may be represented in a file tree having one or more levels of segments … only the lowest level segments are the actual data segments [Column 6, lines 4-15]; the encryption key of a particular node (e.g., child node) is stored together with content of its parent node [Column 5, lines 33-35]); [maintaining a probabilistic segment reference filter to enumerate segments from the impacted container range for the data segments]; and [building a deterministic segment reference filter to enumerate segments from the impacted container range for the metadata segments]. Pogde discloses the claimed subject matter as discussed above but does not explicitly disclose receiving an indication that an encryption key is compromised as a compromised key; by the compromised key. However, Kumar teaches receiving an indication that an encryption key is compromised as a compromised key (detecting 1402 compromise of a key encrypting key. Detecting 1402 compromise of the key encrypting key may be performed in any suitable manner, such as by receiving a report of or otherwise detecting unauthorized use of the key encrypting key [¶ 0077-0078]); by the compromised key as impacted data (compromise of a key encrypting key. Detecting 1402 compromise of the key encrypting key may be performed in any suitable manner, such as by receiving a report of or otherwise detecting unauthorized use of the key encryption key [¶ 0077]; one or more additional operations in order to prevent unauthorized use of the compromised key encryption key to access encrypted data [¶ 0078]; detecting 1402 compromise of a key encrypting key [¶ 0077]; one or more additional operations in order to prevent unauthorized use of the compromised key encryption key to access encrypted data [¶ 0078]; compromise of a key encrypting key. Detecting 1402 compromise of the key encrypting key may be performed in any suitable manner, such as by receiving a report of or otherwise detecting unauthorized use of the key encryption key [¶ 0077]). Pogde and Kumar are analogous art because they are from the same field of endeavor of secure data storage. Therefore, based on Pogde in view of Kumar, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Kumar to the system of Pogde in order to identify a key as compromised so the system can recover from the security breach, and thus protect against unauthorized access of stored data (to protect against unauthorized access to a content encryption key enabling unauthorized decryption of the data object, the data storage service may store content encryption keys in encrypted form [¶ 0023]; despite best efforts, data storage systems may experience security breaches … may through error or malicious intent compromise a key encryption key … allow a data storage system to recover from such security breaches [¶ 0077-0078]). Hence, it would have been obvious to combine the references above to obtain the invention as specified in the instant claim. Pogde in view of Kumar disclose the claimed subject matter as discussed above but do not explicitly disclose identifying a container range containing data encrypted by the compromised key as impacted data. However, Samuels teaches identifying a container range containing data encrypted (the lock manager 415 ensures synchronized access by multiple different user agents to data stored within the storage cloud… Locks restrict access to data objects and/or restrict operations that can be performed on data objects. The lock manager 415 may perform numerous different types of locks. Examples of locks that may be implemented include … exclusive locks (allows read and update access to the resource, and prevents others from having any access to it) [Samuels ¶ 0093-0094, Examiner Note: locking access]). Pogde in view of Kumar and Samuels are analogous art because they are from the same field of endeavor of secure data storage. Therefore, based on Pogde in view of Kumar further in view of Samuels, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Samuels to the system of Pogde in view of Kumar in order to restrict access to data objects and/or restrict operations that can be performed on data objects for improved security. Hence, it would have been obvious to combine the references above to obtain the invention as specified in the instant claim. Pogde in view of Kumar in view of Samuels discloses the claimed subject matter as discussed above but does not explicitly disclose maintaining a probabilistic segment reference filter to enumerate segments from the impacted container range for the data segments; building a deterministic segment reference filter to enumerate segments from the impacted container range for the metadata segments. However, Mondal teaches maintaining a probabilistic segment reference filter to enumerate segments from the impacted container range for the data segments (each of level by level scan takes a vector as input. This can be a bloom filter or a perfect hash. The vector indicates what the matching fingerprints the processing logic needs to look for while scanning for this level. For first scan of the top level, L6 level, processing logic computes this vector by traversing the namespace and adding all L6 fingerprints it finds while doing so. For other levels (e.g., L5-L1), this vector is produced by reading the LP segments selected for processing in the current level and adding the child fingerprints to the vector. This vector is referred to as a wanted vector. While scanning the processing logic actually computes what fingerprints it actually finds. This is stored in another vector referred to as a found vector. Usually any fingerprints