Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Detailed Action
1. The office action is in response to the communication filed 4/17/2025.
Information Disclosure Statement
2. The information disclosure statement (IDS) submitted on 2/26/2026 was filed after the mailing date of the instant application. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Claim Rejections – 35 USC 103
3. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office Action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
4. Claims 1-20 are rejected under 35 USC 103 as being unpatentable over Pearl et al (US 2014/0026182) in view of Addala et al (US 9,438,604).
Regarding claim 1, Pearl et al teaches a method for quarantining files to be stored for a domain on a content management system (fig. 49, which discloses quarantining files in a quarantine report log folder, upon executing a quarantine review process), the method comprising:
determining whether a file stored in cloud storage in association with a domain satisfies a quarantine rule (par [0134] & par [0138], which disclose using the cloud-based platform for quarantining file versions for files, upon a quarantine review process being performed for analyzed files), the determination based on metadata associated with the file that is stored in a content management system repository corresponding to the domain (fig. 49, which discloses determining if the file is assigned to the quarantine folder based on details associated with the file); and
in response to determining that the file that satisfies the quarantine rule:
updating a permissions data structure to provide direct permission to an administrator to access the file (par [0128], lines 2-7 & par [0150], which disclose setting file lockdown status to only allow administrator access to a potentially malicious file), wherein the administrator has access to files stored within a quarantine storage repository for the domain (par [0238], lines 1-10, which discloses the administrator having access to the quarantine report via an administrative interface);
updating the permissions data structure to revoke existing direct permission to access the file for a first set of users (par [0128], lines 5-10, which discloses preventing a group of users from performing access on the file during lockdown status); and
moving the file to the quarantine storage repository (par [0225], which discloses moving the file to the quarantined folder).
Pearl et al does not explicitly teach wherein a second set of users retain inherited permission to access the file based on being permissioned to access one or more files in a given cloud storage location, the one or more files including the file; and in response to moving the file to the quarantine storage repository, revoking the inherited permissions to access the file from each of the second set of users.
However, Addala et al further teaches wherein a second set of users retain inherited permission to access the file based on being permissioned to access one or more files in a given cloud storage location, the one or more files including the file (col. 2, lines 8-10, col. 3, lines 65-67, & col. 4, lines 1-4, “users granted quarantine access to an application”); and
in response to moving the file to the quarantine storage repository, revoking the inherited permissions to access the file from each of the second set of users (col. 16, lines 30-32, which discloses revoking access for users to a data set when a modified version of the data set has been transitioned to a quarantine portion of database).
It would have been obvious to one of ordinary skill in the art, before the effective day of the invention, that one would be motivated to combine the teachings of Addala et al within the concept illustrated by Pearl et al in order to improve managing access requests for secure data by factoring an access allowance rate associated with each requesting user to determine whether or not to grant access to users attempting to access the secure data (as disclosed in the Abstract of Addala et al) because this feature further ensures prevention of unauthorized access to data by users with insufficient privileges or quarantine access status when comparing the requesting parties previous access history metrics.
Regarding claim 2, Pearl et al and Addala et al teach the limitations of claim 1.
Pearl et al further teaches generating, for display, a representation of the file (fig. 4, ‘424); and receiving, from the administrator, a request to add the file to the quarantine storage repository (fig. 8, ‘805/’806 & par [0162], lines 1-5).
Regarding claim 3, Pearl et al and Addala et al teach the limitations of claim 1.
Pearl et al further teaches wherein the permissions data structure stores, for each file in the quarantine storage repository, a records of direct permission provided to and revoked from the file before the file was moved to the quarantine storage repository (par [0265], lines 11-16).
Regarding claim 4, Pearl et al and Addala et al teach the limitations of claim 1.
Pearl et al further teaches receiving, from the administrator, a request to remove the file from the quarantine storage repository (par [0161], lines 1-5);
in response to receiving the request, moving the file to the given cloud storage location (par [0162], lines 1-5); and
in response to moving the file to the given cloud storage location, reinstating the inherited permissions to access the file to each of the second set of users (fig. 37 & par [0039]).
Regarding claim 5, Pearl et al and Addala et al teach the limitations of claim 1.
Pearl et al further teaches updating the permissions data structure to reinstate direct permission to the administrator to access the file (fig. 37 & par [0224]).
Regarding claim 6, Pearl et al and Addala et al teach the limitations of claim 1.
Pearl et al further teaches updating the permissions data structure to reinstate direct permission to access the file in at any location within the cloud storage from the administrator (fig. 37 & par [0039]).
Regarding claim 7, Pearl et al and Addala et al teach the limitations of claim 1.
