DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Amendment / Arguments
Regarding claims rejected under 35 USC 103:
Applicant’s arguments, in view of the amended claim language, have been fully considered and are persuasive. Therefore, the rejection has been withdrawn. However, upon further consideration, a new ground(s) of rejection is made in view of Sabin (US 2010/0154037 A1).
Regarding claims rejected under 35 USC 101:
Applicant's arguments have been fully considered but they are not persuasive.
Applicant first argues that “the amended claims recite receiving data "from a shim application of an endpoint," where the shim application is "inserted into an operational stack of the endpoint via operating system hooks to intercept the action." This is not a mental process. A human analyst cannot insert a shim application into an operating system's operational stack via operating system hooks to intercept application actions. The claims require specific technical operations-intercepting actions via operating system hooks, generating platform identification strings with cryptographic hashes (md5/sha-1), and querying vulnerability databases-that cannot practically be performed in the human mind.”
In response, it is noted that the claim does not require the features that applicant’s argument is based upon (e.g., “a shim application”, “inserting the shim application into an operational stack”, “via operating system hooks to intercept an action”). As per the 35 USC 112(b) rejection below, the shim application, its insertion, and its intercepting are not part of the scope of the claims. The claims are directed to a server apparatus, its method, and the CRM for implementing its method, and the claims’ first step is receiving data from an endpoint (that implemented a shim application as claimed). A human-being could mentally infringe the step of receiving by, for example, reading a display screen with the platform identification string (generating and displayed as per the claimed shim application). Narrowing an object of the limitation instead of the thing doing the function (or the function itself) generally doesn’t aid in overcoming judicial exception 101 rejections. This is easily demonstratable with a single step example that is clearly mentally infringeable by, for example, a human-being reading information (say, a license plate of a vehicle or content on a computer display). Amendments that further describe and narrow the vehicle (in the first case) or the computer screen or computer (in the second case) are irrelevant in overcoming the finding that a human-being can mentally infringe the step by reading the information.
Applicant further argues that “even if some individual limitations could be viewed as abstract, the claims as a whole integrate any such exception into a practical application. The claims recite a specific technical architecture: a server apparatus that receives data from a shim application that intercepts actions via operating system hooks, queries vulnerability databases to determine grayware reputations, and provides response codes and patch notifications.” However, the argued technical architecture is not fully within the claim scope as per the response to arguments above. As such, the claims are not considered to integrate the abstract idea into a practical application.
Applicant further argues that “for example, an executable object called 'process.exe' may not have a single, monolithic reputation assigned to it that either allows all actions or blocks all actions. Rather, each action that 'process.exe' performs may have a separate reputation." As-Filed Specification, paragraph [0016]. This provides an improvement over traditional security architectures that assign monolithic reputations to entire processes.” However, merely assigning a reputation to an object or action is not considered to be addressing a technical problem that requires the functioning of a computer or is intrinsically tied to a technology, other than its being implemented in a computing environment. Thus, there is no finding that this would improve the functioning of a computer itself, or improve another technology or technical field. That is, assigning reputations of different granularities to different objects or actions is a non-technical solution that addresses a non-technical problem that transcends computing and applies to, e.g., people, countries, businesses, and so forth. It just so happens that applicant’s invention is using computers to implement this solution because applicant’s invention is using computers as a tool to execute processes.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1, 6, 10, 21-22, 24-25, 27-29, 31-32, 34-36, and 38-40 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Example independent claim 1 recites “an identifier for an action of the application intercepted by the shim application” and “the shim application inserted into an operational stack of the endpoint via operating system hooks to intercept the action,” which render the claim indefinite because it is not clear whether these claim limitations are part of the claim scope. Specifically, the limitations are drawn to past tense events that appear to have taken place before the “receive,” “query,” “provide,” and “provide” steps of the claim. The claim is drawn to the shim application positively providing a platform identification string and receiving responses, but it does not actually positively recite the interception or insertion of the shim application. As such, a person of ordinary skill in the art could not interpret the metes and bounds of the claim so as to understand how to avoid infringement.