added to a wanted vector will also be added to a found vector unless there are missing LP segments [Column 8, lines 11-26]); building a deterministic segment reference filter to enumerate segments from the impacted container range for the metadata segments (each of level by level scan takes a vector as input. This can be a bloom filter or a perfect hash. The vector indicates what the matching fingerprints the processing logic needs to look for while scanning for this level. For first scan of the top level, L6 level, processing logic computes this vector by traversing the namespace and adding all L6 fingerprints it finds while doing so. For other levels (e.g., L5-L1), this vector is produced by reading the LP segments selected for processing in the current level and adding the child fingerprints to the vector. This vector is referred to as a wanted vector. While scanning the processing logic actually computes what fingerprints it actually finds. This is stored in another vector referred to as a found vector. Usually any fingerprints added to a wanted vector will also be added to a found vector unless there are missing LP segments [Column 8, lines 11-26]). Pogde in view of Kumar further in view of Samuels and Mondal are analogous art because they are from the same field of endeavor of secure data storage. Therefore, based on Pogde in view of Kumar in view of Samuels further in view of Mondal, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Mondal to the system of Pogde in view of Kumar in view of Samuels in order to improve efficiency of segment identification. Hence, it would have been obvious to combine the references above to obtain the invention as specified in the instant claim. As per claim 2: Pogde in view of Kumar in view of Samuels further in view of Mondal teach all the limitations of claim 1. Furthermore, Mondal discloses wherein the deterministic data segment reference filter comprises a perfect hash vector (PHVEC) (A perfect hash function for a set S is a hash function that maps distinct elements in S to a set of integers, with no collisions. A perfect hash function has many of the same applications as other hash functions, but with the advantage that no collision resolution scheme has to be implemented [Column 10, lines 1-5]; Each upper level contains one or more references to one or more lower level segments. In one embodiment, an upper level segment contains a fingerprint (e.g., metadata) of fingerprints of its child level segments. Only the lowest level segments (e.g., L0 segments) are the actual data segments containing the actual deduplicated segments [Column 5, lines 18-25]), and the probabilistic segment reference filter comprises one of: a quotient filter, a Bloom filter, or a cuckoo filter (A bloom filter is a space-efficient probabilistic data structure that is used to test whether an element is a member of a set. False positive retrieval results are possible, but false negatives are not; i.e. a query returns either “inside set (may be wrong)” or “definitely not in set”. Elements can be added to the set, but not removed (though this can be addressed with a counting filter). The more elements that are added to the set, the larger the probability of false positives [Column 9, lines 60-67]; Each upper level contains one or more references to one or more lower level segments. In one embodiment, an upper level segment contains a fingerprint (e.g., metadata) of fingerprints of its child level segments. Only the lowest level segments (e.g., L0 segments) are the actual data segments containing the actual deduplicated segments [Column 5, lines 18-25]). As per claim 18: Pogde discloses a computer program product, comprising a non-transitory computer-readable medium having a computer-readable program code embodied therein, which, when executed by a processor, cause the processor to perform a method of blocking access to files encrypted with a compromised encryption key, comprising (Such a computer program is stored in a non-transitory computer readable medium. A machine-readable medium includes any mechanism for storing information in a form readable by a machine (e.g., a computer). For example, a machine-readable (e.g., computer-readable) medium includes a machine (e.g., a computer) readable storage medium ( e.g., read only memory ("ROM"), random access memory ("RAM"), magnetic disk storage media, optical storage media, flash memory 30 devices) [Column 15, lines 21-31]): The limitations of claim 18 are substantially similar to claim 1 above, and therefore the claim is likewise rejected. As per claim 19: Pogde in view of Kumar in view of Samuels further in view of Mondal teach all the limitations of claim 18. The limitations of claim 19 are substantially similar to claim 2 above, and therefore the claim is likewise rejected. As per claim 20: Pogde in view of Kumar in view of Samuels further in view of Mondal teach all the limitations of claim 19. Furthermore, Pogde and Mondal disclosewherein the directory tree comprises a LO level comprising fingerprints of the data segments and one or more Lp levels comprising fingerprints of the metadata segments, and further wherein the data segments of the LO level are used to populate the probabilistic segment reference filter, and the metadata segments of the one or more Lp levels are used to populate the deterministic segment reference filter (Each upper level contains one or more references to one or more lower level segments. In one embodiment, an upper level segment contains a fingerprint (e.g., metadata) of fingerprints of its child level segments. Only the lowest level segments are the