DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This office action is in response to the applicant’s filing on 03/13/2025. Claims 1-20 are pending. Claims 1, 8, and 15 are independent.
Priority
Acknowledgement is made of applicant’s claiming of priority, as a continuation-in-part, to application 17/682,174 filed on 02/28/2022.
Claim Interpretation
The following is a quotation of 35 U.S.C. 112(f):
(f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof.
The following is a quotation of pre-AIA 35 U.S.C. 112, sixth paragraph:
An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof.
The claims in this application are given their broadest reasonable interpretation using the plain meaning of the claim language in light of the specification as it would be understood by one of ordinary skill in the art. The broadest reasonable interpretation of a claim element (also commonly referred to as a claim limitation) is limited by the description in the specification when 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is invoked.
As explained in MPEP § 2181, subsection I, claim limitations that meet the following three-prong test will be interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph:
(A) the claim limitation uses the term “means” or “step” or a term used as a substitute for “means” that is a generic placeholder (also called a nonce term or a non-structural term having no specific structural meaning) for performing the claimed function;
(B) the term “means” or “step” or the generic placeholder is modified by functional language, typically, but not always linked by the transition word “for” (e.g., “means for”) or another linking word or phrase, such as “configured to” or “so that”; and
(C) the term “means” or “step” or the generic placeholder is not modified by sufficient structure, material, or acts for performing the claimed function.
Use of the word “means” (or “step”) in a claim with functional language creates a rebuttable presumption that the claim limitation is to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites sufficient structure, material, or acts to entirely perform the recited function.
Absence of the word “means” (or “step”) in a claim creates a rebuttable presumption that the claim limitation is not to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is not interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites function without reciting sufficient structure, material or acts to entirely perform the recited function.
Claim limitations in this application that use the word “means” (or “step”) are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. Conversely, claim limitations in this application that do not use the word “means” (or “step”) are not being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action.
This application includes one or more claim limitations that do not use the word “means,” but are nonetheless being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, because the claim limitation(s) uses a generic placeholder that is coupled with functional language without reciting sufficient structure to perform the recited function and the generic placeholder is not preceded by a structural modifier. Such claim limitations are: “a component marking files …”in claim 8 and “a component fencing a container range …” in claim 15.
Because this/these claim limitation(s) is/are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, they are being interpreted to cover the corresponding structure described in the specification as performing the claimed function, and equivalents thereof. The component marking files is described as blocking access to files encrypted with a compromised key (¶ 0043, ¶ 0056, ¶ 0088, ¶ 0006, ¶ 0029, ¶ 0051-0052). The component fencing a container range is described as identifying content impacted by compromised encryption keys to prevent it from being deduplicated to by newer files in the deduplication storage system (¶ 0088, ¶ 0027, ¶ 0051-0052).
If applicant does not intend to have this/these limitation(s) interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, applicant may: (1) amend the claim limitation(s) to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph (e.g., by reciting sufficient structure to perform the claimed function); or (2) present a sufficient showing that the claim limitation(s) recite(s) sufficient structure to perform the claimed function so as to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention.
Claims 1-6 and 8-12 are rejected under 35 U.S.C. 103 as being unpatentable over Pogde et al. (U.S. Patent No. 9432192; hereinafter “Pogde”), in view of Kumar et al. (U.S. PGPub No. 2016/0154963; hereinafter “Kumar”), in view of Mondal (US Patent No. 9715505; hereinafter “Mondal”), in view of Lum (U.S. Patent No. 10733306; hereinafter “Lum”).
As per claim 1: Pogde discloses a system preventing access to files encrypted with a compromised encryption key, comprising:
a memory storage maintaining a map of encryption keys and ranges of containers of files encrypted by respective encryption keys (Index 204 includes information mapping a fingerprint to a storage location that stores a segment represented by the fingerprint… index 204 may be a fingerprint-to-container (FP/CID) index that maps a particular fingerprint to a container that contains the corresponding segment or a compression region (CR) having the segment stored therein [Column 6, lines 25-37; Examiner Note: the fingerprint represents the key as content hash keying is used to generate the keys]; each of the nodes in the hierarchical tree is encrypted by security manager 160 using an encryption key that is generated based on content of the corresponding node [Column 5, lines 28-32; Fig. 2, Fig. 3]; each of the nodes in the hierarchical tree is encrypted using an encryption key that is generated based on the content of the corresponding node [Column 3, lines 3-16]; content hash keying … the keys are computed dynamically from the content of the leaf nodes themselves using a secure hash algorithm [Column 8, lines 4-16]; determine storage locations of nodes 231 and 233 based on keys K10 and K12 (which are also the fingerprints of nodes D10 and D12)… decrypts nodes D10 and D12 using keys K10 and K12 [Column 9, lines 49-55]); and
[hybrid segment reference filter using a probabilistic data structure] for data fingerprints and [a deterministic data structure] for metadata fingerprints, wherein a first level of lookup uses [the probabilistic data structure] to identify parent files referring to data fingerprints from an impacted file encrypted by [a compromised encryption key], and further wherein parent fingerprints referring to child data segments (A storage system hierarchy can be considered as a tree structure where data blocks get pointed to by the metadata blocks which themselves are pointed to by one or more parent levels of additional metadata block in a tree structure [Column 2, lines 53-56]; the hierarchical file system tree of a deduplicated storage system, leaf nodes represent content of deduplicated data chunks or segments [Column 2, lines 62-65]; each of the nodes in the hierarchical tree is encrypted using an encryption key [Column 3, lines 3-6]; a container may contain metadata or fingerprints of all segments therein, where segments are compressed into a compression region [Column 6, lines 38-51; Fig. 2, Fig. 3]; a file may be represented in a file tree having one or more levels of segments … only the lowest level segments are the actual data segments [Column 6, lines 4-15]; the encryption key of a particular node (e.g., child node) is stored together with content of its parent node [Column 5, lines 33-35]; Each upper level contains one or more references to one or more lower level segments. In one embodiment, an upper level segment contains a fingerprint (e.g., metadata) of fingerprints of its child level segments. Only the lowest level segments are the actual data segments containing the actual deduplicated segments. Thus, L1 to L6 are segments only contain metadata of their respective child segments(s), referred to herein as LP segments [Pogde, Column 6, lines 9-17]) in the impacted file are marked in [the deterministic data structure] to [block read access to the impacted file].