Independent claims 10 and 25 recite substantially similar subject matter and are therefore rejected under the same analysis.
The dependent claims do not rectify this issue and are therefore likewise rejected.
Claim 7 is rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention. Claim 7 recites “further instruct a shim agent of the endpoint,” which renders the claim indefinite because it is not clear whether “a shim agent of the endpoint” is referring to “a shim application of an endpoint” in the parent claim. Or whether it is referring to a different entity.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1, 6, 10, 21-22, 24-25, 27-29, 31-32, 34-36, and 38-40 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Note that the courts do not distinguish between mental processes that are performed entirely in the human mind and mental processes that require a human to use a physical aid (e.g., pen and paper or a slide rule) to perform the claim limitation (refer to MPEP 2106.04(a)(2)).
Example independent claim 1 recites the following abstract idea limitations:
receive, from an [entity], a platform identification string comprising a name of an application, an identifier for an action of the application intercepted by the [entity], and at least one of an md5 of the application or a sha-1 of the application (observation as part of performing a mental process—e.g., an analyst receiving information for review from an entity, the information having a particular format);
query a vulnerability [information repository] and platform identification string [information repository] to procure an application-specific grayware reputation for the action, wherein the application-specific grayware reputation for the action represents a likelihood that the action, if taken by the application on the [entity], would be unwanted (evaluation as part performing a mental process—e.g., the analyst looking up reference information from stored information);
provide to the [entity] a response code for the action (delivering work as part of certain methods of organizing human activity—e.g., the analyst delivering the result of their evaluation to the requesting entity);
provide a notification to the [entity] that an update or patch is available (delivering work as part of certain methods of organizing human activity—e.g., the analyst delivering the result of their evaluation to the requesting entity) to repair a vulnerability of the application related to the action (the intended use of the update or patch).
Example independent claim 1 recites the following limitations which may comprise additional elements that are sufficient to amount to significantly more than the abstract idea: “A server apparatus, comprising: a hardware platform comprising a processor circuit and a memory; and instructions encoded within the memory to instruct the processor circuit to [perform the abstract idea limitations];” the entity further comprising “a shim application of an endpoint;” each respective information repository further comprising a “database;” “the shim application inserted into an operational stack of the endpoint via operating system hooks to intercept the action.”
With respect to step 2A, the judicial exception is not integrated into a practical application because it is drawn to receiving and looking up information at a high level of generality, and because adding the words "apply it" (or an equivalent) with the judicial exception, or mere instructions to implement an abstract idea on a computer, or merely using a computer as a tool to perform an abstract idea is not considered to be sufficient—see MPEP 2106.05(f). For instance, the claim is drawn to receiving a string specifying an action, looking up the action in an information repository, determining whether an update exists, and providing notice of the lookup and determination results. This may be performed by a human analyst with pen and paper analogues. Further, the claim does not actually include performing the action by the application. A computer and application performing the action is outside of the scope of the claim language. Likewise, the shim application performs the interception and is described as having been inserted into an operational stack in the past tense. As such, the actual interception and use of the shim application beyond reporting data is outside of the claim scope. Additionally, the determination of whether an update exists may merely be the analyst relying on their own personal knowledge.
Where the claim recites a “server apparatus, comprising: a hardware platform comprising a processor circuit and a memory; and instructions encoded within the memory to instruct the processor circuit to [perform the abstract idea limitations],” “endpoint,” and “database,” these are considered to merely require implementing the abstract idea on a base level computer (i.e., the communicating entity and analyst being computerized and the computers being base level computers consisting of a processor, memory, and database). No particular computer or database technology is specified beyond the generic terminology.
As such, the invention is addressing a problem that transcends computing (performing information lookup and providing results to a requesting entity) rather than improving the functioning of a computer, or an improvement to other technology or a technical field.