actual data segments containing the actual deduplicated segments. Thus, L1 to L6 are segments only contain metadata of their respective child segments(s), referred to herein as LP segments [Pogde, Column 6, lines 9-17]; each of level by level scan takes a vector as input. This can be a bloom filter or a perfect hash. The vector indicates what the matching fingerprints the processing logic needs to look for while scanning for this level. For first scan of the top level, L6 level, processing logic computes this vector by traversing the namespace and adding all L6 fingerprints it finds while doing so. For other levels (e.g., L5-L1), this vector is produced by reading the LP segments selected for processing in the current level and adding the child fingerprints to the vector. This vector is referred to as a wanted vector. While scanning the processing logic actually computes what fingerprints it actually finds. This is stored in another vector referred to as a found vector. Usually any fingerprints added to a wanted vector will also be added to a found vector unless there are missing LP segments [Mondal, Column 8, lines 11-26]). Claims 3-6 are rejected under 35 U.S.C. 103 as being unpatentable over Pogde in view of Kumar in view of Samuels in view of Mondal further in view of Lum (U.S. Patent No. 10733306; hereinafter “Lum”). As per claim 3: Pogde in view of Kumar in view of Samuels further in view of Mondal teach all the limitations of claim 2. Furthermore, Pogde, Mondal, and Samuels disclose further comprising: making a point-in-time copy of a filesystem managing the containers, wherein each file of the filesystem is represented as a directory tree storing fingerprints of data using a hashing method and having a root level and one or more hierarchical lower levels (in a snapshot-based backup and migration system, content of a root node of a hierarchical tree representing a snapshot of content of a storage system at a point in time is different from one snapshot to another [Pogde, Column 3, lines 27-30; Fig. 3, Fig. 1]; segment the data into multiple chunks (also referred to as segments) [Pogde, Column 4, lines 11-14]; the hierarchical file system tree of a deduplicated storage system, leaf nodes represent content of deduplicated data… an intermediate node represents metadata … a root node [Pogde, Column 2, lines 53-67; Fig. 2, Fig. 3]; a root node of the hierarchical tree represents a content handle of a file, a directory of one or more files, and/or the entire file system [Pogde, Column 3, lines 1-3]; each of the nodes in the hierarchical tree is encrypted using an encryption key that is generated based on content of the corresponding node ( e.g., hashing of the content of the corresponding node) [Pogde, Column 3, lines 3-6]); iteratively inspecting, using one of the deterministic or probabilistic segment reference filter, each container in each level of the file trees from the lowest level to a highest level of the files to identify containers having segments encrypted by the compromised key for a corresponding level (each of level by level scan takes a vector as input. This can be a bloom filter or a perfect hash. The vector indicates what the matching fingerprints the processing logic needs to look for while scanning for this level. For first scan of the top level, L6 level, processing logic computes this vector by traversing the namespace and adding all L6 fingerprints it finds while doing so. For other levels (e.g., L5-L1), this vector is produced by reading the LP segments selected for processing in the current level and adding the child fingerprints to the vector. This vector is referred to as a wanted vector. While scanning the processing logic actually computes what fingerprints it actually finds. This is stored in another vector referred to as a found vector. Usually any fingerprints added to a wanted vector will also be added to a found vector unless there are missing LP segments [Mondal, Column 8, lines 11-26]; one or more additional operations in order to prevent unauthorized use of the compromised key encryption key to access encrypted data [Samuels ¶ 0078]; compromise of a key encrypting key. Detecting 1402 compromise of the key encrypting key may be performed in any suitable manner, such as by receiving a report of or otherwise detecting unauthorized use of the key encryption key [Samuels ¶ 0077]); and [marking files corresponding to the identified containers as not readable to block the access to the files encrypted with the compromised key]. Pogde in view of Kumar in view of Samuels in view of Mondal discloses the claimed subject matter as discussed above but does not explicitly disclose marking files corresponding to the identified containers as not readable to block the access to the files encrypted with the compromised key. However, Lum teaches marking files corresponding to the identified containers as not readable to block the access to the files encrypted with the compromised key (metadata used by the secure filesystem during operation on user machine to protect data stored in a file “File1.txt”… each block of data has an associated condition which must be valid in order to allow local reading of the data … the condition is set as a time window, i.e., whether the current date is before a predetermined date [Column 8, lines 28-34; Fig. 3, Fig. 4, see valid read flag marked as N for not valid]; each block additionally has an associated read flag indicating whether the condition is currently valid [Column 8, lines 58-60]; the file-system can determine when the corresponding active key has been deleted and responsively deny the