Pogde discloses the claimed subject matter as discussed above but does not explicitly disclose a compromised encryption key. However, Kumar teaches a compromised encryption key (one or more additional operations in order to prevent unauthorized use of the compromised key encryption key to access encrypted data [¶ 0078]; compromise of a key encrypting key. Detecting 1402 compromise of the key encrypting key may be performed in any suitable manner, such as by receiving a report of or otherwise detecting unauthorized use of the key encryption key [¶ 0077]). Pogde and Kumar are analogous art because they are from the same field of endeavor of secure data storage. Therefore, based on Pogde in view of Kumar, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Kumar to the system of Pogde in order to identify a key as compromised so the system can recover from the security breach, and thus protect against unauthorized access of stored data (to protect against unauthorized access to a content encryption key enabling unauthorized decryption of the data object, the data storage service may store content encryption keys in encrypted form [¶ 0023]; despite best efforts, data storage systems may experience security breaches … may through error or malicious intent compromise a key encryption key … allow a data storage system to recover from such security breaches [¶ 0077-0078]). Hence, it would have been obvious to combine the references above to obtain the invention as specified in the instant claim.
Pogde in view of Kumar discloses the claimed subject matter as discussed above but does not explicitly disclose hybrid segment reference filter using a probabilistic data structure and a deterministic data structure; the probabilistic data structure; the deterministic data structure. However, Mondal teaches hybrid segment reference filter using a probabilistic data structure and a deterministic data structure (each of level by level scan takes a vector as input. This can be a bloom filter or a perfect hash. The vector indicates what the matching fingerprints the processing logic needs to look for while scanning for this level. For first scan of the top level, L6 level, processing logic computes this vector by traversing the namespace and adding all L6 fingerprints it finds while doing so. For other levels (e.g., L5-L1), this vector is produced by reading the LP segments selected for processing in the current level and adding the child fingerprints to the vector. This vector is referred to as a wanted vector. While scanning the processing logic actually computes what fingerprints it actually finds. This is stored in another vector referred to as a found vector. Usually any fingerprints added to a wanted vector will also be added to a found vector unless there are missing LP segments [Column 8, lines 11-26]); the probabilistic data structure (A bloom filter is a space-efficient probabilistic data structure that is used to test whether an element is a member of a set. False positive retrieval results are possible, but false negatives are not; i.e. a query returns either “inside set (may be wrong)” or “definitely not in set”. Elements can be added to the set, but not removed (though this can be addressed with a counting filter). The more elements that are added to the set, the larger the probability of false positives [Column 9, lines 60-67]; Each upper level contains one or more references to one or more lower level segments. In one embodiment, an upper level segment contains a fingerprint (e.g., metadata) of fingerprints of its child level segments. Only the lowest level segments (e.g., L0 segments) are the actual data segments containing the actual deduplicated segments [Column 5, lines 18-25]); the deterministic data structure (A perfect hash function for a set S is a hash function that maps distinct elements in S to a set of integers, with no collisions. A perfect hash function has many of the same applications as other hash functions, but with the advantage that no collision resolution scheme has to be implemented [Column 10, lines 1-5]; Each upper level contains one or more references to one or more lower level segments. In one embodiment, an upper level segment contains a fingerprint (e.g., metadata) of fingerprints of its child level segments. Only the lowest level segments (e.g., L0 segments) are the actual data segments containing the actual deduplicated segments [Column 5, lines 18-25]). Pogde in view of Kumar and Mondal are analogous art because they are from the same field of endeavor of secure data storage. Therefore, based on Pogde in view of Kumar in view of Mondal, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Mondal to the system of Pogde in view of Kumar in order to improve the efficiency of segment identification. Hence, it would have been obvious to combine the references above to obtain the invention as specified in the instant claim.
Pogde in view of Kumar in view of Mondal discloses the claimed subject matter as discussed above but does not explicitly disclose block read access to the impacted file. However, Lum teaches block read access to the impacted file (metadata used by the secure filesystem during operation on user machine to protect data stored in a file “File1.txt”… each block of data has an associated condition which must be valid in order to allow local reading of the data … the condition is set as a time window, i.e., whether the current date is before a predetermined date [Column 8, lines 28-34; Fig. 3, Fig. 4, see valid read flag marked as N for not valid]; each block additionally has an associated read flag indicating whether the condition is currently valid [Column 8, lines 58-60]; the file-system can determine when the corresponding active key has been deleted and responsively deny the request [Column 9, lines 1-7]; the novel filesystem of the present invention [Column 8, lines 2-10]). Pogde in view of Kumar in view of Mondal and Lum are analogous art because they are from the same field of endeavor of secure data storage. Therefore, based on Pogde in view of Kumar in view of Mondal in view of Lum, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Lum to the system of Pogde in view of Kumar in view of Mondal in order to protect data stored in a file from inadvertent or nefarious disclosure by blocking read access of the file (sensitive and private information being recorded by devices and software in files of computing devices. It is highly desirable to protect such data from inadvertent or nefarious disclosure [Column 1, lines 33-36]; protect data stored in a file “File1.txt” [Column 8, line 28-34; Fig. 3]; each block additionally has an associated read flag indicating whether the condition is currently valid [Column 8, lines 58-60]; the file-system can determine when the corresponding active key has been deleted and responsively deny the request [Column 9, lines 1-7]). Hence, it would have been obvious to combine the references above to obtain the invention as specified in the instant claim.
