Prosecution Insights
Last updated: October 02, 2026
Application No. 19/195,213

LOCAL ISOLATION IN A BROWSER

Non-Final OA §103§112
Filed
Apr 30, 2025
Priority
Apr 22, 2021 — provisional 63/177,998 +1 more
Examiner
WADE-WRIGHT, SHAQUEAL D
Art Unit
Tech Center
Assignee
Palo Alto Networks Inc.
OA Round
1 (Non-Final)
85%
Grant Probability
Favorable
1-2
OA Rounds
11m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 85% — above average
85%
Career Allowance Rate
389 granted / 457 resolved
+25.1% vs TC avg
Strong +18% interview lift
Without
With
+18.1%
Interview Lift
resolved cases with interview
Typical timeline
2y 4m
Avg Prosecution
19 currently pending
Career history
469
Total Applications
across all art units

Statute-Specific Performance

§101
15.5%
-24.5% vs TC avg
§103
49.1%
+9.1% vs TC avg
§102
7.6%
-32.4% vs TC avg
§112
18.1%
-21.9% vs TC avg
Black line = Tech Center average estimate • Based on career data from 457 resolved cases

Office Action

§103 §112
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Information Disclosure Statement The information disclosure statement (IDS) submitted on 06/16/2025 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Claim Objections Claim 16 is objected to because of the following informalities: The examiner suggest amending the claim to remove the extra space and period in the middle of the claim in line 12. Appropriate correction is required. Claim Rejections - 35 USC § 112 Claims 17-23 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. The claims discloses limitations “non-transitory machine readable medium having program code,” however, the specification is void and doers not disclose any medium or program code to perform the instructions. The following is a quotation of 35 U.S.C. 112(b): (b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention. The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph: The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention. Claims 1, 4, 9-10, 12, 14, 16-17, 19, 24-26, 28 and 33-34 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claims 1, 4, 9-10, 12, 14, 16-17, 19, 24-26, 28 and 33-34 use the term “and/or”. This term renders the scope of the claim language unclear because it is not clear whether all of the limitations are required or not, in order to fall within the scope of the claim. The use of "and" in the language would require all the limitations to be present in order to fall within the scope of the claim language. The use of "or" in the language would only require one of the limitations to be present in order to fall within the scope of the claim language. The use of "and/or" makes the applicants intended scope unclear because one of ordinary skill in the art would be unable to determine whether or not all of the listed limitations are required or not. Therefore, the claims are rejected for failing to specifically point out and distinctly claim the subject matter which the inventors regard as the invention. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-2, 4-5, 8-11, 13-14, 16-23, 25-32 and 34 are rejected under 35 U.S.C. 103 as being unpatentable over Kashyap et al. (US Pub No. 2017/0180427) in view of Kohavi et al. (US Pub No. 2009/0063869). Regarding independent claim 1, Kashyap teaches a method comprising: maintaining a first environment, which includes at least a browser, wherein the first environment is isolated on an endpoint (Kashyap, Abstract, page 17, paragraph 0163, page 3, paragraph 0030, page 6, paragraph 0055 and page 4, paragraph 0040; first isolated environment/VM); and enabling secure data transfer within the first environment and/or between the first environment and one or more external environments, wherein enabling secure data transfer is based on a backend policy applied to context of the secure data transfer and a user authenticated to the first environment (Kashyap, Abstract, page 17, paragraphs 0163-0165, and pages 15-16, paragraphs 0153-0154; transfer content from first isolated environment to clipboard of second isolated environment). Kashyap does not explicitly teach the method enabling secure data transfer is based on a user authenticated to the first environment. Kohavi teaches enabling secure data transfer is based on a user authenticated to the first environment (Kohavi, page 1, paragraph 0023, page 5, paragraph 0102 and page 8, paragraph 0186; authenticate user identity). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Kashyap with the teachings of Kohavi to use secure filtering & predefined policy to provide the advantage of securing data (Kohavi, page 2, paragraphs 0041-0042). Regarding claim 2, Kashyap in view of Kohavi teaches the method wherein the context of the secure data transfer and the user comprises at least one of characteristics of the user, characteristics of the endpoint, web services, user location, time, and characteristics of one or more processes associated with the secure data transfer (Kashyap, page 12, paragraph 0116, page 16, paragraphs 0156-0157 and page 17, paragraph 0164). Regarding claim 4, Kashyap in view of Kohavi teaches each and every claim limitation of claim 1, however, Kohavi teaches the method wherein enabling secure data transfer across at least the first environment comprises, based on detecting