Prosecution Insights
Last updated: October 02, 2026
Application No. 19/219,811

REAL-TIME METADATA DRIVEN VIDEO DATA LOSS PREVENTION (vDLP)

Non-Final OA §103
Filed
May 27, 2025
Priority
Jan 31, 2024 — continuation of 12/316,647
Examiner
BROWN, ANTHONY D
Art Unit
Tech Center
Assignee
NetSkope Inc.
OA Round
1 (Non-Final)
85%
Grant Probability
Favorable
1-2
OA Rounds
1y 4m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 85% — above average
85%
Career Allowance Rate
745 granted / 872 resolved
+25.4% vs TC avg
Strong +15% interview lift
Without
With
+15.1%
Interview Lift
resolved cases with interview
Typical timeline
2y 8m
Avg Prosecution
21 currently pending
Career history
892
Total Applications
across all art units

Statute-Specific Performance

§101
15.4%
-24.6% vs TC avg
§103
51.5%
+11.5% vs TC avg
§102
17.1%
-22.9% vs TC avg
§112
5.4%
-34.6% vs TC avg
Black line = Tech Center average estimate • Based on career data from 872 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Information Disclosure Statement The information disclosure statement (IDS) submitted on 8/7/2025 was filed after the mailing date of the application on 8/7/2025. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer. Double Patenting Claims 2, 9 and 16 are rejected on the ground of non statutory double patenting as being unpatentable over claims 1, 8 and 15 of U.S. Patent No. 12316647. Although the claims at issue are not identical, they are not patentably distinct from each other because the limitations in each claim set relate to the same concept. US Patent 12316647 19/219,811 A video data loss prevention (vDLP) system that uses machine-learning for protection against data exfiltration of sensitive content across a plurality of tenants in a cloud-based network, the vDLP system comprises: a tenant of the plurality of tenants in the cloud-based network, the tenant includes a plurality of end-user devices; and a vDLP server operable to: intercept traffic at an application layer of the cloud-based network; receive a video file from traffic within the cloud-based network, wherein a viewer for the video file is remote from the cloud-based network; recognize text of audio and a plurality of frames extracted from the video file using a machine-learning engine; analyze the plurality of frames and text for the video file using a plurality of machine-learning classifiers; enforce a plurality of policies against the plurality of machine-learning classifiers for protection against data exfiltration of the sensitive content in the video file, wherein the machine learning classifiers are used to recognize the sensitive content and unauthorized data and appropriately handle the sensitive content according to the plurality of policies; and in response to enforcing the plurality of policies, send a notification away from the cloud-based network upon detection of violation of a policy of the plurality of policies. A video data loss prevention (vDLP) system that enforces policies based on metadata tags in real-time without proxy deployment, the vDLP system comprises: a vDLP server operable to: monitor access attempt by an external user to a sensitive document hosted in a cloud environment; extract and interpret the metadata tags of the sensitive document; apply real-time access control policies based on the metadata tags, wherein the application of the real-time access control policies includes the vDLP server further operable to determine compilation of the external user access with the real-time access control policies based on the metadata tags, wherein the real-time access control policies comprise access control based on the metadata tags assigned to the sensitive document; detect violation of the policies; and block access to the external user in real-time based on the detection of the violation of the policies. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 2-21 are rejected under 35 U.S.C. 103 as being unpatentable over Kundu (US Patent Pub. 2019/0044945) in view of Bonczar (US Patent Pub. 2021/0021572). As per claims 2, 9 and 16: Kundu discloses a video data loss prevention (vDLP) system that enforces policies based on metadata tags in real-time without proxy deployment, the vDLP system comprises (see abstract): a vDLP server operable to (Paragraph 21; In complex distributed cloud environments e.g., VM-based environments), end-users send requests to access restricted resources within a target server): monitor access attempt by an external user to a sensitive document hosted in a cloud environment (Paragraph 49; The communications facilitated between hypervisors can be monitored and examined in real-time by system management module 110. System management module 110 recognizes the identity of entities associated with processes attempting to access resources on a virtual machine (e.g. processes 105A-C) and whether the resources are restricted or not restricted. The IP address is used as the identifier of the USER ID); extract and interpret the metadata tags of the sensitive document (Paragraph 69-72; In an exemplary embodiment, system management module 110 invokes one or more hypervisors to perform the operational steps depicted in flowchart 800 by transmitting non-transitory signals. More specifically, system management module 110 invokes a hypervisor to: [0070] Receive an out-of-band message from another hypervisor in step 805; [0071] Extract the information of the source IP, port (e.g., ports 510A and 510B in FIG. 5), timestamp (e.g., function 440 in FIG. 4), protocol, and message size (in terms of amount of memory the message takes up) in step 810; and [0072] Storing the extracted information (from step 805) in a metadata record queue (e.g., program 610 in FIG. 6) in step); However, Kundu does not specifically disclose apply real-time access control policies based on the metadata tags, wherein the application of the real-time access control policies includes the vDLP server further operable to determine compilation of the external user access with the real-time access control policies based on the metadata tags, wherein the real-time access control policies comprise access control based on the metadata tags assigned to the sensitive document; detect violation of the policies; and block access to the external user in real-time based on the detection of the violation of the policies (See Bonczar; Paragraph 42; provide a level of security through the application of security rules by the intrusion detection and prevention system 109 and the real-time and automatic monitoring of network traffic on behalf of the endpoint device 102, the functionality of the security server 106a may be