With respect to step 2B, the claim does the claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception because adding the words "apply it" (or an equivalent) with the judicial exception, or mere instructions to implement an abstract idea on a computer, or merely using a computer as a tool to perform an abstract idea is not considered to be sufficient-see MPEP 2106.05(f). In this case, the “server apparatus, comprising: a hardware platform comprising a processor circuit and a memory; and instructions encoded within the memory to instruct the processor circuit to [perform the abstract idea limitations]” and “database” may be interpreted as any generic base level computer (e.g., processor and memory) and database for storing information as part of performing the judicial exception. Merely performing the judicial exception using a base level computer and basic computing components is not considered to be sufficient. Further, the shim application is only utilized for reporting data in the claim scope. The interception and installation of the shim application are outside of the claim scope. Thus, a generic computer may implement merely reporting data.
Independent claims 10 and 25 are substantially similar to independent claim 1, and are therefore likewise rejected under the same analysis.
Regarding dependent claim 6, it recites the following abstract idea limitations: wherein the instructions are further to receive a confirmation that the endpoint has installed an updated application or applied a requested patch, and to update a platform identification string for the endpoint (observation and evaluation as part of a mental process—e.g., the analyst receives additional information and updates their stored information in response to evaluation). As such, it is rejected under the same analysis.
Regarding dependent claim 21, it recites the following abstract idea limitations: wherein the response code indicates locally modifying network communication for the application comprising directing the action to a local circular buffer (adding insignificant extra-solution activity to the judicial exception—i.e., merely further specifying the information sent as part of the analyst delivering the result of their evaluation). Claim 21 does not actually comprise performing “modifying network communication for the application comprising directing the action to a local circular buffer.” Instead, it concerns providing information about doing so, where doing so is outside of the claim scope. Therefore, claim 21 is rejected under the same analysis.
Regarding dependent claims 22, 24, 27-29, 31-32, 34-36, and 38-40, they are likewise rejected under the same analysis because they merely further specify the format of the information (i.e., the string having additional information; the order it appears in the string).
Dependent claims 2 and 7 are not rejected as being drawn to an abstract idea without significantly more.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1-2, 10, and 25 is/are rejected under 35 U.S.C. 103 as being unpatentable over Harris (US 9,967,264 B2) in view of Pham (US 2005/0182958 A1) and Sabin (US 2010/0154037 A1).
Regarding claim 1, Harris discloses: A server apparatus (e.g., threat management facility 204 in FIG. 2 of Harris), comprising:
a hardware platform comprising a processor circuit and a memory; and
instructions encoded within the memory to instruct the processor circuit to:
receive, from [an agent] of an endpoint (e.g., endpoint 202 in FIG. 2 of Harris), a platform identification string comprising a name of an application (e.g., Col. 9, Ll. 62-64 and Col. 60, Ll. 36-48 of Harris concerning an object and descriptor such as a name), an identifier for an action of the application intercepted by the [agent];
Refer to at least Col. 35, Ll. 3-31 of Harris concerning accessing a network resource as an exemplary “action.”
Refer to at least 1202-1204 in FIG. 12 and Col. 55, Ll. 3-21 of Harris with respect to detecting an action by an application at an endpoint, collecting descriptions, and providing an indication of compromise (IOC) transmission to the threat management facility.
query a vulnerability database and platform identification string database to procure an application-specific grayware reputation for the action, wherein the application-specific grayware reputation for the action represents a likelihood that the action, if taken by the application on the endpoint, would be unwanted;
Refer to at least 1206 in FIG. 12 and Col. 55, Ll. 22-38 of Harris with respect to the threat management facility looking up a reputation score for the particular action / IOC.
Refer to at least Col. 55, Ll. 39-51 of Harris with respect to the reputation score being any suitable score for any level of granularity (e.g., 1-100).
Refer to at least FIG. 16 of Harris with respect to unknown (grayware) reputations and application-specificity.