Pearl et al further teaches wherein the quarantine rule is determined by:
inputting historical data associated with interactions of the administrator with the content management system to a machine learning model (par [0193], lines 1-4, “historical indications”), the machine learning model trained on historical data labeled with a set of matching criteria entered by the administrator (par [0213], “historical violations”); and
receiving, from the machine leaning model, the matching criteria (par [0070], lines 2-7).
Regarding claim 8, Pearl et al and Addala et al teach the limitations of claim 1.
Pearl et al further teaches each of the first set of users received access to the file in cloud storage from a creator of the file (par [0092], lines 6-9).
Regarding claim 9, Pearl et al teaches a non-transitory computer-readable storage medium storing instructions (par [0260], lines 1-5) that, when executed, cause a processor to perform one or more steps, the method comprising:
determining whether a file stored in cloud storage in association with a domain satisfies a quarantine rule (par [0134] & par [0138], which disclose using the cloud-based platform for quarantining file versions for files, upon a quarantine review process being performed for analyzed files), the determination based on metadata associated with the file that is stored in a content management system repository corresponding to the domain (fig. 49, which discloses determining if the file is assigned to the quarantine folder based on details associated with the file); and
in response to determining that the file that satisfies the quarantine rule:
updating a permissions data structure to provide direct permission to an administrator to access the file (par [0128], lines 2-7 & par [0150], which disclose setting file lockdown status to only allow administrator access to a potentially malicious file), wherein the administrator has access to files stored within a quarantine storage repository for the domain (par [0238], lines 1-10, which discloses the administrator having access to the quarantine report via an administrative interface);
updating the permissions data structure to revoke existing direct permission to access the file for a first set of users (par [0128], lines 5-10, which discloses preventing a group of users from performing access on the file during lockdown status); and
moving the file to the quarantine storage repository (par [0225], which discloses moving the file to the quarantined folder).
Pearl et al does not explicitly teach wherein a second set of users retain inherited permission to access the file based on being permissioned to access one or more files in a given cloud storage location, the one or more files including the file; and in response to moving the file to the quarantine storage repository, revoking the inherited permissions to access the file from each of the second set of users.
However, Addala et al further teaches wherein a second set of users retain inherited permission to access the file based on being permissioned to access one or more files in a given cloud storage location, the one or more files including the file (col. 2, lines 8-10, col. 3, lines 65-67, & col. 4, lines 1-4, “users granted quarantine access to an application”); and
in response to moving the file to the quarantine storage repository, revoking the inherited permissions to access the file from each of the second set of users (col. 16, lines 30-32, which discloses revoking access for users to a data set when a modified version of the data set has been transitioned to a quarantine portion of database).
It would have been obvious to one of ordinary skill in the art, before the effective day of the invention, that one would be motivated to combine the teachings of Addala et al within the concept illustrated by Pearl et al in order to improve managing access requests for secure data by factoring an access allowance rate associated with each requesting user to determine whether or not to grant access to users attempting to access the secure data (as disclosed in the Abstract of Addala et al) because this feature further ensures prevention of unauthorized access to data by users with insufficient privileges or quarantine access status when comparing the requesting parties previous access history metrics.
Regarding claim 10, Pearl et al and Addala et al teach the limitations of claim 9.
Pearl et al further teaches generating, for display, a representation of the file (fig. 4, ‘424); and receiving, from the administrator, a request to add the file to the quarantine storage repository (fig. 8, ‘805/’806 & par [0162], lines 1-5).
Regarding claim 11, Pearl et al and Addala et al teach the limitations of claim 9.
Pearl et al further teaches wherein the permissions data structure stores, for each file in the quarantine storage repository, a records of direct permission provided to and revoked from the file before the file was moved to the quarantine storage repository (par [0265], lines 11-16).
Regarding claim 12, Pearl et al and Addala et al teach the limitations of claim 9.
Pearl et al further teaches receiving, from the administrator, a request to remove the file from the quarantine storage repository (par [0161], lines 1-5);
in response to receiving the request, moving the file to the given cloud storage location (par [0162], lines 1-5); and
in response to moving the file to the given cloud storage location, reinstating the inherited permissions to access the file to each of the second set of users (fig. 37 & par [0039]).
Regarding claim 13, Pearl et al and Addala et al teach the limitations of claim 9.
Pearl et al further teaches updating the permissions data structure to reinstate direct permission to the administrator to access the file (fig. 37 & par [0224]).
Regarding claim 14, Pearl et al and Addala et al teach the limitations of claim 9.
Pearl et al further teaches updating the permissions data structure to reinstate direct permission to access the file in at any location within the cloud storage from the administrator (fig. 37 & par [0039]).
Regarding claim 15, Pearl et al and Addala et al teach the limitations of claim 9.