somewhat limited in that the security server 106a will typically only have access to the data addressed to an endpoint device 102 that connected directly to the security server 106a. In an embodiment in which there are a plurality of endpoint devices and endpoint security servers in the network 104a, the security server 106a will not typically have sufficient data to identify threats and attacks across the network 104a). Therefore, it would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains, having the teachings of Kundu in view of Bonczar in it’s entirety, to modify the technique of Kundu for thwarting attempts at the unauthorized access to the restricted resources within the target server by adopting Bonczar's teaching for automatically securing endpoint device data communications. The motivation would have been to improve Real Time metadata driven VDLP. As per claims 3, 10 and 17: The vDLP system of claim 2, wherein access to the external user is blocked in real-time without having to deploy a proxy (See Kundu; Paragraph 66 determining that the attempt to access the restricted resource is not authorized, Paragraph 69-72; In an exemplary embodiment, system management module 110 invokes one or more hypervisors to perform the operational steps depicted in flowchart 800 by transmitting non-transitory signals. More specifically, system management module 110 invokes a hypervisor to: [0070] Receive an out-of-band message from another hypervisor in step 805). As per claims 4, 11 and 18: The vDLP system of claim 2, wherein the real-time access control policies based on the metadata tags are applied on documents using the metadata tags (See Kundu; Paragraph 36; adds metadata that indicates the identity of the original requester is. Policy enforcer (e.g., access control units 215A-B) is a component of a hypervisor which is responsible for allowing or disallowing the READ system call based on a configured security policy). As per claims 5 and 12: The vDLP system of claim 2, wherein the real-time access control policies based on the metadata tags exclude content-based policies such as a data-identifier, a keyword, and a regular expression (See Kundu; Paragraph 37; the information contained within the metadata is delivered to hypervisor 205A from hypervisor 205B through the message enricher in hypervisor 205B. The configured security policy indicates the conditions and entities which are granted permission to access and not granted permission to access resources on a virtual machine). As per claims 6, 13 and :The vDLP system of claim 2, wherein monitoring activity of external users comprises intercepting synchronous events from Office 365ᵀM events (See Bonczar; Paragraph 27; The database 103 may be an ODBC-compliant database. For example, the database 103 may be provided as an ORACLE database, manufactured by Oracle Corporation of Redwood Shores, Calif. In other embodiments, the database 103 can be a Microsoft ACCESS database or a Microsoft SQL server database, manufactured by Microsoft Corporation of Redmond, Wash.). As per claims 7, 14 and 20: The vDLP system of claim 2, wherein the metadata tags comprise tenant-specific policy labels stored in a meta database (See Kundu; Paragraph 30; database). As per claims 8, 15 and 21: The vDLP system of claim 2, further comprises a data loss prevention (DLP) engine configured to: detect a policy violation; and transmit an event to an event forwarder, wherein the event forwarder is configured to communicate the policy violation to a management plane for further incident handling (See Kundu; Paragraph 24; security incident arises when a process, among the one or more processes (e.g., processes 105A-C), on a first virtual machine attempts to access a sensitive/restricted resource on the second virtual machine. In other embodiments, there are threat models which are different from the setup of processes 105A-C; components 125A-D; message queue 130; database 135; key-value stores 140A-B; and message 145, as depicted in FIG. 1, which are compatible with system management module 110). detect unusual activity from the external user by applying a machine learning classifier, wherein the machine learning classifier is a pre-trained model that is customizable to tenant- specific patterns of behavior; retrieve user-specific data loss prevention policies associated with a tenant (See Bonczar; Paragraph 47; the malicious traffic patterns prevention engine compares destination port information in the log files to its records of standard behavior for communication protocols. If the inspected destination port information deviates from its standard behavior, a rule is written to block/drop the destination traffic. The rule is then loaded on all security servers); Relevant Prior Art References The following prior art is cited as being of interest to the claimed invention but has not been applied in any of the current rejections. Ng et al.- US Patent Publication 2016/0248800- the prior art teaches techniques for cyber vulnerability. Findlay et al.- US Patent Pub. 20170346846 - the prior art teaches techniques for security threat information gathering and incident reporting. Dotan et al. – US Patent Pub. 2016/0212168 - the prior art teaches techniques for managing multiple security devices in customer datacenter. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to ANTHONY D BROWN whose telephone number is (571)270-1472. The examiner can normally be reached 730-330pm. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Linglan Edwards can be reached at 5712705440. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /ANTHONY D BROWN/Primary Examiner, Art Unit 2408
Read full office action

Prosecution Timeline

May 27, 2025
Application Filed
Aug 26, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12750370
Systems and methods for enforcing policy based on assigned user risk scores in a cloud-based system
2y 7m to grant Granted Sep 29, 2026
Patent 12750238
FAST SIGNATURE GENERATION AND VERIFICATION
2y 0m to grant Granted Sep 29, 2026
Patent 12744795
REMOTE RECOVERY AND RE-ESTABLISHMENT OF IDENTITY FOR NETWORK DEVICES WITH EXPIRED AUTHENTICATION VIA POISONED NETWORK SERVICES
2y 3m to grant Granted Sep 22, 2026
Patent 12731200
DATA MANAGEMENT METHOD AND APPARATUS
2y 2m to grant Granted Sep 08, 2026
Patent 12712917
ENFORCING SECURITY POLICIES AND ATTESTATION ON EDGE INFRASTRUCTURE
2y 4m to grant Granted Aug 18, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
85%
Grant Probability
99%
With Interview (+15.1%)
2y 8m (~1y 4m remaining)
Median Time to Grant
Low
PTA Risk
Based on 872 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month