As per claim 2: Pogde in view of Kumar in view of Mondal in view of Lum teach all the limitations of claim 1. Furthermore, Mondal discloses wherein the deterministic data structure comprises a perfect hash vector (PHVEC), and the probabilistic data structure comprises one of: a quotient filter, a Bloom filter, or a cuckoo filter (each of level by level scan takes a vector as input. This can be a bloom filter or a perfect hash. The vector indicates what the matching fingerprints the processing logic needs to look for while scanning for this level. For first scan of the top level, L6 level, processing logic computes this vector by traversing the namespace and adding all L6 fingerprints it finds while doing so. For other levels (e.g., L5-L1), this vector is produced by reading the LP segments selected for processing in the current level and adding the child fingerprints to the vector. This vector is referred to as a wanted vector. While scanning the processing logic actually computes what fingerprints it actually finds. This is stored in another vector referred to as a found vector. Usually any fingerprints added to a wanted vector will also be added to a found vector unless there are missing LP segments [Column 8, lines 11-26]; A perfect hash function for a set S is a hash function that maps distinct elements in S to a set of integers, with no collisions. A perfect hash function has many of the same applications as other hash functions, but with the advantage that no collision resolution scheme has to be implemented [Column 10, lines 1-5]; Each upper level contains one or more references to one or more lower level segments. In one embodiment, an upper level segment contains a fingerprint (e.g., metadata) of fingerprints of its child level segments. Only the lowest level segments (e.g., L0 segments) are the actual data segments containing the actual deduplicated segments [Column 5, lines 18-25]; A bloom filter is a space-efficient probabilistic data structure that is used to test whether an element is a member of a set. False positive retrieval results are possible, but false negatives are not; i.e. a query returns either “inside set (may be wrong)” or “definitely not in set”. Elements can be added to the set, but not removed (though this can be addressed with a counting filter). The more elements that are added to the set, the larger the probability of false positives [Column 9, lines 60-67]; Each upper level contains one or more references to one or more lower level segments. In one embodiment, an upper level segment contains a fingerprint (e.g., metadata) of fingerprints of its child level segments. Only the lowest level segments (e.g., L0 segments) are the actual data segments containing the actual deduplicated segments [Column 5, lines 18-25]).
As per claim 3: Pogde in view of Kumar in view of Mondal in view of Lum teach all the limitations of claim 2. Furthermore, Pogde discloses further comprising a directory tree representing a filesystem managing the containers and storing fingerprints of data segments and metadata segments using a hashing method and having a root level and one or more hierarchical lower levels (A storage system hierarchy can be considered as a tree structure where data blocks get pointed to by the metadata blocks which themselves are pointed to by one or more parent levels of additional metadata block in a tree structure [Column 2, lines 53-56]; the hierarchical file system tree of a deduplicated storage system, leaf nodes represent content of deduplicated data chunks or segments [Column 2, lines 62-65]; each of the nodes in the hierarchical tree is encrypted using an encryption key [Column 3, lines 3-6]; a container may contain metadata or fingerprints of all segments therein, where segments are compressed into a compression region [Column 6, lines 38-51; Fig. 2, Fig. 3]; a file may be represented in a file tree having one or more levels of segments … only the lowest level segments are the actual data segments [Column 6, lines 4-15]; the encryption key of a particular node (e.g., child node) is stored together with content of its parent node [Column 5, lines 33-35]; Each upper level contains one or more references to one or more lower level segments. In one embodiment, an upper level segment contains a fingerprint (e.g., metadata) of fingerprints of its child level segments. Only the lowest level segments are the actual data segments containing the actual deduplicated segments. Thus, L1 to L6 are segments only contain metadata of their respective child segments(s), referred to herein as LP segments [Pogde, Column 6, lines 9-17]; each of the nodes in the hierarchical tree is encrypted using an encryption key that is generated based on content of the corresponding node (e.g., hashing of the content of the corresponding node) [Pogde, Column 3, lines 3-6]).
As per claim 4: Pogde in view of Kumar in view of Mondal in view of Lum teach all the limitations of claim 3. Furthermore, Pogde discloses wherein the directory tree comprises a LO level comprising fingerprints of the data segments and one or more Lp levels comprising fingerprints of the metadata segments (Each upper level contains one or more references to one or more lower level segments. In one embodiment, an upper level segment contains a fingerprint (e.g., metadata) of fingerprints of its child level segments. Only the lowest level segments are the actual data segments containing the actual deduplicated segments. Thus, L1 to L6 are segments only contain metadata of their respective child segments(s), referred to herein as LP segments [Pogde, Column 6, lines 9-17]).
As per claim 5: Pogde in view of Kumar in view of Mondal in view of Lum teach all the limitations of claim 4. Furthermore, Pogde and Mondal disclose wherein the data segments of the LO level are used to populate the PHVEC, and the metadata segments of the one or more Lp levels are used to populate the Bloom filter (A storage system hierarchy can be considered as a tree structure where data blocks get pointed to by the metadata blocks which themselves are pointed to by one or more parent levels of additional metadata block in a tree structure [Pogde, Column 2, lines 53-56]; the hierarchical file system tree of a deduplicated storage system, leaf nodes represent content of deduplicated data chunks or segments [Pogde, Column 2, lines 62-65]; each of the nodes in the hierarchical tree is encrypted using an encryption key [Pogde, Column 3, lines 3-6]; a container may contain metadata or fingerprints of all segments therein, where segments are compressed into a compression region [Pogde, Column 6, lines 38-51; Fig. 2, Fig. 3]; a file may be represented in a file tree having one or more levels of segments … only the lowest level segments are the actual data segments [Pogde, Column 6, lines 4-15]; the encryption key of a particular node (e.g., child node) is stored together with content of its parent node [Pogde, Column 5, lines 33-35]; Each upper level contains one or more references to one or more lower level segments. In one embodiment, an upper level segment contains a fingerprint (e.g., metadata) of fingerprints of its child level segments. Only the lowest level segments are the actual data segments containing the actual deduplicated segments. Thus, L1 to L6 are segments only contain metadata of their respective child segments(s), referred to herein as LP segments [Pogde, Column 6, lines 9-17]; each of level by level scan takes a vector as input. This can be a bloom filter or a perfect hash. The vector indicates what the matching fingerprints the processing logic needs to look for while scanning for this level. For first scan of the top level, L6 level, processing logic computes this vector by traversing the namespace and adding all L6 fingerprints it finds while doing so. For other levels (e.g., L5-L1), this vector is produced by reading the LP segments selected for processing in the current level and adding the child fingerprints to the vector. This vector is referred to as a wanted vector. While scanning the processing logic actually computes what fingerprints it actually finds. This is stored in another vector referred to as a found vector. Usually any fingerprints added to a wanted vector will also be added to a found vector unless there are missing LP segments [Column 8, lines 11-26]).
