Prosecution Insights
Last updated: August 17, 2026
Application No. 19/182,297

USER INTERFACE FOR CONVERTING SEARCH RESULTS OF DOMAIN-LEVEL CLOUD CONTENT ITEMS INTO SECURITY RULE

Non-Final OA §103§112
Filed
Apr 17, 2025
Priority
Apr 18, 2024 — provisional 63/636,051
Examiner
LEE, MICHAEL M
Art Unit
2436
Tech Center
2400 — Computer Networks
Assignee
Material Security Inc.
OA Round
1 (Non-Final)
84%
Grant Probability
Favorable
1-2
OA Rounds
1y 4m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 84% — above average
84%
Career Allowance Rate
229 granted / 273 resolved
+25.9% vs TC avg
Strong +41% interview lift
Without
With
+41.0%
Interview Lift
resolved cases with interview
Typical timeline
2y 9m
Avg Prosecution
25 currently pending
Career history
293
Total Applications
across all art units

Statute-Specific Performance

§101
9.2%
-30.8% vs TC avg
§103
52.8%
+12.8% vs TC avg
§102
8.2%
-31.8% vs TC avg
§112
19.9%
-20.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 273 resolved cases

Office Action

§103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This is a non-final office action in response to applicant’s communication filed on 4/17/2025. Claims 1-20 are pending and being considered. Priority Applicant’s claim for the benefit of a prior-filed application (No. 63/636,051, filed on 4/18/2024) under 35 U.S.C. 119(e) or under 35 U.S.C. 120, 121, 365(c), or 386(c) is acknowledged. Information Disclosure Statement The information disclosure statement (IDS) submitted on 2/26/2026, has been considered. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, initialed and dated copy of Applicant’s IDS form 1449 filed as stated above is attached to the instant Office Action. Claim Objections Claims 1, 4, 6, 8, 11, 13, 15, 19 are objected to because of the following informalities: Claim 1 line 3, “… of matching criteria …” may read “… of the matching criteria …”. Similarly, claim 6 line 2; claim 8 line 4; claim 13 line 3; claim 15 line 7; claim 19 line 2. Claim 4 line 4, “… to access a first file …” may read “… to access the first file …”. Line 5, “direction permission” may read “the direct permission”. Similarly, claim 11. Claim 15 line 4, “cause the processor to perform one or more steps comprising:” is suggested to read “cause the processor to perform Claim Rejections - 35 USC § 112 The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 5, 12, 18 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claim 5 lines 3-9 recites, “determining …: moving …”. It is not clear what the object of the “determining” is. Similarly, claim 12, 18. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. Claims 1-2, 8-9, 15-16 are rejected under 35 U.S.C. 103 as being unpatentable over Meriaux et al (US10878115B1, hereinafter, “Meriaux”), in view of Frank et al (US20070271235A1, hereinafter, “Frank”). Regarding claim 1, similarly claim 8, claim 15, Meriaux teaches: A method/A non-transitory computer-readable storage medium storing instructions that, when executed, cause a processor/A system comprising: a processor; and a non-transitory computer-readable storage medium storing instructions (Meriaux, discloses systems and methods for controlling record relationship changes in a content management system, see [Abstract]. Fig. 2 Processing Unit and System Memory), for identifying security vulnerabilities, the method comprising: generating for display a test interface including an input field for matching criteria (e.g., Fig. 5, and [Col. 5 lines 42-45] As shown in FIG. 5, a user interface 500 may display one or more fields of user setup objects, and allow the system administrator to select the matchable document field(s), or vice versa); receiving input of matching criteria from an administrator of a domain ([Col. 4 lines 57-64] A customer's system administrator may define what role(s) a user may play, assign users or employees different roles, and manage the roles with the user setup records. A system administrator may use attributes in fields of the user setup records to group users depending on its business need. The system administrator may select default fields and/or attributes provided by the content management system 110, or add new fields and/or attributes to customize user roles. And [Col. 6 lines 61-63] At 621, a user interface 500, as shown in FIG. 5, may be displayed for the system administrator to define the matching rule); searching for files within a content management system repository corresponding to the domain ([Col. 5 lines 38-45] the matching module 1143 may compare attributes associated with the user group (i.e., relevant attributes of user setup records in a user group) and the corresponding attributes of a document, e.g., product to product, and country to country. As shown in FIG. 5, a user interface 500 may display one or more fields of user setup objects, and allow the system administrator to select the matchable document field(s), or vice versa. And [Col. 7 lines 1-4] At 625, matchable documents for each user group may be determined based on attributes of user setup records in the user group, the matching rule, and attributes of the documents); receiving user input to form a rule based on the matching criteria ([Col. 6 lines 16-22] The matching module 1143 may interpret the rules at setup time and the document stamping module 1144 may stamp the user groups to the documents at setup time as well. Once it is done, at the run time, when a user searches the documents, the access controller 114 may know immediately what kind of role he/she may play on what document without further interpretation of the rules); and monitoring for files satisfying the rule, the monitoring resulting in a remediation action for files satisfying the rule ([Abstract] Actions for creating, deleting and reassigning are permitted only when the inbound relationship is editable according to the secure inbound relationship attribute. And [Col. 13 lines 34-41] When the relationship between the master and detail objects is secured, the state and roles applied on the master object records drive behaviors of related objects on the object details page of a master object. If the inbound relationship is editable, the process may proceed to 1090 where actions for Creating, Deleting, and Updating records should honor secured inbound relationship(s) and be enabled). While Meriaux teaches matching document in a content management system based on matching rule, but does not specifically