an attempt to communicate data across at least the first environment and external software-as-a-service and/or web applications, at least one of, blocking the attempt to communicate data; alerting the user regarding the attempt to communicate data; prompting the user to provide additional data regarding the attempt to access data; raising an alert to an alerting system indicating the attempt to access the data; prompting an administrator to investigate the attempt to access the data to block or allow the attempt to access the data; prompting the user to reauthenticate at least one of a password, a biometric method, and hardware device, and a two-factor authentication application to the browser; deanonymizing the attempt to access the data; logging the attempt to access the data; erasing a process that attempted to access the data; disabling one or more components of the endpoint; pausing activity of the endpoint in the first environment for a predefined time period; reinstalling the first environment; and disconnecting the endpoint from a network (Kohavi, page 6, paragraphs 0136-0137 and page 11, paragraphs 0278-281; block access/output; log attempt and send to administrators). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Kashyap with the teachings of Kohavi to use secure filtering & predefined policy to provide the advantage of securing data (Kohavi, page 2, paragraphs 0041-0042). Regarding claim 5, Kashyap in view of Kohavi teaches the method wherein enabling secure data transfer across at least the first environment and the one or more external environments comprises allowing shared access by one or more processes running in the first environment to files in the first environment (Kashyap, page 1, paragraph 0009, page 8, paragraphs 0073 & 0077 and page 15, paragraph 0153; shared file system). Regarding claim 8, Kashyap in view of Kohavi teaches the method wherein maintaining the first environment comprises allowing shared access to a clipboard in the first environment that is separate from a local clipboard for the endpoint (Kashyap, pages 15-16, paragraphs 0153 & 0155 and page 17, paragraph 0163 & 0165). Regarding claim 9, Kashyap in view of Kohavi teaches the method further comprising at least one of, purging the clipboard after at least one of a timeout event, a user logout event, and an idle event; monitoring, modifying, and/or scanning the clipboard according to the backend policy; and based on detecting a copy or paste event related to the clipboard, determining whether the copy or paste event is allowed; based on determining that the copy or paste event is allowed, storing data associated with the copy or paste event in the clipboard; and based on determining that the copy or paste event is not allowed, performing one or more actions related to the copy or paste event (Kashyap, page 16, paragraphs 0155-0162 and page 17, paragraph 0164- 0165). Regarding claim 10, Kashyap in view of Kohavi teaches the method wherein at least one of, the one or more actions comprise modifying content of the clipboard based on the copy or paste event according to a privacy, security, and/or data leakage prevention policy of the backend policy, and determining whether the copy or paste event is allowed comprises, detecting uniform resource locators (URLs) in the copy or paste event; and determining whether at least one of the URLs, content associated with the URLs, and personal data and/or credentials associated with the copy or paste event is malicious and/or sensitive (Kashyap, page 16, paragraph 0155 and page 17, paragraph 0163-0165). Regarding claim 11, Kashyap in view of Kohavi teaches the method further comprising: based on detecting an attempt to at least one of export data from the first environment to the one or more external environments and import data from the one or more external environments to the first environment, evaluating the attempt for allowability against a context of the attempt; based on determining that the attempt is allowable, communicating the data to a target of the attempt in the one or more external environments; and based on determining that the attempt is not allowable, performing a remediation action based on characteristics of the attempt (Kashyap, pages 15-16, paragraphs 0153-0156 and page 17, paragraph 0163-0165). Regarding claim 13, Kashyap in view of Kohavi teaches each and every claim limitation of claim 1, however, Kohavi teaches the method further comprising: identifying screen capture events across the first environment; and acting upon the screen capture events according to the backend policy, wherein acting upon the screen capture events comprises, logging the screen capture events across the first environment; and applying the backend policy to at least partially mitigate risk of data leakage of screen captures from the first environment (Kohavi, page 6, paragraphs 0130-0137, page 8, paragraphs 0188-0190; monitor output data based on predefined policy; screen capture; log records). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Kashyap with the teachings of Kohavi to use secure filtering & predefined policy to provide the advantage of securing data (Kohavi, page 2, paragraphs 0041-0042). Regarding claim 14, Kashyap in view of Kohavi teaches the method further comprising: analyzing keyboard capture across the endpoint to identify a process and/or driver and/or malware running on the endpoint that accessed data for the keyboard capture; and determining whether the process is allowed to access data for the keyboard capture based, at least in part, on the analysis (Kashyap, page 16, paragraphs 0155-0157 and 0162; keystrokes). Regarding claim 16, Kashyap in view of Kohavi teaches each and every claim limitation of claim 1, however, Kohavi teaches the method further comprising: monitoring copy of files across the first environment and the one or more external environments to identify an attempt to copy a file between the first environment and the one or more external environments; and based on determining that the attempt is not allowed, at least one of, encrypting the file with a cryptographic key only accessible to the first environment; storing the file in an undocumented location; protecting the file to disallow access by the one or more external environments; configuring the files and/or a file system to disable access to the file by processes running only in the one or more external environments; logging the attempt to copy the file; and blocking the attempt to copy the file (Kohavi, page 6, paragraphs 0130-0137 & 0044, page 9, paragraphs 0221-0225 and page 11, paragraphs 0278-0280; block attempt/access or modify/encryption). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Kashyap with the teachings of Kohavi to use secure filtering & predefined policy to provide the advantage of securing data (Kohavi, page 2, paragraphs 0041-0042). Regarding independent claim 17, Kashyap teaches a non-transitory machine-readable medium having program code stored thereon, the program code comprising instructions to: maintain a first environment, which includes at least a browser, wherein the first environment is isolated on an endpoint (Kashyap, Abstract, page 17, paragraph 0163, page 3, paragraph 0030, page 6, paragraph 0055 and page 4, paragraph 0040; first isolated environment/VM); and enable secure data transfer within the first environment and/or between the first environment and one or more external environments, wherein enabling secure data transfer is based on a backend policy applied to context of the secure data transfer and a user authenticated to the first environment (Kashyap, Abstract, page 17, paragraphs 0163-0165, and pages 15-16, paragraphs 0153-0154; transfer content from first isolated environment to clipboard of second isolated environment). Kashyap does not explicitly teach the method enable secure data transfer is based on a user authenticated to the first environment. Kohavi teaches enable secure data transfer is based on a user authenticated to the first environment (Kohavi, page 1, paragraph 0023, page 5, paragraph 0102 and page 8, paragraph 0186; authenticate user identity). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Kashyap with the teachings of Kohavi to use secure filtering & predefined policy to provide the advantage of securing data (Kohavi, page 2, paragraphs 0041-0042). Regarding claim 18, Kashyap in view of Kohavi teaches the non-transitory machine-readable medium wherein the context of the secure data transfer and the user comprises at least one of characteristics of the user, characteristics of the endpoint, web services, user location, time, and characteristics of one or more processes associated with the secure data transfer (Kashyap, page 12, paragraph 0116, page 16, paragraphs 0156-0157 and page 17, paragraph 0164). Regarding claim 19, Kashyap in view of Kohavi teaches each and every claim limitation of claim 17, however, Kohavi teaches the non-transitory machine-readable medium wherein the instructions to enable secure data transfer across at least the first environment comprises, based on detecting an attempt to communicate data across at least the first environment and external software-as-a-service and/or web applications, at least one of, blocking the attempt to communicate data; alerting the user regarding the attempt to communicate data; prompting the user to provide additional data regarding the attempt to access data; raising an alert to an alerting system indicating the attempt to access the data; prompting an administrator to investigate the attempt to access the data to block or allow the attempt to access the data; prompting the user to reauthenticate at least one of a password, a biometric method, and hardware device, and a two-factor authentication application to the browser; deanonymizing the attempt to access the data; logging the attempt to access the data; erasing a process that attempted to access the data; disabling one or more components of the endpoint; pausing activity of the endpoint in the first environment for a predefined time period; reinstalling the first environment; and disconnecting the endpoint from a network (Kohavi, page 6, paragraphs 0136-0137 and page 11, paragraphs 0278-281; block access/output; log attempt and send to administrators). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Kashyap with the teachings of Kohavi to use secure filtering & predefined policy to provide the advantage of securing data (Kohavi, page 2, paragraphs 0041-0042). Regarding claim 20, Kashyap in view of Kohavi teaches the non-transitory machine-readable medium wherein the instructions to enable secure data transfer across at least the first environment and the one or more external environments comprises allowing shared access by one or more processes running in the first environment to files in the first environment (Kashyap, page 1, paragraph 0009, page 8, paragraphs 0073 & 0077 and page 15, paragraph 0153; shared file system). Regarding claim 21, Kashyap in view of Kohavi teaches the non-transitory machine-readable medium wherein the instructions to maintain the first environment comprises allowing shared access to a clipboard in the first environment that is separate from a local clipboard for the endpoint (Kashyap, pages 15-16, paragraphs 0153 & 0155 and page 17, paragraph 0163 & 0165). Regarding claim 22, Kashyap in view of Kohavi teaches the non-transitory machine-readable medium wherein the program code further comprises instructions to: based on detecting an attempt to at least one of export data from the first environment to the one or more external environments and import data from the one or more external environments to the first environment, evaluating the attempt for allowability against a context of the attempt; based on determining that the attempt is allowable, communicating the data to a target of the attempt in the one or more external environments; and based on determining that the attempt is not allowable, performing a remediation action based on characteristics of the attempt (Kashyap, pages 15-16, paragraphs 0153-0156 and page 17, paragraph 0163-0165). Regarding claim 23, Kashyap in view of Kohavi teaches each and every claim limitation of claim 17, however, Kohavi teaches the non-transitory machine-readable medium wherein the program code further comprises instructions to: identify screen capture events across the first environment; and act upon the screen capture events according to the backend policy, wherein acting upon the screen capture events comprises, log the screen capture events across the first environment; and apply the backend policy to at least partially mitigate risk of data leakage of screen captures from the first environment (Kohavi, page 6, paragraphs 0130-0137, page 8, paragraphs 0188-0190; monitor output data based on predefined policy; screen capture; log records). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Kashyap with the teachings of Kohavi to use secure filtering & predefined policy to provide the advantage of securing data (Kohavi, page 2, paragraphs 0041-0042). Regarding claim 24, Kashyap in view of Kohavi teaches the non-transitory machine-readable medium wherein the program code further comprises instructions to: analyze keyboard capture across the endpoint to identify a process and/or driver and/or malware running on the endpoint that accessed data for the keyboard capture; and determine whether the process is allowed to access data for the keyboard capture based, at least in part, on the analysis (Kashyap, page 16, paragraphs 0155-0157 and 0162; keystrokes). Regarding claim 25, Kashyap in view of Kohavi teaches each and every claim limitation of claim 17, however, Kohavi teaches the non-transitory machine-readable medium wherein the program code further comprises instructions to: monitor copy of files across the first environment and the one or more external environments to identify an attempt to copy a file between the first environment and the one or more external environments; and based on determining that the attempt is not allowed, at least one of, encrypt the file with a cryptographic key only accessible to the first environment; store the file in an undocumented location; protect the file to disallow access by the one or more external environments; configure the files and/or a file system to disable access to the file by processes running only in the one or more external environments; log the attempt to copy the file; and block the attempt to copy the file (Kohavi, page 6, paragraphs 0130-0137 & 0044, page 9, paragraphs 0221-0225 and page 11, paragraphs 0278-0280; block attempt/access or modify/encryption). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Kashyap with the teachings of Kohavi to use secure filtering & predefined policy to provide the advantage of securing data (Kohavi, page 2, paragraphs 0041-0042). Regarding independent claim 17, Kashyap teaches a system comprising one or more endpoints that host one or more external environments; and a first endpoint that, maintains a first environment which includes at least a browser, wherein the first environment is isolated on the first endpoint (Kashyap, Abstract, page 17, paragraph 0163, page 3, paragraph 0030, page 6, paragraph 0055 and page 4, paragraph 0040; first isolated environment/VM); and enables secure data transfer within the first environment and/or between the first environment and one or more external environments, wherein enabling secure data transfer is based on a backend policy applied to context of the secure data transfer and a user authenticated to the first environment (Kashyap, Abstract, page 17, paragraphs 0163-0165, and pages 15-16, paragraphs 0153-0154; transfer content from first isolated environment to clipboard of second isolated environment). Kashyap does not explicitly teach the method enable secure data transfer is based on a user authenticated to the first environment. Kohavi teaches enable secure data transfer is based on a user authenticated to the first environment (Kohavi, page 1, paragraph 0023, page 5, paragraph 0102 and page 8, paragraph 0186; authenticate user identity). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Kashyap with the teachings of Kohavi to use secure filtering & predefined policy to provide the advantage of securing data (Kohavi, page 2, paragraphs 0041-0042). Regarding claim 27, Kashyap in view of Kohavi teaches the system wherein the context of the secure data transfer and the user comprises at least one of characteristics of the user, characteristics of the endpoint, web services, user location, time, and characteristics of one or more processes associated with the secure data transfer (Kashyap, page 12, paragraph 0116, page 16, paragraphs 0156-0157 and page 17, paragraph 0164). Regarding claim 28, Kashyap in view of Kohavi teaches each and every claim limitation of claim 26, however, Kohavi teaches the system wherein enabling secure data transfer across at least the first environment comprises, based on detecting an attempt to communicate data across at least the first environment and external software-as-a-service and/or web applications, at least one of, blocking the attempt to communicate data; alerting the user regarding the attempt to communicate data; prompting the user to provide additional data regarding the attempt to access data; raising an alert to an alerting system indicating the attempt to access the data; prompting an administrator to investigate the attempt to access the data to block or allow the attempt to access the data; prompting the user to reauthenticate at least one of a password, a biometric method, and hardware device, and a two-factor authentication application to the browser; deanonymizing the attempt to access the data; logging the attempt to access the data; erasing a process that attempted to access the data; disabling one or more components of the endpoint; pausing activity of the endpoint in the first environment for a predefined time period; reinstalling the first environment; and disconnecting the endpoint from a network (Kohavi, page 6, paragraphs 0136-0137 and page 11, paragraphs 0278-281; block access/output; log attempt and send to administrators). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Kashyap with the teachings of Kohavi to use secure filtering & predefined policy to provide the advantage of securing data (Kohavi, page 2, paragraphs 0041-0042). Regarding claim 29, Kashyap in view of Kohavi teaches the system wherein enabling secure data transfer across at least the first environment and the one or more external environments comprises allowing shared access by one or more processes running in the first environment to files in the first environment (Kashyap, page 1, paragraph 0009, page 8, paragraphs 0073 & 0077 and page 15, paragraph 0153; shared file system). Regarding claim 30, Kashyap in view of Kohavi teaches the system wherein maintaining the first environment comprises allowing shared access to a clipboard in the first environment that is separate from a local clipboard for the endpoint (Kashyap, pages 15-16, paragraphs 0153 & 0155 and page 17, paragraph 0163 & 0165). Regarding claim 31, Kashyap in view of Kohavi teaches the system where in the first endpoint: based on detecting an attempt to at least one of export data from the first environment to the one or more external environments and import data from the one or more external environments to the first environment, evaluating the attempt for allowability against a context of the attempt; based on determining that the attempt is allowable, communicating the data to a target of the attempt in the one or more external environments; and based on determining that the attempt is not allowable, performing a remediation action based on characteristics of the attempt (Kashyap, pages 15-16, paragraphs 0153-0156 and page 17, paragraph 0163-0165). Regarding claim 32, Kashyap in view of Kohavi teaches each and every claim limitation of claim 26, however, Kohavi teaches the system wherein the first endpoint: identifies screen capture events across the first environment; and acts upon the screen capture events according to the backend policy, wherein acting upon the screen capture events comprises, log the screen capture events across the first environment; and applying the backend policy to at least partially mitigate risk of data leakage of screen captures from the first environment (Kohavi, page 6, paragraphs 0130-0137, page 8, paragraphs 0188-0190; monitor output data based on predefined policy; screen capture; log records). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Kashyap with the teachings of Kohavi to use secure filtering & predefined policy to provide the advantage of securing data (Kohavi, page 2, paragraphs 0041-0042). Regarding claim 33, Kashyap in view of Kohavi teaches the system wherein the first endpoint analyzes keyboard capture across the endpoint to identify a process and/or driver and/or malware running on the endpoint that accessed data for the keyboard capture; and determine whether the process is allowed to access data for the keyboard capture based, at least in part, on the analysis (Kashyap, page 16, paragraphs 0155-0157 and 0162; keystrokes). Regarding claim 34, Kashyap in view of Kohavi teaches each and every claim limitation of claim 26, however, Kohavi teaches the system wherein the first endpoint: monitor copy of files across the first environment and the one or more external environments to identify an attempt to copy a file between the first environment and the one or more external environments; and based on determining that the attempt is not allowed, at least one of, encrypt the file with a cryptographic key only accessible to the first environment; store the file in an undocumented location; protect the file to disallow access by the one or more external environments; configure the files and/or a file system to disable access to the file by processes running only in the one or more external environments; log the attempt to copy the file; and block the attempt to copy the file (Kohavi, page 6, paragraphs 0130-0137 & 0044, page 9, paragraphs 0221-0225 and page 11, paragraphs 0278-0280; block attempt/access or modify/encryption). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Kashyap with the teachings of Kohavi to use secure filtering & predefined policy to provide the advantage of securing data (Kohavi, page 2, paragraphs 0041-0042). Claim(s) 3 and 12 are rejected under 35 U.S.C. 103 as being unpatentable over Kashyap et al. (US Pub No. 2017/0180427) in view of Kohavi et al. (US Pub No. 2009/0063869), as applied to claims 1-2, 4-5, 8-11, 13-14, and 16-34 above and in further view of Andrews et al. (US Pub No. 2021/0133336). Regarding claim 3, Kashyap in view of Kohavi teaches each and every claim limitation of claim 2. Kashyap in view of Kohavi does not explicitly teach the method wherein the characteristics include risk levels. Andrews teaches wherein the characteristics include risk levels (Andrews, page 8, paragraphs 0066-0067 and page 9, paragraph 0071; risk score; secure transfer data between workspace). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Kashyap in view of Kohavi with the teachings of Andrews to incorporate risk levels to provide the advantage of improving the security target of the destination workspace (Andrews, page 9, paragraph 0071). Regarding claim 12, Kashyap in view of Kohavi teaches each and every claim limitation of claim 11. Kashyap in view of Kohavi does not explicitly teach the method wherein evaluating the attempt for allowability against context of the attempt comprises evaluating a risk level associated with context of the attempt, wherein the context for the attempt comprises at least one of a user and/or service that submitted the attempt, a target website, service, and/or resource of the attempt, endpoint posture, a time of day of the attempt, a location of the attempt, and an endpoint type and/or security posture of the endpoint. Andrews teaches wherein evaluating the attempt for allowability against context of the attempt comprises evaluating a risk level associated with context of the attempt, wherein the context for the attempt comprises at least one of a user and/or service that submitted the attempt, a target website, service, and/or resource of the attempt, endpoint posture, a time of day of the attempt, a location of the attempt, and an endpoint type and/or security posture of the endpoint (Andrews, page 8, paragraphs 0066-0067 and page 9, paragraph 0071; risk score; secure transfer data between workspace). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Kashyap in view of Kohavi with the teachings of Andrews to incorporate risk levels to provide the advantage of improving the security target of the destination workspace (Andrews, page 9, paragraph 0071). Claim(s) 6-7 are rejected under 35 U.S.C. 103 as being unpatentable over Kashyap et al. (US Pub No. 2017/0180427) in view of Kohavi et al. (US Pub No. 2009/0063869), as applied to claims 1-2, 4-5, 8-11, 13-14 and 16-34 above and in further view of Diep et al. (US Pub No. 2014/0237261). Regarding claim 6, Kashyap in view of Kohavi teaches the method wherein the files comprise encrypted files (Kohavi, page 5, paragraphs 0107-0108 and page 9, paragraphs 0212-0216; encrypted data units). Kashyap in view of Kohavi does not explicitly teach the method, wherein allowing shared access to the encrypted files comprises, in the first environment, based on detecting a first attempt, at a first of the one or more processes, to make first data available to the one or more processes via the encrypted files, creating a cryptographic key; and encrypting the first data in the encrypted files; based on detecting a second attempt, at a second of the one or more processes, for access to the first data, verifying that the second process is allowed to access the first data; and decrypting the first data for the second process with the cryptographic key. Diep teaches wherein allowing shared access to the encrypted files comprises, in the first environment, based on detecting a first attempt, at a first of the one or more processes, to make first data available to the one or more processes via the encrypted files, creating a cryptographic key; and encrypting the first data in the encrypted files; based on detecting a second attempt, at a second of the one or more processes, for access to the first data, verifying that the second process is allowed to access the first data; and decrypting the first data for the second process with the cryptographic key (Diep, page 1, paragraph 0023, page 8, paragraphs 0095-0100; process key generation request/ first process & write request/ second process). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Kashyap in view of Kohavi with the teachings of Diep to have processes associated with keys to provide the advantage of preventing illicit access to content (Diep, page 1, paragraph 0023). Regarding claim 7, Kashyap in view of Kohavi and in further view of Diep teaches each and every claim limitation of claim 6, however, Diep teaches the method wherein at least one of, verifying that the second process is allowed to access the first data comprises determining that a context of the second process indicates that the second process is allowed to access the first data, wherein the context of the second process comprises at least one of an identifier of the second process, an identifier of the user, an identifier of a process for the second process, and an identifier of a thread for the second process, verifying that the second process is allowed to access the first data is by at least one of a file system hook, a file system filter, and a file system driver in the first environment, and creating the cryptographic key comprises creating the cryptographic key at a hardware component in the first environment, wherein the hardware component comprises at least one of a hardware security module, a trusted platform module, and a secure enclave, wherein decrypting the first data with the cryptographic key comprises decrypting the first data at the hardware component (Diep, page 2, paragraph 0030, page 6, paragraph 0066, page 7, paragraph 0087 and page 9, paragraphs 0108-0109; process key associated with process identifier). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Kashyap in view of Kohavi with the teachings of Diep to have processes associated with keys to provide the advantage of preventing illicit access to content (Diep, page 1, paragraph 0023). Claim(s) 15 is rejected under 35 U.S.C. 103 as being unpatentable over Kashyap et al. (US Pub No. 2017/0180427) in view of Kohavi et al. (US Pub No. 2009/0063869), as applied to claims 1-2, 4-5, 8-11, 13-14, and 16-34 above and in further view of He et al. (US Patent No. 8,826,452). Regarding claim 15, Kashyap in view of Kohavi teaches the each and every claim limitation of claim 14. Kashyap in view of Kohavi does not explicitly teach the method further comprising, based on determining that the process is not allowed to access data for the keyboard capture, erasing all or part of the data of the keyboard capture being communicated to the process, wherein analyzing the keyboard capture comprises identifying hooks used for keyboard capture across the endpoint. He teaches further comprising, based on determining that the process is not allowed to access data for the keyboard capture, erasing all or part of the data of the keyboard capture being communicated to the process, wherein analyzing the keyboard capture comprises identifying hooks used for keyboard capture across the endpoint (He, column 3, lines 55-67). It would have been obvious to one having ordinary skill in the art before the effective filing date of the claimed invention to modify Kashyap in view of Kohavi with the teachings of HE to monitor screen capture and keyboard hooks to provide the advantage of improving data loss prevention (He, column 1, lines 10-25). Prior Art The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Reus et al. (US Pub No. 2013/0160072). Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to SHAQUEAL D WADE whose telephone number is (571)270-0357. The examiner can normally be reached M-F 8:00-5:00. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Catherine Thiaw can be reached at 571-270-1138. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /SHAQUEAL D WADE-WRIGHT/Primary Examiner, Art Unit 2407
Read full office action

Prosecution Timeline

Apr 30, 2025
Application Filed
Aug 12, 2026
Non-Final Rejection mailed — §103, §112 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12743539
SEARCH EXECUTION DEVICE, SEARCH EXECUTION METHOD, COMPUTER READABLE MEDIUM AND SEARCHABLE ENCRYPTION SYSTEM
2y 9m to grant Granted Sep 22, 2026
Patent 12730895
APPARATUSES AND METHODS FOR VERIFICATION OF UPDATED DATA-SET
3y 2m to grant Granted Sep 08, 2026
Patent 12719838
STATISTICALLY PRIVATE OBLIVIOUS TRANSFER FROM CDH
2y 4m to grant Granted Aug 25, 2026
Patent 12705319
METHOD OF INSERTING AUDIO-WATERMARK SPECIALIZED FOR MUSIC USAGE AND NFT AND PROVIDING MUSIC SOURCE
1y 8m to grant Granted Aug 11, 2026
Patent 12695629
AUTHENTICATION METHOD AND APPARATUS
3y 1m to grant Granted Jul 28, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
85%
Grant Probability
99%
With Interview (+18.1%)
2y 4m (~11m remaining)
Median Time to Grant
Low
PTA Risk
Based on 457 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month