As per claim 6: Pogde in view of Kumar in view of Mondal in view of Lum teach all the limitations of claim 5. Furthermore, Pogde, Kumar, Mondal, and Lum disclose further comprising a data storage server executing a deduplication backup process making a point-in-time copy of a filesystem (in a snapshot-based backup and migration system, content of a root node of a hierarchical tree representing a snapshot of content of a storage system at a point in time is different from one snapshot to another [Pogde, Column 3, lines 27-30; Fig. 3, Fig. 1]; segment the data into multiple chunks (also referred to as segments) [Pogde, Column 4, lines 11-14]; the hierarchical file system tree of a deduplicated storage system, leaf nodes represent content of deduplicated data… an intermediate node represents metadata … a root node [Pogde, Column 2, lines 53-67; Fig. 2, Fig. 3]; a root node of the hierarchical tree represents a content handle of a file, a directory of one or more files, and/or the entire file system [Pogde, Column 3, lines 1-3]; each of the nodes in the hierarchical tree is encrypted using an encryption key that is generated based on content of the corresponding node ( e.g., hashing of the content of the corresponding node) [Pogde, Column 3, lines 3-6]), and configured to: iteratively inspect, using one of the PHVEC or Bloom filter, each container in each level of the file trees from the lowest level to a highest level of the files to identify containers having segments encrypted (each of level by level scan takes a vector as input. This can be a bloom filter or a perfect hash. The vector indicates what the matching fingerprints the processing logic needs to look for while scanning for this level. For first scan of the top level, L6 level, processing logic computes this vector by traversing the namespace and adding all L6 fingerprints it finds while doing so. For other levels (e.g., L5-L1), this vector is produced by reading the LP segments selected for processing in the current level and adding the child fingerprints to the vector. This vector is referred to as a wanted vector. While scanning the processing logic actually computes what fingerprints it actually finds. This is stored in another vector referred to as a found vector. Usually any fingerprints added to a wanted vector will also be added to a found vector unless there are missing LP segments [Mondal, Column 8, lines 11-26]) by the compromised key for a corresponding level (one or more additional operations in order to prevent unauthorized use of the compromised key encryption key to access encrypted data [Kumar ¶ 0078]; compromise of a key encrypting key. Detecting 1402 compromise of the key encrypting key may be performed in any suitable manner, such as by receiving a report of or otherwise detecting unauthorized use of the key encryption key [Kumar ¶ 0077]); and mark files corresponding to the identified containers as not readable (metadata used by the secure filesystem during operation on user machine to protect data stored in a file “File1.txt”… each block of data has an associated condition which must be valid in order to allow local reading of the data … the condition is set as a time window, i.e., whether the current date is before a predetermined date [Column 8, lines 28-34; Fig. 3, Fig. 4, see valid read flag marked as N for not valid]; each block additionally has an associated read flag indicating whether the condition is currently valid [Column 8, lines 58-60]; the file-system can determine when the corresponding active key has been deleted and responsively deny the request [Column 9, lines 1-7]; the novel filesystem of the present invention [Column 8, lines 2-10]).
As per claim 8: Pogde discloses a system for blocking access to files encrypted with a compromised encryption key, comprising:
a backup server executing a deduplication backup program (the encrypted content of the nodes are then stored in one or more storage units of the storage system in a deduplicated manner [Pogde, abstract]; the hierarchical file system tree of a deduplicated storage system, leaf nodes represent content of deduplicated data chunks or segments stored in the deduplicated storage system [Pogde, Column 2, lines 61-65; Fig. 1, Fig. 2]; Storage system 104 may include any type of server or cluster of servers. For example, storage system 104 may be a storage server used for any of various different purposes, such as to provide multiple users with access to shared data and/or to back up data (e.g., mission critical data). In one embodiment, storage system 104 includes, but is not limited to, backup engine 106, deduplication storage engine 107, and one or more storage units 108-109 communicatively coupled to each other [Pogde, Column 3, lines 57-66]);
a filesystem maintaining a directory tree of files (The encryption scheme allows for auto key rotation towards a root node of the file system hierarchy as the file system is modified, for example, by only modifying an encryption key of the root node [Pogde, Column 2, lines 41-45]; A root node of the hierarchical tree represents a content handle of a file , a directory of one or more files, and/or the entire file system [Pogde, Column 5, lines 3-6]) processed by the backup server, and storing compression region fingerprints in a plurality of levels with a root level, and encrypted with a key (a deduplicated segment is transmitted to storage system 104 only it has not been stored in storage system 104 [Pogde, Column 4, lines 38-55]; a container may contain metadata or fingerprints of all segments therein, where segments are compressed into a compression region [Pogde, Column 6, lines 38-50; Fig. 2]; each of the nodes in the hierarchical tree is encrypted by security manager 160 using an encryption key that is generated based on content of the corresponding node [Pogde, Column 5, lines 28-32; Fig. 2, Fig. 3]; a list of fingerprints is used to indicate chunk(s) associated with a file. File system control 1008 passes chunk association information (representative data such as fingerprint) to index. Index 1024 is used to locate stored chunks in storage units 1010 via storage unit interface 1012… identifies whether a newly received chunk has already been stored in storage units [Pogde, Column 13, lines 53-67]; Thus, each of the nodes in a hierarchical tree is encrypted using a different key. The encryption key of a particular node ( e.g., child node) is stored together with content of its parent node. The encryption key of the child node and content of the parent node are then encrypted by a parent key, where the parent key is generated based on content of the parent node (e.g., hashing of the content of the parent node), and so on. In this embodiment, the encryption process of a hierarchical tree is performed via a bottom-up approach, starting with leaf nodes and ending with a root node of the hierarchical tree [Pogde, Column 3, lines 6-16]);
data containers storing data and metadata for the set of files, including at least one container impacted by [the compromised encryption key] (a container may contain metadata or fingerprints of all segments therein, where segments are compressed into a compression region [Pogde, Column 6, lines 38-50; Fig. 2]);
[a probabilistic segment reference filter scanning data containers in a data level of the directory tree to find containers with data segments encrypted] with [a compromised key];
[a deterministic segment reference filter built to scan metadata containers in metadata levels of the directory tree to find containers with metadata segments encrypted] with [the compromised key] by going up from a lowest to the root level using parent-child references of the directory tree (the encryption process of a hierarchical tree is performed via a bottom-up approach, starting with leaf nodes and ending with a root node of the hierarchical tree [Column 3, lines 13-16, Fig. 2, Fig. 4]; the above example process is iteratively performed in a bottom-up manner, from leaf nodes 251-255, until it reaches root nodes 221-223 [Column 9, lines 22-39]; a storage system hierarchy can be considered as a tree structure where data blocks get pointed to by the metadata blocks which themselves are pointed to by one or more parent levels of additional metadata block [Column 5, lines 10-15]; a container may contain metadata or fingerprints of all segments therein, where segments are compressed into a compression region [Column 6, lines 38-51; Fig. 2, Fig. 3]); and
[a component marking files] having data or metadata segments encrypted with (deduplication engine is configured to segment the data into multiple chunks (also referred to as segments) [Column 4, lines 12-14; Fig. 2, Fig. 3]; the encryption process of a hierarchical tree is performed via a bottom-up approach, starting with leaf nodes and ending with a root node of the hierarchical tree [Column 3, lines 13-16, Fig. 2, Fig. 4]; the above example process is iteratively performed in a bottom-up manner, from leaf nodes 251-255, until it reaches root nodes 221-223 [Column 9, lines 22-39]; a storage system hierarchy can be considered as a tree structure where data blocks get pointed to by the metadata blocks which themselves are pointed to by one or more parent levels of additional metadata block [Column 5, lines 10-15]; a container may contain metadata or fingerprints of all segments therein, where segments are compressed into a compression region [Column 6, lines 38-51; Fig. 2, Fig. 3]; ) [the compromised key] [as not readable to block accesses to the files].
