Prosecution Insights
Last updated: October 02, 2026
Application No. 19/238,954

Multi-Tenant Cloud to Cloud Incident Routing

Non-Final OA §103
Filed
Jun 16, 2025
Priority
Apr 21, 2020 — CIP of 11/671,433 +3 more
Examiner
OTTO, ALAN
Art Unit
2139
Tech Center
2100 — Computer Architecture & Software
Assignee
Zscaler Inc.
OA Round
1 (Non-Final)
67%
Grant Probability
Favorable
1-2
OA Rounds
2y 1m
Est. Remaining
85%
With Interview

Examiner Intelligence

Grants 67% — above average
67%
Career Allowance Rate
250 granted / 375 resolved
+11.7% vs TC avg
Strong +18% interview lift
Without
With
+17.9%
Interview Lift
resolved cases with interview
Typical timeline
3y 5m
Avg Prosecution
12 currently pending
Career history
395
Total Applications
across all art units

Statute-Specific Performance

§101
6.5%
-33.5% vs TC avg
§103
53.1%
+13.1% vs TC avg
§102
21.9%
-18.1% vs TC avg
§112
13.2%
-26.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 375 resolved cases

Office Action

§103
Detailed Action The instant application having Application No. 19/238,954 has a total of 20 claims pending in the application; there are 2 independent claims and 18 dependent claims, all of which are ready for examination by the examiner. This Office action is in response to the claims filed 6/16/25. Claims 1-20 are pending. NOTICE OF PRE-AIA OR AIA STATUS The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . INFORMATION CONCERNING DRAWINGS Drawings The applicant's drawings submitted 6/16/25 are acceptable for examination purposes. REJECTIONS BASED ON PRIOR ART Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1-3, 6-13 and 16-20 are rejected under 35 U.S.C. 103 as being unpatentable over Chennuru et al. (U.S. Patent No. 9,716,724), herein referred to as Chennuru et al. in view of He et al. (U.S. Patent No. 9,380,075), herein referred to as He et al. and in view of Thampy (U.S. Patent Application Publication No. 2019/0068627), herein referred to as Thampy. Referring to claim 1, Chennuru et al. disclose as claimed, a method for securely transferring Data Loss Prevention (DLP) incident data from a cloud-based DLP system to a tenant's cloud storage account in a multi-tenant environment, the method comprising steps of: detecting a DLP incident by identifying a policy violation and generating an incident event (see col. 5, lines 35-50, where the DLP system detects a violation or non-compliance and may compile a report); and writing DLP incident data associated with the DLP incident into the tenant's public cloud storage account (see col. 3, lines 7-20, where a cloud service may be a public cloud service. See fig. 3, showing the cloud DLP system writing reports and alerts to the enterprise data network). Chennuru et al. disclose the claimed invention except where the tenant’s account is a cloud storage account; and an associated request containing metadata and contextual information for the incident; processing the request, the processing comprising validating the tenant's configuration settings for storage access permissions and target storage details and determining routing information for the tenant's cloud storage account However, He et al. disclose where the tenant’s account is a cloud storage account (see col. 9, lines 23-43, where when a security incident occurs, a security supervisor of a first cloud communicates with a security supervisor of a different cloud and sends information about the security event. When combined with Chennuru et al., which already discloses the tenant using a public cloud account, this would enable security data to be recorded and stored at a tenant’s public cloud storage account). Chennuru et al. and He et al. are analogous art because they are from the same field of endeavor of cloud storage systems (see Chennuru et al., abstract and He et al., abstract, regarding cloud storage systems). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Chennuru et al. to comprise where the tenant’s account is a cloud storage account, as taught by He et al., in order to determine whether prefetched data is used to determine future likelihoods of prefetched data in similar situations being used. This would result in a higher cache hit rate and increased performance. Chennuru et al. and He et al. disclose the claimed invention except for an associated request containing metadata and contextual information for the incident; processing the request, the processing comprising validating the tenant's configuration settings for storage access permissions and target storage details and determining routing information for the tenant's cloud storage account However, Thampy discloses an associated request containing metadata and contextual information for the incident; processing the request, the processing comprising validating the tenant's configuration settings for storage access permissions and target storage details and determining routing information for the tenant's cloud storage account (see para. 185-186, where in response to a detected threat, a cloud seeder process may be invoked which coordinates security and collects registration information from a tenant to connect to a cloud provider. The routing information and tenant’s account would need to be determined in order to connect to the tenant’s cloud storage account. Also see para. 136 and 146, where contextual information about the incident is collected and used to improve security threat predictions) Chennuru et al. and Thampy are analogous art because they are from the same field of endeavor of cloud storage systems (see Chennuru et al., abstract and Thampy, abstract, regarding cloud storage systems). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Chennuru et al. to comprise where the tenant’s account is a cloud storage account, as taught by Thampy, in order to allow for secure monitoring and communication and access to a cloud storage account to store a report if an incident occurs, and that report could be accessed anywhere through the cloud. Claim 11 recites limitations similar to claim 1 and would be rejected using the same rationale. As to claim 2, Chennuru et al., He et al. and Thampy also disclose the method of claim 1, wherein generating the request comprises incorporating additional fields in an Internet Content Adaptation Protocol (ICAP) header (see Chennuru et al., col. 5, lines 50-60, where ICAP protocol is used for communications), the additional fields including customer-specific identifiers, incident severity, file metadata, and a DLP rule that triggered the incident (see Thampy, para. 137-138, where alerts may be sent and contain information about events, including identifiers, category of the event, risk level, security controls or rules for the event and other related metadata). Claim 12 recites limitations similar to claim 2 and would be rejected using the same rationale. As to claim 3, Chennuru et al., He et al. and Thampy also disclose the method of claim 1, further comprising logging transmission details and operational metrics, including timestamps, file sizes, storage locations, and transfer performance metrics for auditing and monitoring purposes (see Thampy, para. 86-92, where data about network activity and application usage is logged, including domain information. See para. 119-120, where file operations are tracked as well as access metrics, application metrics, login/logout statistics, operations, functions, devices used to access applications and files/folders accessed). Claim 13 recites limitations similar to claim 3 and would be rejected using the same rationale. As to claim 6, Chennuru et al., He et al. and Thampy also disclose the method of claim 1, further comprising encrypting all communications between the cloud-based DLP system and the tenant's cloud storage account (see