request [Column 9, lines 1-7]; the novel filesystem of the present invention [Column 8, lines 2-10]). Pogde in view of Kumar in view of Samuels in view of Mondal and Lum are analogous art because they are from the same field of endeavor of secure data storage. Therefore, based on Pogde in view of Kumar in view of Samuels in view of Mondal in view of Lum, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Lum to the system of Pogde in view of Kumar in view of Samuels in view of Mondal in order to protect data stored in a file from inadvertent or nefarious disclosure by blocking read access of the file (sensitive and private information being recorded by devices and software in files of computing devices. It is highly desirable to protect such data from inadvertent or nefarious disclosure [Column 1, lines 33-36]; protect data stored in a file “File1.txt” [Column 8, line 28-34; Fig. 3]; each block additionally has an associated read flag indicating whether the condition is currently valid [Column 8, lines 58-60]; the file-system can determine when the corresponding active key has been deleted and responsively deny the request [Column 9, lines 1-7]). Hence, it would have been obvious to combine the references above to obtain the invention as specified in the instant claim. As per claim 4: Pogde in view of Kumar in view of Samuels in view of Mondal in view of Lum teach all the limitations of claim 3. Furthermore, Pogde discloses wherein the directory tree comprises a LO level comprising fingerprints of the data segments and one or more Lp levels comprising fingerprints of the metadata segments (Each upper level contains one or more references to one or more lower level segments. In one embodiment, an upper level segment contains a fingerprint (e.g., metadata) of fingerprints of its child level segments. Only the lowest level segments are the actual data segments containing the actual deduplicated segments. Thus, L1 to L6 are segments only contain metadata of their respective child segments(s), referred to herein as LP segments [Pogde, Column 6, lines 9-17]). As per claim 5: Pogde in view of Kumar in view of Samuels in view of Mondal in view of Lum teach all the limitations of claim 4. Furthermore, Mondal discloses wherein the data segments of the LO level are used to populate the probabilistic segment reference filter, and the metadata segments of the one or more Lp levels are used to populate the deterministic segment reference filter (each of level by level scan takes a vector as input. This can be a bloom filter or a perfect hash. The vector indicates what the matching fingerprints the processing logic needs to look for while scanning for this level. For first scan of the top level, L6 level, processing logic computes this vector by traversing the namespace and adding all L6 fingerprints it finds while doing so. For other levels (e.g., L5-L1), this vector is produced by reading the LP segments selected for processing in the current level and adding the child fingerprints to the vector. This vector is referred to as a wanted vector. While scanning the processing logic actually computes what fingerprints it actually finds. This is stored in another vector referred to as a found vector. Usually any fingerprints added to a wanted vector will also be added to a found vector unless there are missing LP segments [Mondal, Column 8, lines 11-26]). As per claim 6: Pogde in view of Kumar in view of Samuels in view of Mondal in view of Lum teach all the limitations of claim 5. Furthermore, Pogde discloses wherein the data and metadata segments are processed as part of a deduplication backup process executed by a data storage server that looks up the fingerprints in a hash table constituting an index to determine if the fingerprints exist or do not exist within the hash table, and if not, compressing and encrypting corresponding data segments into compression regions for storing in the containers (the encrypted content of the nodes are then stored in one or more storage units of the storage system in a deduplicated manner [Pogde, abstract]; the hierarchical file system tree of a deduplicated storage system, leaf nodes represent content of deduplicated data chunks or segments stored in the deduplicated storage system [Pogde, Column 2, lines 61-65; Fig. 1, Fig. 2]; a deduplicated segment is transmitted to storage system 104 only it has not been stored in storage system 104 [Pogde, Column 4, lines 38-55]; a container may contain metadata or fingerprints of all segments therein, where segments are compressed into a compression region [Pogde, Column 6, lines 38-50; Fig. 2]; each of the nodes in the hierarchical tree is encrypted by security manager 160 using an encryption key that is generated based on content of the corresponding node [Pogde, Column 5, lines 28-32; Fig. 2, Fig. 3]; a list of fingerprints is used to indicate chunk(s) associated with a file. File system control 1008 passes chunk association information (representative data such as fingerprint) to index. Index 1024 is used to locate stored chunks in storage units 1010 via storage unit interface 1012… identifies whether a newly received chunk has already been stored in storage units [Pogde, Column 13, lines 53-67]). Claims 10-14 are rejected under 35 U.S.C. 103 as being unpatentable over Pogde in view of Kumar in view of Mondal in view of Lum. As per claim 10: Pogde discloses a computer-implemented method of blocking access to files encrypted with a compromised encryption key, comprising: defining tree structures for each file of the set of files processed by a deduplication backup system, and storing