[generate] a response code (e.g., colors as response codes according to at least [0074] of the instant specification) for the action;
Refer to at least Col. 61, Ll. 19-Col. 62, Ll. 20 of Harris with respect to an evaluation tool on the threat management facility, which may generate a score or color for IOCs.
provide a notification to the endpoint that an update or patch is available to repair a vulnerability of the application related to the action.
Refer to at least Col. 16, Ll. 35-43 of Harris with respect to the threat management facility providing updates, e.g., in reaction to a threat notice. Further see at least Col. 19, Ll. 1-17 of Harris with respect to providing updated definition files to a client facility responsive to a received malicious code alert.
Refer to at least Col. 62, Ll. 34-37 of Harris with respect to a determination to fix the object responsive to the evaluation. Further refer to at least Col. 10, Ll. 15-19 of Harris, wherein the threat management facility may provide for patch management for applications to reduce vulnerability to threats. Additionally, at least Col. 18, Ll. 54-58 of Harris discloses that as threats are identified and characterized, the threat management facility may create definition updates to detect and remediate applications.
Refer to at least Col. 18, Ll. 20-53 of Harris with respect to pushing information from the threat management facility (e.g., updates).
Although Harris teaches a descriptor for the object as part of the IOC, it does not appear to specify: the platform identification string further comprising at least one of an md5 of the application or a sha-1 of the application. Harris also does not specify: the agent further comprising a shim application; the shim application inserted into an operational stack of the endpoint via operating system hooks to intercept the action; generating a response code for the action further comprising: provide to the endpoint a response code. However, Harris in view of Pham discloses: the platform identification string further comprising at least one of an md5 of the application or a sha-1 of the application;
Refer to at least the last paragraph in section 5 of Aslam and to section 3.2 of Aslam with respect to a suggestion to include a reference hash in a CPE string. The following example string is provided: “cpe:/a:software:vendor:version:sha1.”
generating a response code for the action further comprising: provide to the endpoint a response code.
Refer to at least [0045] of Pham with respect to a request response containing an enabled, qualified enable, or denied status value which is returned.
The teachings of Pham likewise concern querying a server for policy information associated with application operations, and are considered to be within the same field of endeavor and combinable as such.
Therefore it would have been obvious to one of ordinary skill in the art before the filing date of Applicant’s invention to modify the teachings of Harris to further implement response codes for at least the purpose of reducing required network bandwidth (i.e., sending a simple response rather than detailed policy and enforcement information). Further, the substitution of one known element for another would have yielded predictable results to one of ordinary skill in the art at the time (i.e., the type of hash within the CPE string).
Harris-Pham does not specify: the agent further comprising a shim application; the shim application inserted into an operational stack of the endpoint via operating system hooks to intercept the action. However, Harris-Pham in view of Sabin discloses: the agent further comprising a shim application; the shim application inserted into an operational stack of the endpoint via operating system hooks to intercept the action.
Refer to at least [0024]-[0029] and [0080] of Sabin with respect to a shim the hooks into the network OS to intercept application actions (e.g., communications) and obtain information (e.g., process ID) for further reporting.
The teachings of both Harris-Pham and Sabin concern intercepting application actions using an OS embedded agent and are considered to be within the same field of endeavor and combinable as such.
Therefore it would have been obvious to one of ordinary skill in the art before the filing date of Applicant’s invention to modify the teachings of Harris-Pham to further implement a shim hooked into the OS because the substitution of one known element for another would have yielded predictable results to one of ordinary skill in the art at the time (i.e., the cited portions of Sabin concerning substitution of, e.g., driver and shim).
Regarding claim 2, it is rejected for substantially the same reasons as claim 1 above (i.e., the citations).
Regarding independent claim 10, it is substantially similar to independent claim 1 above, and is therefore likewise rejected (i.e., the citations and obviousness rationale).
Regarding independent claim 25, it is substantially similar to independent claim 1 above, and is therefore likewise rejected (i.e., the citations and obviousness rationale).