Pogde discloses the claimed subject matter as discussed above but does not explicitly disclose the compromised encryption key; a compromised key; the compromised key; the compromised key. However, Kumar teaches the compromised encryption key (one or more additional operations in order to prevent unauthorized use of the compromised key encryption key to access encrypted data [¶ 0078]; compromise of a key encrypting key. Detecting 1402 compromise of the key encrypting key may be performed in any suitable manner, such as by receiving a report of or otherwise detecting unauthorized use of the key encryption key [¶ 0077]); a compromised key (one or more additional operations in order to prevent unauthorized use of the compromised key encryption key to access encrypted data [¶ 0078]; compromise of a key encrypting key. Detecting 1402 compromise of the key encrypting key may be performed in any suitable manner, such as by receiving a report of or otherwise detecting unauthorized use of the key encryption key [¶ 0077]); the compromised key (one or more additional operations in order to prevent unauthorized use of the compromised key encryption key to access encrypted data [¶ 0078]; compromise of a key encrypting key. Detecting 1402 compromise of the key encrypting key may be performed in any suitable manner, such as by receiving a report of or otherwise detecting unauthorized use of the key encryption key [¶ 0077]); the compromised key (one or more additional operations in order to prevent unauthorized use of the compromised key encryption key to access encrypted data [¶ 0078]; compromise of a key encrypting key. Detecting 1402 compromise of the key encrypting key may be performed in any suitable manner, such as by receiving a report of or otherwise detecting unauthorized use of the key encryption key [¶ 0077]). Pogde and Kumar are analogous art because they are from the same field of endeavor of secure data storage. Therefore, based on Pogde in view of Kumar, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Kumar to the system of Pogde in order to identify a key as compromised so the system can recover from the security breach, and thus protect against unauthorized access of stored data (to protect against unauthorized access to a content encryption key enabling unauthorized decryption of the data object, the data storage service may store content encryption keys in encrypted form [¶ 0023]; despite best efforts, data storage systems may experience security breaches … may through error or malicious intent compromise a key encryption key … allow a data storage system to recover from such security breaches [¶ 0077-0078]). Hence, it would have been obvious to combine the references above to obtain the invention as specified in the instant claim.
Pogde in view of Kumar discloses the claimed subject matter as discussed above but does not explicitly disclose a probabilistic segment reference filter scanning data containers in a data level of the directory tree to find containers with data segments encrypted; a deterministic segment reference filter built to scan metadata containers in metadata levels of the directory tree to find containers with metadata segments encrypted. However, Mondal teaches a probabilistic segment reference filter scanning data containers in a data level of the directory tree to find containers with data segments encrypted (each of level by level scan takes a vector as input. This can be a bloom filter or a perfect hash. The vector indicates what the matching fingerprints the processing logic needs to look for while scanning for this level. For first scan of the top level, L6 level, processing logic computes this vector by traversing the namespace and adding all L6 fingerprints it finds while doing so. For other levels (e.g., L5-L1), this vector is produced by reading the LP segments selected for processing in the current level and adding the child fingerprints to the vector. This vector is referred to as a wanted vector. While scanning the processing logic actually computes what fingerprints it actually finds. This is stored in another vector referred to as a found vector. Usually any fingerprints added to a wanted vector will also be added to a found vector unless there are missing LP segments [Column 8, lines 11-26]); a deterministic segment reference filter built to scan metadata containers in metadata levels of the directory tree to find containers with metadata segments encrypted (each of level by level scan takes a vector as input. This can be a bloom filter or a perfect hash. The vector indicates what the matching fingerprints the processing logic needs to look for while scanning for this level. For first scan of the top level, L6 level, processing logic computes this vector by traversing the namespace and adding all L6 fingerprints it finds while doing so. For other levels (e.g., L5-L1), this vector is produced by reading the LP segments selected for processing in the current level and adding the child fingerprints to the vector. This vector is referred to as a wanted vector. While scanning the processing logic actually computes what fingerprints it actually finds. This is stored in another vector referred to as a found vector. Usually any fingerprints added to a wanted vector will also be added to a found vector unless there are missing LP segments [Column 8, lines 11-26]). Pogde in view of Kumar and Mondal are analogous art because they are from the same field of endeavor of secure data storage. Therefore, based on Pogde in view of Kumar in view of Mondal, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Mondal to the system of Pogde in view of Kumar in order to improve the efficiency of segment identification. Hence, it would have been obvious to combine the references above to obtain the invention as specified in the instant claim.