compression region fingerprints in a plurality of levels with a root level, and encrypted with a key (each CH represents a file that is abstracted as a file tree (e.g., a Merkle tree or Mtree) of segments. A file tree is also referred to a fingerprint tree since it contains mostly fingerprints of the associated deduplicated segments [Pogde, Colum 6, lines 59-65; Fig. 2, Fig. 3]; manage files stored in a file system of the storage system in a hierarchical manner [Column 6, lines 2-4]; manage the files in the system [Column 6, lines 52-54]; a tree structure where data blocks which themselves are pointed to by the metadata blocks which themselves are pointed to by one or more parent levels of additional metadata block in a tree structure [Pogde, Column 4, lines 56-61]; the hierarchical file system tree of a deduplicated storage system, leaf nodes represent content of deduplicated data chunks or segments [Column 2, lines 62-65]; hashing of the content of the corresponding node [Pogde, Column 5, lines 28-32]; a container may contain metadata or fingerprints of all segments therein, where segments are compressed into a compression region [Column 6, lines 38-51; Fig. 2, Fig. 3]; the hierarchical file system tree of a deduplicated storage system, leaf nodes represent content of deduplicated data… an intermediate node represents metadata … a root node [Column 2, lines 53-67; Fig. 2, Fig. 3]; each of the nodes in the hierarchical tree is encrypted by security manager 160 using an encryption key that is generated based on content of the corresponding node [Column 5, lines 28-32; Fig. 2, Fig. 3]); reading a container header of containers [impacted by a compromised key] to identify a list of segments referred to by the impacted containers (Index 204 includes information mapping a fingerprint to a storage location that stores a segment represented by the fingerprint… index 204 may be a fingerprint-to-container (FP/CID) index that maps a particular fingerprint to a container that contains the corresponding segment or a compression region (CR) having the segment stored therein [Column 6, lines 25-37; Examiner Note: the fingerprint represents the key as content hash keying is used to generate the keys]; each of the nodes in the hierarchical tree is encrypted by security manager 160 using an encryption key that is generated based on content of the corresponding node [Column 5, lines 28-32; Fig. 2, Fig. 3]; each of the nodes in the hierarchical tree is encrypted using an encryption key that is generated based on the content of the corresponding node [Column 3, lines 3-16]; content hash keying … the keys are computed dynamically from the content of the leaf nodes themselves using a secure hash algorithm [Column 8, lines 4-16]; determine storage locations of nodes 231 and 233 based on keys K10 and K12 (which are also the fingerprints of nodes D10 and D12)… decrypts nodes D10 and D12 using keys K10 and K12 [Column 9, lines 49-55]; the metadata (e.g., fingerprints) and the data section of the current level segments can be obtained from the identified container [Column 6, lines 38-40; Fig. 2, Fig. 3]); first scanning, using [a probabilistic segment reference filter], data containers in a data level of the directory tree to find containers with data segments encrypted with [a compromised key] (the encryption process of a hierarchical tree is performed via a bottom-up approach, starting with leaf nodes and ending with a root node of the hierarchical tree [Column 3, lines 13-16, Fig. 2, Fig. 4]; the above example process is iteratively performed in a bottom-up manner, from leaf nodes 251-255, until it reaches root nodes 221-223 [Column 9, lines 22-39]; a storage system hierarchy can be considered as a tree structure where data blocks get pointed to by the metadata blocks which themselves are pointed to by one or more parent levels of additional metadata block [Column 5, lines 10-15]; a container may contain metadata or fingerprints of all segments therein, where segments are compressed into a compression region [Column 6, lines 38-51; Fig. 2, Fig. 3]; based on the fingerprints of the current level segments, container manager 203, which may be part of a content store manager, can identify which of the containers in which the segments are stored based on indexing information [Column 6, lines 22-35]; each CH represents a file that is abstracted as a file tree (e.g., a Merkle tree or Mtree) of segments [Column 6, lines 59-66]); second scanning, using [a deterministic segment reference filter], metadata containers in metadata levels of the directory tree to find containers with metadata segments encrypted with [a compromised key] by going up from a lowest to the root level using parent-child references of the directory tree (the encryption process of a hierarchical tree is performed via a bottom-up approach, starting with leaf nodes and ending with a root node of the hierarchical tree [Column 3, lines 13-16, Fig. 2, Fig. 4]; the above example process is iteratively performed in a bottom-up manner, from leaf nodes 251-255, until it reaches root nodes 221-223 [Column 9, lines 22-39]; a storage system hierarchy can be considered as a tree structure where data blocks get pointed to by the metadata blocks which themselves are pointed to by one or more parent levels of additional metadata block [Column 5, lines 10-15]; a container may contain metadata or fingerprints of all segments therein, where segments are compressed into a compression region [Column 6, lines 38-51; Fig. 2, Fig. 3]; based on the fingerprints of the current level segments, container manager 203, which may be part