Claim(s) 21 is/are rejected under 35 U.S.C. 103 as being unpatentable over Harris-Pham-Sabin as applied to claims 1-2, 10, and 25 above, and further in view of Zhu (US 2013/0036470 A1).
Regarding claim 21, Harris-Pham-Sabin does not disclose: wherein the response code indicates locally modifying network communication for the application comprising directing the action to a local circular buffer. However, Harris-Pham-Sabin in view of Zhu discloses: wherein the response code indicates locally modifying network communication for the application comprising directing the action to a local circular buffer.
Refer to at least the abstract and FIG. 3A-B of Zhu with respect to initializing a circular buffer to intercept packets for network filtering.
The teachings of Harris-Pham-Sabin and Zhu concern malware and malicious traffic detection and filtering, and are considered to be within the same field of endeavor and combinable as such. Further, at least [0013] of Zhu implies interoperability with a firewall (e.g., the firewall of Harris).
Therefore it would have been obvious to one of ordinary skill in the art before the filing date of Applicant’s invention modify the teachings of Harris-Pham-Sabin to include utilizing a circular buffer for filtering network traffic for at least the purpose of increasing performance (e.g., [0008] of Zhu).
Claim(s) 6-7 is/are rejected under 35 U.S.C. 103 as being unpatentable over Harris-Pham-Sabin as applied to claims 1-2, 10, and 25 above, and further in view of Chen (US 2016/0092190 A1).
Regarding claim 6, Harris-Pham-Sabin does not disclose: wherein the instructions are further to receive a confirmation that the endpoint has installed an updated application or applied a requested patch, and to update a platform identification string for the endpoint. However, Harris-Pham-Sabin in view of Chen discloses: wherein the instructions are further to receive a confirmation that the endpoint has installed an updated application or applied a requested patch, and to update a platform identification string for the endpoint.
Refer to at least [0074]-[0076] and FIG. 4 of Chen with respect to logging application installation by a user.
The teachings of Harris-Pham-Sabin and Chen concern inspecting and remediating applications and are considered to be within the same field of endeavor and combinable as such.
Therefore it would have been obvious to one of ordinary skill in the art before the filing date of Applicant’s invention to modify the teachings of Harris-Pham-Sabin to include update confirmation and logging for at least the purpose of providing correct information in later requests as per at least FIG. 4 of Chen (i.e., the next request to the server would have correctly updated information for the application at issue).
Regarding claim 7, Harris-Pham-Sabin-Chen discloses: The server apparatus of claim 6, wherein the instructions are further to instruct a shim agent of the endpoint to monitor the updated or patched application.
Refer to at least FIG. 3, [0051], and [0054] of Chen with respect to a client installed on the mobile device, the client configured for downloading and reinstalling applications.
Refer to at least FIG. 3, [0049], and [0052] of Chen with respect to the client and its monitoring module.
Therefore it would have been obvious to one of ordinary skill in the art before the filing date of Applicant’s invention modify the teachings of Harris-Pham-Sabin to include a patching client because the substitution of one known element for another would have yielded predictable results to one of ordinary skill in the art at the time (i.e., the implementation of pushing a patch to an endpoint).
Claim(s) 22, 24, 27-29, 31-32, 35-36, and 38-40 is/are rejected under 35 U.S.C. 103 as being unpatentable over Harris-Pham-Sabin as applied to claims 1-2, 10, and 25 above, and further in view of Aslam ("Continuous Security Evaluation and Auditing of Remote Platforms by Combining Trusted Computing and Security Automation Techniques").
Regarding claim 22, Harris-Pham-Sabin does not disclose: wherein the platform identification string further comprises an identifier of a version of the application. However, Harris-Pham-Sabin in view of Aslam discloses: wherein the platform identification string further comprises an identifier of a version of the application.
Refer to at least “Step 2 – Vulnerability Assessment” and the last paragraph in section 5 of Aslam with respect to version information as part of the CPE string.