Pogde in view of Kumar in view of Mondal discloses the claimed subject matter as discussed above but does not explicitly disclose a component marking files having data encrypted as not readable to block accesses to the files. However, Lum teaches a component marking files having data encrypted as not readable to block accesses to the files (metadata used by the secure filesystem during operation on user machine to protect data stored in a file “File1.txt”… each block of data has an associated condition which must be valid in order to allow local reading of the data … the condition is set as a time window, i.e., whether the current date is before a predetermined date [Column 8, lines 28-34; Fig. 3, Fig. 4, see valid read flag marked as N for not valid]; each block additionally has an associated read flag indicating whether the condition is currently valid [Column 8, lines 58-60]; the file-system can determine when the corresponding active key has been deleted and responsively deny the request [Column 9, lines 1-7]; the novel filesystem of the present invention [Column 8, lines 2-10]). Pogde in view of Kumar in view of Mondal and Lum are analogous art because they are from the same field of endeavor of secure data storage. Therefore, based on Pogde in view of Kumar in view of Mondal in view of Lum, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Lum to the system of Pogde in view of Kumar in view of Mondal in order to protect data stored in a file from inadvertent or nefarious disclosure by blocking read access of the file (sensitive and private information being recorded by devices and software in files of computing devices. It is highly desirable to protect such data from inadvertent or nefarious disclosure [Column 1, lines 33-36]; protect data stored in a file “File1.txt” [Column 8, line 28-34; Fig. 3]; each block additionally has an associated read flag indicating whether the condition is currently valid [Column 8, lines 58-60]; the file-system can determine when the corresponding active key has been deleted and responsively deny the request [Column 9, lines 1-7]). Hence, it would have been obvious to combine the references above to obtain the invention as specified in the instant claim.
As per claim 9: Pogde in view of Kumar in view of Mondal in view of Lum teaches all the limitations of claim 8. Furthermore, Mondal discloses wherein the probabilistic segment reference filter comprises one of: a quotient filter, a Bloom filter, or a cuckoo filter, and further wherein the deterministic segment reference filter comprises a perfect hash vector (PHVEC) (each of level by level scan takes a vector as input. This can be a bloom filter or a perfect hash. The vector indicates what the matching fingerprints the processing logic needs to look for while scanning for this level. For first scan of the top level, L6 level, processing logic computes this vector by traversing the namespace and adding all L6 fingerprints it finds while doing so. For other levels (e.g., L5-L1), this vector is produced by reading the LP segments selected for processing in the current level and adding the child fingerprints to the vector. This vector is referred to as a wanted vector. While scanning the processing logic actually computes what fingerprints it actually finds. This is stored in another vector referred to as a found vector. Usually any fingerprints added to a wanted vector will also be added to a found vector unless there are missing LP segments [Column 8, lines 11-26]; A perfect hash function for a set S is a hash function that maps distinct elements in S to a set of integers, with no collisions. A perfect hash function has many of the same applications as other hash functions, but with the advantage that no collision resolution scheme has to be implemented [Column 10, lines 1-5]; Each upper level contains one or more references to one or more lower level segments. In one embodiment, an upper level segment contains a fingerprint (e.g., metadata) of fingerprints of its child level segments. Only the lowest level segments (e.g., L0 segments) are the actual data segments containing the actual deduplicated segments [Column 5, lines 18-25]; A bloom filter is a space-efficient probabilistic data structure that is used to test whether an element is a member of a set. False positive retrieval results are possible, but false negatives are not; i.e. a query returns either “inside set (may be wrong)” or “definitely not in set”. Elements can be added to the set, but not removed (though this can be addressed with a counting filter). The more elements that are added to the set, the larger the probability of false positives [Column 9, lines 60-67]; Each upper level contains one or more references to one or more lower level segments. In one embodiment, an upper level segment contains a fingerprint (e.g., metadata) of fingerprints of its child level segments. Only the lowest level segments (e.g., L0 segments) are the actual data segments containing the actual deduplicated segments [Column 5, lines 18-25]).
As per claim 10: Pogde in view of Kumar in view of Mondal in view of Lum teaches all the limitations of claim 9. Furthermore, Pogde discloses wherein the directory tree comprises a LO level comprising fingerprints of the data segments and one or more Lp levels comprising fingerprints of the metadata segments (Each upper level contains one or more references to one or more lower level segments. In one embodiment, an upper level segment contains a fingerprint (e.g., metadata) of fingerprints of its child level segments. Only the lowest level segments (e.g., L0 segments) are the actual data segments containing the actual deduplicated segments [Column 5, lines 18-25]).
As per claim 11: Pogde in view of Kumar in view of Mondal in view of Lum teaches all the limitations of claim 10. Furthermore, Pogde discloses wherein the data segments of the LO level are used to populate the probabilistic segment reference filter, and the metadata segments of the one or more Lp levels are used to populate the deterministic segment reference filter (A storage system hierarchy can be considered as a tree structure where data blocks get pointed to by the metadata blocks which themselves are pointed to by one or more parent levels of additional metadata block in a tree structure [Pogde, Column 2, lines 53-56]; the hierarchical file system tree of a deduplicated storage system, leaf nodes represent content of deduplicated data chunks or segments [Pogde, Column 2, lines 62-65]; each of the nodes in the hierarchical tree is encrypted using an encryption key [Pogde, Column 3, lines 3-6]; a container may contain metadata or fingerprints of all segments therein, where segments are compressed into a compression region [Pogde, Column 6, lines 38-51; Fig. 2, Fig. 3]; a file may be represented in a file tree having one or more levels of segments … only the lowest level segments are the actual data segments [Pogde, Column 6, lines 4-15]; the encryption key of a particular node (e.g., child node) is stored together with content of its parent node [Pogde, Column 5, lines 33-35]; Each upper level contains one or more references to one or more lower level segments. In one embodiment, an upper level segment contains a fingerprint (e.g., metadata) of fingerprints of its child level segments. Only the lowest level segments are the actual data segments containing the actual deduplicated segments. Thus, L1 to L6 are segments only contain metadata of their respective child segments(s), referred to herein as LP segments [Pogde, Column 6, lines 9-17]; each of level by level scan takes a vector as input. This can be a bloom filter or a perfect hash. The vector indicates what the matching fingerprints the processing logic needs to look for while scanning for this level. For first scan of the top level, L6 level, processing logic computes this vector by traversing the namespace and adding all L6 fingerprints it finds while doing so. For other levels (e.g., L5-L1), this vector is produced by reading the LP segments selected for processing in the current level and adding the child fingerprints to the vector. This vector is referred to as a wanted vector. While scanning the processing logic actually computes what fingerprints it actually finds. This is stored in another vector referred to as a found vector. Usually any fingerprints added to a wanted vector will also be added to a found vector unless there are missing LP segments [Column 8, lines 11-26]).