of a content store manager, can identify which of the containers in which the segments are stored based on indexing information [Column 6, lines 22-35]; each CH represents a file that is abstracted as a file tree (e.g., a Merkle tree or Mtree) of segments [Column 6, lines 59-66]); and [marking files] having data or metadata segments encrypted with [the compromised key] [as not readable to block accesses to the files] (deduplication engine is configured to segment the data into multiple chunks (also referred to as segments) [Column 4, lines 12-14; Fig. 2, Fig. 3]; in the hierarchical file system tree of a deduplicated storage system, leaf nodes represent content of deduplicate data chunks or segments stored [Column 5, lines 19-27]; each of the nodes in the hierarchical tree is encrypted by security manager 160 using an encryption key that is generated based on content of the corresponding node [Column 5, lines 28-32]). Pogde discloses the claimed subject matter as discussed above but does not explicitly disclose impacted by a compromised key; a compromised key; a compromised key; the compromised key. However, Kumar teaches impacted by a compromised key (one or more additional operations in order to prevent unauthorized use of the compromised key encryption key to access encrypted data [¶ 0078]; detecting 1402 compromise of a key encrypting key [¶ 0077]; one or more additional operations in order to prevent unauthorized use of the compromised key encryption key to access encrypted data [¶ 0078]; compromise of a key encrypting key. Detecting 1402 compromise of the key encrypting key may be performed in any suitable manner, such as by receiving a report of or otherwise detecting unauthorized use of the key encryption key [¶ 0077]); a compromised key (one or more additional operations in order to prevent unauthorized use of the compromised key encryption key to access encrypted data [¶ 0078]; detecting 1402 compromise of a key encrypting key [¶ 0077]; one or more additional operations in order to prevent unauthorized use of the compromised key encryption key to access encrypted data [¶ 0078]; compromise of a key encrypting key. Detecting 1402 compromise of the key encrypting key may be performed in any suitable manner, such as by receiving a report of or otherwise detecting unauthorized use of the key encryption key [¶ 0077]); a compromised key (one or more additional operations in order to prevent unauthorized use of the compromised key encryption key to access encrypted data [¶ 0078]; detecting 1402 compromise of a key encrypting key [¶ 0077]; one or more additional operations in order to prevent unauthorized use of the compromised key encryption key to access encrypted data [¶ 0078]; compromise of a key encrypting key. Detecting 1402 compromise of the key encrypting key may be performed in any suitable manner, such as by receiving a report of or otherwise detecting unauthorized use of the key encryption key [¶ 0077]); the compromised key (one or more additional operations in order to prevent unauthorized use of the compromised key encryption key to access encrypted data [¶ 0078]; detecting 1402 compromise of a key encrypting key [¶ 0077]; one or more additional operations in order to prevent unauthorized use of the compromised key encryption key to access encrypted data [¶ 0078]; compromise of a key encrypting key. Detecting 1402 compromise of the key encrypting key may be performed in any suitable manner, such as by receiving a report of or otherwise detecting unauthorized use of the key encryption key [¶ 0077]). Pogde and Kumar are analogous art because they are from the same field of endeavor of secure data storage. Therefore, based on Pogde in view of Kumar, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Kumar to the system of Pogde in order to identify a key as compromised so the system can recover from the security breach, and thus protect against unauthorized access of stored data (to protect against unauthorized access to a content encryption key enabling unauthorized decryption of the data object, the data storage service may store content encryption keys in encrypted form [¶ 0023]; despite best efforts, data storage systems may experience security breaches … may through error or malicious intent compromise a key encryption key … allow a data storage system to recover from such security breaches [¶ 0077-0078]). Hence, it would have been obvious to combine the references above to obtain the invention as specified in the instant claim. Pogde in view of Kumar discloses the claimed subject matter as discussed above but does not explicitly disclose a probabilistic segment reference filter; a deterministic segment reference filter. However, Mondal teaches a probabilistic segment reference filter (each of level by level scan takes a vector as input. This can be a bloom filter or a perfect hash. The vector indicates what the matching fingerprints the processing logic needs to look for while scanning for this level. For first scan of the top level, L6 level, processing logic computes this vector by traversing the namespace and adding all L6 fingerprints it finds while doing so. For other levels (e.g., L5-L1), this vector is produced by reading the LP segments selected for processing in the current level and adding the child fingerprints to the vector. This vector is referred to as a wanted vector. While scanning the processing logic actually computes what fingerprints it actually finds. This is stored in another vector referred to as a found vector. Usually any fingerprints added to a wanted vector will also be added to a found vector unless there