Chennuru et al., col. 1, lines 40-45, where all data between cloud services are encrypted and see Thampy, para. 118, where connection to cloud services is done over an encrypted communication channel). Claim 16 recites limitations similar to claim 6 and would be rejected using the same rationale. As to claim 7, Chennuru et al., He et al. and Thampy also disclose the method of claim 1, wherein the steps ensure compliance with data protection standards by not storing any customer-sensitive data on local or temporary disk storage during processing (see He et al., para. 4, where in a cloud computing environment, applications and data are no longer found on the local computer or on a nearby server, but instead on the cloud). Claim 17 recites limitations similar to claim 7 and would be rejected using the same rationale. As to claim 8, Chennuru et al., He et al. and Thampy also disclose the method of claim 1, wherein the method supports a multi-tenant framework enabling multiple customer configurations, ensuring data segregation such that the DLP incident data from different tenants is independently and securely stored in each tenant's cloud storage account (see Thampy, para. 51, where each tenant may have their own account and receive their own reports, and set different security controls. Also see fig. 1, showing monitoring traffic of different devices. Also see para. 91-92, outlining security policies and configurations for tenants and devices. See He et al., col. 9, lines 23-43, where when a security incident occurs, a security supervisor of a first cloud communicates with a security supervisor of a different cloud and sends information about the security event. When combined with Chennuru et al., which already discloses the tenant using a public cloud account, this would enable security data to be recorded and stored at each tenant’s cloud storage account). Claim 18 recites limitations similar to claim 8 and would be rejected using the same rationale. As to claim 9, Chennuru et al., He et al. and Thampy also disclose the method of claim 1, wherein the detecting comprises: receiving DLP configurations for one or more devices associated with the tenant, wherein the DLP configurations define how exfiltration of sensitive data is protected for the one or more devices; monitoring traffic of the one or more devices; and scanning the traffic of the one or more devices using the DLP configurations for the one or more devices (see Thampy, para. 51, where each tenant may have their own account and receive their own reports, and set different security controls. Also see fig. 1, showing monitoring traffic of different devices. Also see para. 91-92, outlining security policies and configurations for tenants and devices). Claim 19 recites limitations similar to claim 9 and would be rejected using the same rationale. As to claim 10, Chennuru et al., He et al. and Thampy also disclose the method of claim 1, wherein the steps include requesting and obtaining an authorization token using tenant-specific identifiers and routing information, wherein the authorization token grants secured and time-limited access to a designated storage location in the tenant's cloud storage account (see Thampy, para. 185-186, where in response to a detected threat, a cloud seeder process may be invoked which coordinates security and collects registration information from a tenant to connect to a cloud provider. The routing information and tenant’s account would need to be determined in order to connect to the tenant’s cloud storage account. See Chennuru et al., col. 6, lines 33-46, where access is granted to a cloud provider through a time-limited token). Claim 20 recites limitations similar to claim 10 and would be rejected using the same rationale. Claims 4 and 14 are rejected under 35 U.S.C. 103 as being unpatentable over Chennuru et al., He et al. and Thampy, and further in view of Davis (U.S. Patent No. 7,281,030), herein referred to as Davis. As to claim 4, Chennuru et al., He et al. and Thampy disclose the claimed invention except for the method of claim 1, further comprising initiating an automatic retry mechanism for transient errors encountered during the writing into the tenant's cloud storage account. However, Davis discloses initiating an automatic retry mechanism for transient errors encountered during the writing into the tenant's cloud storage account (see para. 20, where read and write retry takes place on transient errors for a storage system). Chennuru et al. and Davis are analogous art because they are from the same field of endeavor of storage systems (see Chennuru et al., abstract and Davis, abstract, regarding storage systems). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Chennuru et al. to comprise initiating an automatic retry mechanism for transient errors encountered during the writing into the tenant's cloud storage account, as taught by Davis, in order to allow operations to finish or resume after a temporary problem. Automatic retry when dealing with transient errors is well known in the art and would be obvious to include with Chennuru et al. Claim 14 recites limitations similar to claim 4 and would be rejected using the same rationale. Claims 5 and 15 are rejected under 35 U.S.C. 103 as being unpatentable over Chennuru et al., He et al. and Thampy, and further in view of Burkitt et al. (U.S. Patent Application Publication No. 2012/0254917), herein referred to as Burkitt et al. As to claim 5, Chennuru et al., He et al. and Thampy also disclose the method of claim 1, wherein the writing includes organizing the DLP incident data within the tenant's cloud storage account using a hierarchical folder structure that categorizes incident data by date, severity, or DLP rule type. However, Burkitt et al. disclose wherein the writing includes organizing the DLP incident data within the tenant's cloud storage account using a hierarchical folder structure that categorizes incident data by date, severity, or DLP rule type (see para. 273, where files in a storage system are organized in a hierarchical folder system that uses date information). Chennuru et al. and Burkitt et al. are analogous art because they are from the same field of endeavor of storage systems (see Chennuru et al., abstract and Burkitt et al., para. 2, regarding storage systems). It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Chennuru et al. to comprise wherein the writing includes organizing the DLP incident data within the tenant's cloud storage account using a hierarchical folder structure that categorizes incident data by date, severity, or DLP rule type, as taught by Burkitt et al., in order to easily retrieve and locate files. Organizing files in a folder system is well known in the art and would be obvious to include with Chennuru et al. Claim 15 recites limitations similar to claim 5 and would be rejected using the same rationale. CLOSING COMMENTS Conclusion a. STATUS OF CLAIMS IN THE APPLICATION The following is a summary of the treatment and status of all claims in the application as recommended by M.P.E.P. 707.07(i): a(1) CLAIMS REJECTED IN THE APPLICATION Per the instant office action, claims 1-20 have received a first action on the merits and are the subject of a first action non-final. b. DIRECTION OF FUTURE CORRESPONDENCES Any inquiry concerning this communication or earlier communications from the examiner should be directed to ALAN OTTO whose telephone number is (571)270-1626. The examiner can normally be reached M-F 8:30AM-5:00PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Hosain Alam can be reached at 571-272-3978. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /A.O/Examiner, Art Unit 2132 /HOSAIN T ALAM/Supervisory Patent Examiner, Art Unit 2132
Read full office action