The teachings of Aslam likewise concern a remote verifier and software security, and are considered to be within the same field of endeavor and combinable as such.
Therefore it would have been obvious to one of ordinary skill in the art before the filing date of Applicant’s invention to modify the teachings of Harris-Pham-Sabin to further include version information as part of the CPE string because particular known technique was recognized as part of the ordinary capabilities of one skilled in the art (i.e., it is part of the CPE standard and naming convention).
Regarding claims 24 and 27, they are substantially similar to claim 22 above, and are therefore likewise rejected.
Regarding claim 28, Harris-Pham-Sabin discloses: The server apparatus of claim 22, wherein the identifier of the version of the application precedes, in the platform identification string, the at least one of the md5 or the sha-1.
Refer to at least the last paragraph in section 5 of Aslam and to section 3.2 of Aslam with respect to example string “cpe:/a:software:vendor:version:sha1.” The version element is before the sha1 element.
This claim would have been obvious for substantially the same reasons as claims 1 and 22 above.
Regarding claim 29, Harris-Pham-Sabin discloses: The server apparatus of claim 1, wherein the platform identification string further comprises a vendor name of the application, and the vendor name precedes, in the platform identification string, the name of the application.
Refer to at least “Step 2 – Vulnerability Assessment” of Aslam with respect to example string “cpe:/a:google:chrome:27.0.1453.112.” The vendor name element (google) precedes the application name element (chrome).
This claim would have been obvious for substantially the same reasons as claims 1 and 22 above.
Regarding claims 31-32 and 35-36, they are substantially similar to claims 28-29 above, and are therefore likewise rejected.
Regarding claim 38, Harris-Pham-Sabin discloses: The server apparatus of claim 28, wherein the identifier of the version of the application is adjacent, in the platform identification string, to the name of the application.
See “cpe:/a:google:chrome:27.0.1453.112” in 4.2 of Aslam, where the version value “27.0.1453.112” is adjacent to the name of the application “chrome.”
This claim would have been obvious for substantially the same reasons as claims 1 and 22 above.
Regarding claims 39-40, they are substantially similar to claim 38 above, and are therefore likewise rejected.
Claim(s) 34 is/are rejected under 35 U.S.C. 103 as being unpatentable over Harris-Pham-Sabin as applied to claims 1-2, 10, and 25 above, and further in view of Nemcek (“Analysis of Malware Classification Schemas”).
Regarding claim 34, Harris-Pham-Sabin does not disclose: wherein the CPE-like string further comprises the md5 and the sha-1, and the md5 is adjacent, in the CPE-like string, to the sha-1. However, Harris-Pham-Sabin in view of Nemcek discloses: wherein the CPE-like string further comprises the md5 and the sha-1, and the md5 is adjacent, in the CPE-like string, to the sha-1.
Refer to at least pages 75-76 of Nemcek with respect to “<File0bj:Hashes> “ including an MD5 hash and a SHA1 hash.
The teachings of Nemcek likewise relate to malware classification schemas and semantics, and are considered to be within the same field of endeavor and combinable as such.
Therefore it would have been obvious to one of ordinary skill in the art before the filing date of Applicant’s invention modify the teachings of Harris-Pham-Sabin to include both sha-1 and md5 signatures because all of the claimed elements were known in the prior art (md5 and sha-1 algorithms and using the digests as signatures) and one skilled in the art could have combined the elements as claimed by known methods with no change in their respective functions (concatenating additional elements in the string as needed, using colon/semicolon according to the standard), and the combination would have yielded predictable results to one of ordinary skill in the art at the time (a CPE string with given optional/extended elements).
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to VADIM SAVENKOV whose telephone number is (571)270-5751. The examiner can normally be reached 12PM-8PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey L Nickerson can be reached at (469) 295-9235. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/Jeffrey Nickerson/Supervisory Patent Examiner, Art Unit 2432
/V.S/Examiner, Art Unit 2432