are missing LP segments [Column 8, lines 11-26])); a deterministic segment reference filter (each of level by level scan takes a vector as input. This can be a bloom filter or a perfect hash. The vector indicates what the matching fingerprints the processing logic needs to look for while scanning for this level. For first scan of the top level, L6 level, processing logic computes this vector by traversing the namespace and adding all L6 fingerprints it finds while doing so. For other levels (e.g., L5-L1), this vector is produced by reading the LP segments selected for processing in the current level and adding the child fingerprints to the vector. This vector is referred to as a wanted vector. While scanning the processing logic actually computes what fingerprints it actually finds. This is stored in another vector referred to as a found vector. Usually any fingerprints added to a wanted vector will also be added to a found vector unless there are missing LP segments [Column 8, lines 11-26])). Pogde in view of Kumar and Mondal are analogous art because they are from the same field of endeavor of secure data storage. Therefore, based on Pogde in view of Kumar in view of Mondal, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Mondal to the system of Pogde in view of Kumar in order to improve efficiency of segment identification. Hence, it would have been obvious to combine the references above to obtain the invention as specified in the instant claim. Pogde in view of Kumar in view of Mondal discloses the claimed subject matter as discussed above but does not explicitly disclose marking files having data or metadata segments as not readable to block accesses to the files. However, Lum teaches marking files having data or metadata segments as not readable to block accesses to the files (metadata used by the secure filesystem during operation on user machine to protect data stored in a file “File1.txt”… each block of data has an associated condition which must be valid in order to allow local reading of the data … the condition is set as a time window, i.e., whether the current date is before a predetermined date [Column 8, lines 28-34; Fig. 3, Fig. 4, see valid read flag marked as N for not valid]; each block additionally has an associated read flag indicating whether the condition is currently valid [Column 8, lines 58-60]; the file-system can determine when the corresponding active key has been deleted and responsively deny the request [Column 9, lines 1-7]; the novel filesystem of the present invention [Column 8, lines 2-10]). Pogde in view of Kumar in view of Mondal and Lum are analogous art because they are from the same field of endeavor of secure data storage. Therefore, based on Pogde in view of Kumar in view of Mondal in view of Lum, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Lum to the system of Pogde in view of Kumar in view of Mondal in order to protect data stored in a file from inadvertent or nefarious disclosure by blocking read access of the file (sensitive and private information being recorded by devices and software in files of computing devices. It is highly desirable to protect such data from inadvertent or nefarious disclosure [Column 1, lines 33-36]; protect data stored in a file “File1.txt” [Column 8, line 28-34; Fig. 3]; each block additionally has an associated read flag indicating whether the condition is currently valid [Column 8, lines 58-60]; the file-system can determine when the corresponding active key has been deleted and responsively deny the request [Column 9, lines 1-7]). Hence, it would have been obvious to combine the references above to obtain the invention as specified in the instant claim. As per claim 11: Pogde in view of Kumar in view of Mondal in view of Lum teach all the limitations of claim 10 above. Furthermore, Mondal discloses wherein the probabilistic data segment reference filter comprises one of: a quotient filter, a Bloom filter, or a cuckoo filter (A bloom filter is a space-efficient probabilistic data structure that is used to test whether an element is a member of a set. False positive retrieval results are possible, but false negatives are not; i.e. a query returns either “inside set (may be wrong)” or “definitely not in set”. Elements can be added to the set, but not removed (though this can be addressed with a counting filter). The more elements that are added to the set, the larger the probability of false positives [Column 9, lines 60-67]; Each upper level contains one or more references to one or more lower level segments. In one embodiment, an upper level segment contains a fingerprint (e.g., metadata) of fingerprints of its child level segments. Only the lowest level segments (e.g., L0 segments) are the actual data segments containing the actual deduplicated segments [Column 5, lines 18-25]), and further wherein the deterministic segment reference filter comprises a perfect hash vector (PHVEC) (A perfect hash function for a set S is a hash function that maps distinct elements in S to a set of integers, with no collisions. A perfect hash function has many of the same applications as other hash functions, but with the advantage that no collision resolution scheme has to be implemented [Column 10, lines 1-5]; Each upper level contains one or more references to one or more lower level segments. In one embodiment, an upper level segment contains a fingerprint (e.g., metadata) of fingerprints of its child level segments. Only the lowest level segments (e.g., L0 segments) are the actual data segments containing the actual deduplicated segments [Column 5, lines 18-25]). As per