As per claim 12: Pogde in view of Kumar in view of Mondal in view of Lum teaches all the limitations of claim 11. Furthermore, Pogde discloses wherein the deduplication backup program looks up the fingerprints in a hash table constituting an index to determine if the fingerprints exist or do not exist within the hash table, and if not, compressing and encrypting corresponding data segments into compression regions for storing in the containers (the encrypted content of the nodes are then stored in one or more storage units of the storage system in a deduplicated manner [Pogde, abstract]; the hierarchical file system tree of a deduplicated storage system, leaf nodes represent content of deduplicated data chunks or segments stored in the deduplicated storage system [Pogde, Column 2, lines 61-65; Fig. 1, Fig. 2]; a deduplicated segment is transmitted to storage system 104 only it has not been stored in storage system 104 [Pogde, Column 4, lines 38-55]; a container may contain metadata or fingerprints of all segments therein, where segments are compressed into a compression region [Pogde, Column 6, lines 38-50; Fig. 2]; each of the nodes in the hierarchical tree is encrypted by security manager 160 using an encryption key that is generated based on content of the corresponding node [Pogde, Column 5, lines 28-32; Fig. 2, Fig. 3]; a list of fingerprints is used to indicate chunk(s) associated with a file. File system control 1008 passes chunk association information (representative data such as fingerprint) to index. Index 1024 is used to locate stored chunks in storage units 1010 via storage unit interface 1012… identifies whether a newly received chunk has already been stored in storage units [Pogde, Column 13, lines 53-67]).
Claim 15 is rejected under 35 U.S.C. 103 as being unpatentable over Pogde et al. (U.S. Patent No. 9432192; hereinafter “Pogde”), in view of Kumar et al. (U.S. PGPub No. 2016/0154963; hereinafter “Kumar”), in view of Mondal (US Patent No. 9715505; hereinafter “Mondal”), in view of Samuels (U.S. PGPub No. 2010/0274772; hereinafter “Samuels”).
As per claim 15: Pogde discloses A system for blocking access to files encrypted with a compromised encryption key, comprising:
a deduplication backup server making a point-in-time copy of the filesystem managing the data segments, wherein each file of the file system is represented as a directory tree storing fingerprints of data using a hashing method and having a root level and one or more hierarchical lower levels (the encrypted content of the nodes are then stored in one or more storage units of the storage system in a deduplicated manner [Pogde, abstract]; the hierarchical file system tree of a deduplicated storage system, leaf nodes represent content of deduplicated data chunks or segments stored in the deduplicated storage system [Pogde, Column 2, lines 61-65; Fig. 1, Fig. 2]; Storage system 104 may include any type of server or cluster of servers. For example, storage system 104 may be a storage server used for any of various different purposes, such as to provide multiple users with access to shared data and/or to back up data (e.g., mission critical data). In one embodiment, storage system 104 includes, but is not limited to, backup engine 106, deduplication storage engine 107, and one or more storage units 108-109 communicatively coupled to each other [Pogde, Column 3, lines 57-66]; in a snapshot-based backup and migration system, content of a root node of a hierarchical tree representing a snapshot of content of a storage system at a point in time is different from one snapshot to another [Pogde, Column 3, lines 27-30; Fig. 3, Fig. 1]; segment the data into multiple chunks (also referred to as segments) [Pogde, Column 4, lines 11-14]; the hierarchical file system tree of a deduplicated storage system, leaf nodes represent content of deduplicated data… an intermediate node represents metadata … a root node [Pogde, Column 2, lines 53-67; Fig. 2, Fig. 3]; a root node of the hierarchical tree represents a content handle of a file, a directory of one or more files, and/or the entire file system [Pogde, Column 3, lines 1-3]; each of the nodes in the hierarchical tree is encrypted using an encryption key that is generated based on content of the corresponding node ( e.g., hashing of the content of the corresponding node) [Pogde, Column 3, lines 3-6]);
a storage maintaining a map of encryption keys and ranges of containers encrypted by respective encryption keys (Index 204 includes information mapping a fingerprint to a storage location that stores a segment represented by the fingerprint… index 204 may be a fingerprint-to-container (FP/CID) index that maps a particular fingerprint to a container that contains the corresponding segment or a compression region (CR) having the segment stored therein [Column 6, lines 25-37; Examiner Note: the fingerprint represents the key as content hash keying is used to generate the keys]; each of the nodes in the hierarchical tree is encrypted by security manager 160 using an encryption key that is generated based on content of the corresponding node [Column 5, lines 28-32; Fig. 2, Fig. 3]; each of the nodes in the hierarchical tree is encrypted using an encryption key that is generated based on the content of the corresponding node [Column 3, lines 3-16]; content hash keying … the keys are computed dynamically from the content of the leaf nodes themselves using a secure hash algorithm [Column 8, lines 4-16]; determine storage locations of nodes 231 and 233 based on keys K10 and K12 (which are also the fingerprints of nodes D10 and D12)… decrypts nodes D10 and D12 using keys K10 and K12 [Column 9, lines 49-55]);
[a hybrid segment reference filter] iteratively inspecting, from the lowest level to a highest level, each container in each level of the file trees of the files to identify containers having segments encrypted (the encryption process of a hierarchical tree is performed via a bottom-up approach, starting with leaf nodes and ending with a root node of the hierarchical tree [Column 3, lines 13-16, Fig. 2, Fig. 4]; the above example process is iteratively performed in a bottom-up manner, from leaf nodes 251-255, until it reaches root nodes 221-223 [Column 9, lines 22-39]; a storage system hierarchy can be considered as a tree structure where data blocks get pointed to by the metadata blocks which themselves are pointed to by one or more parent levels of additional metadata block [Column 5, lines 10-15]; a container may contain metadata or fingerprints of all segments therein, where segments are compressed into a compression region [Column 6, lines 38-51; Fig. 2, Fig. 3]) by [the compromised key] for a corresponding level; and
[a component fencing a container range corresponding to data segments encrypted] by [the compromised key] [to prevent deduplication operations on the data segments upon receiving an indication] that [an encryption key is compromised as a compromised key].