Pearl et al further teaches wherein the quarantine rule is determined by:
inputting historical data associated with interactions of the administrator with the content management system to a machine learning model (par [0193], lines 1-4, “historical indications”), the machine learning model trained on historical data labeled with a set of matching criteria entered by the administrator (par [0213], “historical violations”); and
receiving, from the machine leaning model, the matching criteria (par [0070], lines 2-7).
Regarding claim 16, Pearl et al and Addala et al teach the limitations of claim 9.
Pearl et al further teaches each of the first set of users received access to the file in cloud storage from a creator of the file (par [0092], lines 6-9).
Regarding claim 17, Pearl et al teaches a system comprising:
a processor (fig. 2); and
a non-transitory computer-readable storage medium storing instructions (par [0260], lines 1-5) that, when executed, cause the processor to perform one or more steps comprising:
determining whether a file stored in cloud storage in association with a domain satisfies a quarantine rule (par [0134] & par [0138], which disclose using the cloud-based platform for quarantining file versions for files, upon a quarantine review process being performed for analyzed files), the determination based on metadata associated with the file that is stored in a content management system repository corresponding to the domain (fig. 49, which discloses determining if the file is assigned to the quarantine folder based on details associated with the file); and
in response to determining that the file that satisfies the quarantine rule:
updating a permissions data structure to provide direct permission to an administrator to access the file (par [0128], lines 2-7 & par [0150], which disclose setting file lockdown status to only allow administrator access to a potentially malicious file), wherein the administrator has access to files stored within a quarantine storage repository for the domain (par [0238], lines 1-10, which discloses the administrator having access to the quarantine report via an administrative interface);
updating the permissions data structure to revoke existing direct permission to access the file for a first set of users (par [0128], lines 5-10, which discloses preventing a group of users from performing access on the file during lockdown status); and
moving the file to the quarantine storage repository (par [0225], which discloses moving the file to the quarantined folder).
Pearl et al does not explicitly teach wherein a second set of users retain inherited permission to access the file based on being permissioned to access one or more files in a given cloud storage location, the one or more files including the file; and in response to moving the file to the quarantine storage repository, revoking the inherited permissions to access the file from each of the second set of users.
However, Addala et al further teaches wherein a second set of users retain inherited permission to access the file based on being permissioned to access one or more files in a given cloud storage location, the one or more files including the file (col. 2, lines 8-10, col. 3, lines 65-67, & col. 4, lines 1-4, “users granted quarantine access to an application”); and
in response to moving the file to the quarantine storage repository, revoking the inherited permissions to access the file from each of the second set of users (col. 16, lines 30-32, which discloses revoking access for users to a data set when a modified version of the data set has been transitioned to a quarantine portion of database).
It would have been obvious to one of ordinary skill in the art, before the effective day of the invention, that one would be motivated to combine the teachings of Addala et al within the concept illustrated by Pearl et al in order to improve managing access requests for secure data by factoring an access allowance rate associated with each requesting user to determine whether or not to grant access to users attempting to access the secure data (as disclosed in the Abstract of Addala et al) because this feature further ensures prevention of unauthorized access to data by users with insufficient privileges or quarantine access status when comparing the requesting parties previous access history metrics.
Regarding claim 18, Pearl et al and Addala et al teach the limitations of claim 17.
Pearl et al further teaches generating, for display, a representation of the file (fig. 4, ‘424); and receiving, from the administrator, a request to add the file to the quarantine storage repository (fig. 8, ‘805/’806 & par [0162], lines 1-5).
Regarding claim 19, Pearl et al and Addala et al teach the limitations of claim 17.
Pearl et al further teaches wherein the permissions data structure stores, for each file in the quarantine storage repository, a records of direct permission provided to and revoked from the file before the file was moved to the quarantine storage repository (par [0265], lines 11-16).
Regarding claim 20, Pearl et al and Addala et al teach the limitations of claim 9.
Pearl et al further teaches receiving, from the administrator, a request to remove the file from the quarantine storage repository (par [0161], lines 1-5);
in response to receiving the request, moving the file to the given cloud storage location (par [0162], lines 1-5); and
in response to moving the file to the given cloud storage location, reinstating the inherited permissions to access the file to each of the second set of users (fig. 37 & par [0039]).
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Randy A. Scott whose telephone number is (571) 272-3797. The examiner can normally be reached on Monday-Thursday 7:30 am-5:00 pm, second Fridays 7:30 am-4pm.
If attempts to reach the examiner by telephone are unsuccessful, the examiner's supervisor, Luu Pham can be reached on (571) 270-5002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/RANDY A SCOTT/Primary Examiner, Art Unit 2439
20260713