claim 12: Pogde in view of Kumar in view of Mondal in view of Lum teach all the limitations of claim 11 above. Furthermore, Pogde discloses wherein the directory tree comprises a LO level comprising fingerprints of the data segments and one or more Lp levels comprising fingerprints of the metadata segments (Each upper level contains one or more references to one or more lower level segments. In one embodiment, an upper level segment contains a fingerprint (e.g., metadata) of fingerprints of its child level segments. Only the lowest level segments are the actual data segments containing the actual deduplicated segments. Thus, L1 to L6 are segments only contain metadata of their respective child segments(s), referred to herein as LP segments [Pogde, Column 6, lines 9-17]). As per claim 13: Pogde in view of Kumar in view of Mondal in view of Lum teach all the limitations of claim 12 above. Furthermore, Mondal discloses wherein the data segments of the LO level are used to populate the probabilistic segment reference filter, and the metadata segments of the one or more Lp levels are used to populate the deterministic segment reference filter (each of level by level scan takes a vector as input. This can be a bloom filter or a perfect hash. The vector indicates what the matching fingerprints the processing logic needs to look for while scanning for this level. For first scan of the top level, L6 level, processing logic computes this vector by traversing the namespace and adding all L6 fingerprints it finds while doing so. For other levels (e.g., L5-L1), this vector is produced by reading the LP segments selected for processing in the current level and adding the child fingerprints to the vector. This vector is referred to as a wanted vector. While scanning the processing logic actually computes what fingerprints it actually finds. This is stored in another vector referred to as a found vector. Usually any fingerprints added to a wanted vector will also be added to a found vector unless there are missing LP segments [Mondal, Column 8, lines 11-26]). As per claim 14: Pogde in view of Kumar in view of Mondal in view of Lum teach all the limitations of claim 13 above. Furthermore, Pogde discloses wherein the deduplication backup system looks up the fingerprints in a hash table constituting an index to determine if the fingerprints exist or do not exist within the hash table, and if not, compressing and encrypting corresponding data segments into compression regions for storing in the containers (the encrypted content of the nodes are then stored in one or more storage units of the storage system in a deduplicated manner [Pogde, abstract]; the hierarchical file system tree of a deduplicated storage system, leaf nodes represent content of deduplicated data chunks or segments stored in the deduplicated storage system [Pogde, Column 2, lines 61-65; Fig. 1, Fig. 2]; a deduplicated segment is transmitted to storage system 104 only it has not been stored in storage system 104 [Pogde, Column 4, lines 38-55]; a container may contain metadata or fingerprints of all segments therein, where segments are compressed into a compression region [Pogde, Column 6, lines 38-50; Fig. 2]; each of the nodes in the hierarchical tree is encrypted by security manager 160 using an encryption key that is generated based on content of the corresponding node [Pogde, Column 5, lines 28-32; Fig. 2, Fig. 3]; a list of fingerprints is used to indicate chunk(s) associated with a file. File system control 1008 passes chunk association information (representative data such as fingerprint) to index. Index 1024 is used to locate stored chunks in storage units 1010 via storage unit interface 1012… identifies whether a newly received chunk has already been stored in storage units [Pogde, Column 13, lines 53-67]). Allowable Subject Matter Claims 7-9 and 15-16 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. Claim 17 would be allowable if rewritten to overcome the double patenting rejection set forth in this office action and to include all of the limitations of the base claim and any intervening claims. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to JAMES P MOLES whose telephone number is (703)756-1043. The examiner can normally be reached M-F 8:00am-5:00pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jung Kim can be reached at (571) 272-3804. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /JAMES P MOLES/Examiner, Art Unit 2494 /JUNG W KIM/Supervisory Patent Examiner, Art Unit 2494
Read full office action

Prosecution Timeline

Mar 13, 2025
Application Filed
Aug 19, 2026
Non-Final Rejection mailed — §103, §DOUBLEPATENT (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12743521
Systems and Methods for Merging Performance and Security into a Unit Testing Environment
4y 4m to grant Granted Sep 22, 2026
Patent 12732388
NON-FUNGIBLE TOKEN (NFT) BASED INTELLIGENT DOCUMENT PROTOCOLS
3y 4m to grant Granted Sep 08, 2026
Patent 12724884
Adaptive Incident Prioritization Based on User Feedback
2y 3m to grant Granted Sep 01, 2026
Patent 12705362
METHOD, APPARATUS, SYSTEM AND COMPUTER PROGRAM FOR IDENTIFYING AND RESPONDING TO QUANTUM VULNERABILITY USING DYNAMIC ANALYSIS FOR APPLICATION
2y 2m to grant Granted Aug 11, 2026
Patent 12671592
METHOD AND APPARATUS FOR ESTABLISHING END-TO-END SECURITY IN WIRELESS COMMUNICATION SYSTEM
3y 6m to grant Granted Jun 30, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
67%
Grant Probability
95%
With Interview (+28.6%)
2y 9m (~1y 3m remaining)
Median Time to Grant
Low
PTA Risk
Based on 48 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month