Prosecution Timeline

Jun 16, 2025
Application Filed
Sep 22, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12664092
METHOD AND SYSTEM FOR MANAGING CACHE DATA BASED ON SCORE
1y 9m to grant Granted Jun 23, 2026
Patent 12625779
AUTOMATED RECONSTRUCTION AND ATTRIBUTION OF DATA MODIFICATIONS
2y 7m to grant Granted May 12, 2026
Patent 12608136
FLASH MEMORY SCHEME CAPABLE OF CONTROLLING FLASH MEMORY DEVICE AUTOMATICALLY GENERATING DEBUG INFORMATION AND TRANSMITTING DEBUG INFORMATION BACK TO FLASH MEMORY CONTROLLER WITH MAKING MEMORY CELL ARRAY GENERATING ERRORS
3y 3m to grant Granted Apr 21, 2026
Patent 12602324
STORAGE CONTROLLER, MEMORY MANAGEMENT METHOD AND STORAGE DEVICE
1y 7m to grant Granted Apr 14, 2026
Patent 12591367
TECHNIQUES FOR LOG ORDERING TO OPTIMIZE WRITE LATENCY IN SYSTEMS ASSIGNING LOGICAL ADDRESS OWNERSHIP
2y 1m to grant Granted Mar 31, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
67%
Grant Probability
85%
With Interview (+17.9%)
3y 5m (~2y 1m remaining)
Median Time to Grant
Low
PTA Risk
Based on 375 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month