Pogde discloses the claimed subject matter as discussed above but does not explicitly disclose the compromised key; the compromised key; an encryption key is compromised as a compromised key. However, Kumar teaches the compromised key (one or more additional operations in order to prevent unauthorized use of the compromised key encryption key to access encrypted data [¶ 0078]; compromise of a key encrypting key. Detecting 1402 compromise of the key encrypting key may be performed in any suitable manner, such as by receiving a report of or otherwise detecting unauthorized use of the key encryption key [¶ 0077]); the compromised key (one or more additional operations in order to prevent unauthorized use of the compromised key encryption key to access encrypted data [¶ 0078]; compromise of a key encrypting key. Detecting 1402 compromise of the key encrypting key may be performed in any suitable manner, such as by receiving a report of or otherwise detecting unauthorized use of the key encryption key [¶ 0077]); an encryption key is compromised as a compromised key (one or more additional operations in order to prevent unauthorized use of the compromised key encryption key to access encrypted data [¶ 0078]; compromise of a key encrypting key. Detecting 1402 compromise of the key encrypting key may be performed in any suitable manner, such as by receiving a report of or otherwise detecting unauthorized use of the key encryption key [¶ 0077]). Pogde and Kumar are analogous art because they are from the same field of endeavor of secure data storage. Therefore, based on Pogde in view of Kumar, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Kumar to the system of Pogde in order to identify a key as compromised so the system can recover from the security breach, and thus protect against unauthorized access of stored data (to protect against unauthorized access to a content encryption key enabling unauthorized decryption of the data object, the data storage service may store content encryption keys in encrypted form [¶ 0023]; despite best efforts, data storage systems may experience security breaches … may through error or malicious intent compromise a key encryption key … allow a data storage system to recover from such security breaches [¶ 0077-0078]). Hence, it would have been obvious to combine the references above to obtain the invention as specified in the instant claim.
Pogde in view of Kumar discloses the claimed subject matter as discussed above but does not explicitly disclose a hybrid segment reference filter. However, Mondal teaches a hybrid segment reference filter (each of level by level scan takes a vector as input. This can be a bloom filter or a perfect hash. The vector indicates what the matching fingerprints the processing logic needs to look for while scanning for this level. For first scan of the top level, L6 level, processing logic computes this vector by traversing the namespace and adding all L6 fingerprints it finds while doing so. For other levels (e.g., L5-L1), this vector is produced by reading the LP segments selected for processing in the current level and adding the child fingerprints to the vector. This vector is referred to as a wanted vector. While scanning the processing logic actually computes what fingerprints it actually finds. This is stored in another vector referred to as a found vector. Usually any fingerprints added to a wanted vector will also be added to a found vector unless there are missing LP segments [Column 8, lines 11-26]; A bloom filter is a space-efficient probabilistic data structure that is used to test whether an element is a member of a set. False positive retrieval results are possible, but false negatives are not; i.e. a query returns either “inside set (may be wrong)” or “definitely not in set”. Elements can be added to the set, but not removed (though this can be addressed with a counting filter). The more elements that are added to the set, the larger the probability of false positives [Column 9, lines 60-67]; Each upper level contains one or more references to one or more lower level segments. In one embodiment, an upper level segment contains a fingerprint (e.g., metadata) of fingerprints of its child level segments. Only the lowest level segments (e.g., L0 segments) are the actual data segments containing the actual deduplicated segments [Column 5, lines 18-25]; A perfect hash function for a set S is a hash function that maps distinct elements in S to a set of integers, with no collisions. A perfect hash function has many of the same applications as other hash functions, but with the advantage that no collision resolution scheme has to be implemented [Column 10, lines 1-5]; Each upper level contains one or more references to one or more lower level segments. In one embodiment, an upper level segment contains a fingerprint (e.g., metadata) of fingerprints of its child level segments. Only the lowest level segments (e.g., L0 segments) are the actual data segments containing the actual deduplicated segments [Column 5, lines 18-25]). Pogde in view of Kumar and Mondal are analogous art because they are from the same field of endeavor of secure data storage. Therefore, based on Pogde in view of Kumar in view of Mondal, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Mondal to the system of Pogde in view of Kumar in order to improve the efficiency of segment identification. Hence, it would have been obvious to combine the references above to obtain the invention as specified in the instant claim.
Pogde in view of Kumar in view of Mondal discloses the claimed subject matter as discussed above but does not explicitly disclose a component fencing a container range corresponding to data segments encrypted to prevent deduplication operations on the data segments upon receiving an indication. However, Samuels teaches a component fencing a container range corresponding to data segments encrypted to prevent deduplication operations on the data segments upon receiving an indication (the lock manager 415 ensures synchronized access by multiple different user agents to data stored within the storage cloud… Locks restrict access to data objects and/or restrict operations that can be performed on data objects. The lock manager 415 may perform numerous different types of locks. Examples of locks that may be implemented include … exclusive locks (allows read and update access to the resource, and prevents others from having any access to it) [Samuels ¶ 0093-0094, Examiner Note: locking access]). Pogde in view of Kumar in view of Mondal and Samuels are analogous art because they are from the same field of endeavor of secure data storage. Therefore, based on Pogde in view of Kumar in view of Mondal in view of Samuels, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teaching of Samuels to the system of Pogde in view of Kumar in view of Mondal in order to restrict access to data objects and/or restrict operations that can be performed on data objects for improved security. Hence, it would have been obvious to combine the references above to obtain the invention as specified in the instant claim.
Allowable Subject Matter
Claims 7, 13-14, and 16-20 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to JAMES P MOLES whose telephone number is (703)756-1043. The examiner can normally be reached M-F 8:00am-5:00pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jung Kim can be reached at (571) 272-3804. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/JAMES P MOLES/Examiner, Art Unit 2494
/JUNG W KIM/Supervisory Patent Examiner, Art Unit 2494