teach generating for display representations of files as shown below, in the same field of endeavor Frank teaches: generating for display representations of files within the content management system repository corresponding to the domain having content that matches the matching criteria (Frank, discloses method for displaying information about documents in a corpus of documents, [Abstract] accepting search criteria including a free text entry query and a domain identifier identifying a domain; in response to accepting the search criteria, identifying a set of documents among the corpus of documents, wherein each document of the set of documents: (1) contains anywhere within the document location-related information that locates that document within the domain; and (2) contains anywhere within the document information that is responsive to the free text entry query, wherein said identified documents are identified by a plurality of document identifiers. And [0082] The elements may be defined in a sequence allowing the user to select a collection of documents … When viewing a set of documents in a map 805, the user may change the map view to display a subset of this document set), Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have employed the teachings of Frank in the controlling record relationship changes in a content management system of Meriaux by displaying information about documents in a corpus of documents based on search criteria. This would have been obvious because the person having ordinary skill in the art would have been motivated to identify set of documents in response to accepting search criteria (Frank, [Abstract]). Meriaux further teaches: wherein the representations are updated as the matching criteria is edited ([Col. 6 lines 5-14] When an existing rule is changed, some of the old document stamps may become obsolete because they are based on the old rule. The matching module 1143 may determine which old document stamps are based on the old rule, check all the groups related to the old rule and all the documents, and try to match them. The document stamping module 1144 may then stamp the documents with their new matchable groups. Events that may trigger document stamping from rule change may include adding and updating a matching rule, changing the status of a matching rule (e.g., activate and deactivate) and removing a matching rule). Regarding claim 2, similarly claim 9, claim 16, Meriaux-Frank combination teaches the method of claim 1, the non-transitory computer-readable storage medium of claim 8, the system of claim 15, Meriaux further teaches: wherein the content management system is a cloud service that stores content at an electronic repository for users of the domain ([Col. 3 lines 22-26] The content storage system 111 may store content that user computing devices 120a-120n may access. Each content repository (e.g., 111a or 111b) may store a specific category of content, and allow users to interact with its content in a specific business context. And [Col. 3 lines 47-51] the content management system 110 may run on a cloud computing platform. Users can access content on the cloud independently by using a virtual machine image, or purchasing access to a service maintained by a cloud database provider). Claims 3, 10, 17 are rejected under 35 U.S.C. 103 as being unpatentable over Meriaux-Frank as applied above to claim 1, 8, 15 respectively, further in view of Zimmermann et al (US20180027006A1, hereinafter, “Zimmermann”). Regarding claim 3, similarly claim 10, claim 17, Meriaux-Frank combination teaches the method of claim 1, the non-transitory computer-readable storage medium of claim 8, the system of claim 15, The combination of Meriaux-Frank does not specifically teach, Zimmermann in the same field of endeavor teaches: the method further comprising: capturing, via a webhook, a first file recently added at the domain (Zimmermann, discloses system and method for securing enterprise computing environment, see [Abstract]/[Title]. And [0109] One can also scan for file metadata, apply rules on the metadata, and pull down content for scanning. An alternative to full scanning of a file system is using a web hook for the domain to obtain selected information); Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have employed the teachings of Zimmermann in the controlling record relationship changes in a content management system of Meriaux-Frank by using webhook to obtain information for domain. This would have been obvious because the person having ordinary skill in the art would have been motivated to have enterprise APIs for connecting to information technology infrastructure of an enterprise and discover information about entities relevant to the information security of the enterprise (Zimmermann, [Abstract]). Meriaux further teaches: determining whether the first file contains content that matches the matching criteria of the rule; and in response to determining that the first file contains content that matches the matching criteria of the rule, performing the remediation action (Meriaux, the teachings of Meriaux for the “files” may be similarly applied to the “first file” including matching criteria of the rule and remediation action). Claims 6, 13, 19 are rejected under 35 U.S.C. 103 as being unpatentable over Meriaux-Frank as applied above to claim 1, 8, 15 respectively, further in view of Karlin et al (US20230040678A1, hereinafter, “Karlin”). Regarding claim 6, similarly claim 13, claim 19, Meriaux-Frank combination teaches the method of claim 1, the non-transitory computer-readable storage medium of claim 8, the system of claim 15, The combination of Meriaux-Frank does not specifically teach, Karlin in the similar field of endeavor teaches: further comprising: generating recommendations for matching criteria using a machine learning model trained to output recommendations based on prior searches performed by at least one client device associated with an administrator (Karlin, discloses methods and systems for recommendations based on user supplied criteria, [Title]/[Abstract]. And [0012] systems for providing recommendations based on user-supplied criteria using machine learning models. For example, the system may receive a user preference for content recommendations from a user. The system may retrieve a user profile for the user. The system may compare the user preference to the user profile to determine a criterion for content recommendations for the user. The system may receive a content attribute for content provided by a content provider. The system may match the criterion to the content attribute. The system may, in response to matching the criterion to the content attribute, generate for display a recommendation to the user for the content). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have employed the teachings of Karlin in the controlling record relationship changes in a content management system of Meriaux-Frank by providing recommendations based on user-supplied criteria using machine learning models. This would have been obvious because the person having ordinary skill in the art would have been motivated to generate recommendation for user content for user preference (Karlin, [Abstract]). Claims 7, 14, 20 are rejected under 35 U.S.C. 103 as being unpatentable over Meriaux-Frank-Karlin as applied above to claim 6, 13, 19 respectively, further in view of Ramanan et al (US20240296231A1, hereinafter, “Ramanan”). Regarding claim 7, similarly claim 14, claim 20, Meriaux-Frank-Karlin combination teaches the method of claim 6, the non-transitory computer-readable storage medium of claim 13, the system of claim 19, The combination of Meriaux-Frank-Karlin does not specifically teach, Ramanan in the same field of endeavor teaches: wherein the machine learning model is trained on search strings, each search string labeled with whether or not a security rule was established based on the search string (Ramanan, discloses apparatus and method for security feature implementation with a single trained machine model across security features improves prediction quality and efficiency of predictions, [Abstract]. And [0014] Prior to deployment of the machine learning model, a search engine query generator (hereinafter simply “generator”) identifies important tokens for each security feature via term frequency-inverse document frequency (tf-idf) statistics of tokens extracted from documents related to each security feature… Subsequently, a trainer uses the documents and corresponding SaaS application identifiers as training data for the machine learning model, with labels comprising vectors with each entry indicating whether a corresponding feature is implemented). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to have employed the teachings of Ramanan in the controlling record relationship changes in a content management system of Meriaux-Frank-Karlin by training machine learning model for improving security feature quality and efficiency prediction. This would have been obvious because the person having ordinary skill in the art would have been motivated to implement security features output based on confidence values output by the trained machine learning model and identifies sentences that describe the implementations in corresponding content for top-ranked URLs (Ramanan, [Abstract]). Allowable Subject Matter Claims 4-5, 11-12, 18 are objected to as being dependent upon a rejected base claim(s), but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims as well as resolving of any outstanding informalities and concerns under 35 USC 112(b) presented in this office action. The following is a statement of reasons for the indication of allowable subject matter: Claim 4 (similarly claims 11) depends on claim 3 (claim 10) which further depends on claim 1 (claim 8), further recites, “wherein the matching criteria indicates to detect content with corresponding metadata including an indication that the content is suspicious, and wherein performing the remediation action comprises: allocating direct permission to access a first file to a first user of the domain; revoking direction permission to access the first file from a second user of the domain; and moving the first file to a quarantine storage area, wherein the first user has access to the quarantine storage area”. Claim 5 (similarly claims 12, claim 18) depends on claim 1 (claim 8, claim 15), further recites, “wherein the remediation action comprises quarantining files that satisfy the rule, the method further comprising: determining in response to receiving, for a first file in a quarantine storage area, an indication from the administrator to remove the first file from the quarantine storage area: moving the first file from the quarantine storage area to a first folder of the content management system repository, wherein moving the first file to the content management system repository causes inherited permissions associated with the first folder to be provided for the first file”. The prior arts identified, either singularly or in combination fails to anticipate or render obvious the claimed limitations of claims shown above. Citation of References The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. The following references are cited but not been replied upon for this office action: Meriaux et al (US12549557B1) discloses systems and methods for user identity security in content management system. Schwartz, et al (US20220114267A1) discloses system and method for secure sharing of documents via a content management repository. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to MICHAEL M LEE whose telephone number is (571)272-1975. The examiner can normally be reached on M-F: 8:30AM - 5:30PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Shewaye Gelagay can be reached on (571) 272-4219. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /MICHAEL M LEE/Primary Examiner, Art Unit 2436
Read full office action

Prosecution Timeline

Apr 17, 2025
Application Filed
Aug 05, 2026
Non-Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12706924
TECHNIQUES FOR DETECTING PERSISTENT DIGITAL ASSETS ON AN EXTERNAL ATTACK SURFACE
2y 9m to grant Granted Aug 11, 2026
Patent 12689611
Prioritization For Time-Deterministic Firewalls
1y 12m to grant Granted Jul 21, 2026
Patent 12676884
Spoofed UDP Packet Detection
2y 2m to grant Granted Jul 07, 2026
Patent 12671994
INTEGRITY PROTECTION FAILURE HANDLING METHOD AND APPARATUS, AND USER EQUIPMENT
3y 7m to grant Granted Jun 30, 2026
Patent 12665914
VEHICLE SECURITY ANALYSIS APPARATUS, AND METHOD AND PROGRAM STORAGE MEDIUM
2y 4m to grant Granted Jun 23, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
84%
Grant Probability
99%
With Interview (+41.0%)
2y 9m (~1y 4m remaining)
Median Time to Grant
Low
PTA Risk
Based on 273 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month