Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This is responsive to amendment filed on 1/22/26. Claims 1, 3-18 and 20-21 are pending.
Response to Amendment
Claims 1 and 13 are amended. Claims 2 and 19 are cancelled. Claims 1, 3-18 and 20-21 are pending.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1 and 13 rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claims 1 and 13 recites the limitation "….with the predefined mark and… There is insufficient antecedent basis for this limitation in the claim.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1, 3-18 and 20-21 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Although claims 1, 3-18 and 20-21 fall under at least one of the four statutory categories, it should be determined whether the claim wholly embraces a judicially recognized exception, which includes laws of nature, physical phenomena, and abstract ideas, or is it a particular practical application of a judicial exception (See MPEP 2106 I and II).
Claims 1, 3-18 and 20-21 are directed to a judicial exception (i.e., a law of nature, natural phenomenon, or abstract idea) without significantly more.
Part I: Step 2A, Prong One: Identify the Abstract Idea
Under step 2A, Prong One of the Alice framework, the claims are analyzed to determine if the claims are directed to a judicial exception. MPEP §2106.04(a). The determination consists of a) identifying the specific limitations in the claim that recite an abstract idea; and b) determining whether the identified limitations fall within at least one of the three subject matter groupings of abstract ideas (i.e., mathematical concepts, mental processes, and certain methods of organizing human activity). See 2019 Revised Patent Subject Matter Eligibility Guidance (“PEG” 2019 Revised Patent Subject Matter Eligibility Guidance, 84 Fed. Reg. No. 4, 50-57 (Jan. 7, 2019)).
The identified limitations of independent claims 1, 13, 21 recite:
Claim 21. A method for indicating a use of an illicit IP address in a local communication network, the local communication network being connected to another communication network by means of a router, wherein the method comprises the steps, performed by the router, of:
receiving a packet from at least one device belonging to the local communication network, said received packet comprising an illicit source IP address;
generating an error message packet and marking the error message packet with a predefined mark (a person writing out a notice i.e. an observation, evaluation, judgment, opinion” which could be performed as a mental process. See MPEP § 2106.04(a)(2)(III)(A).); and
returning the marked error message packet to the at least one device using an additional routing table redirecting each packet to the local communication network and a routing rule applying the additional routing table to each packet marked with the predefined mark (a person observing that an entry is not yet present in a list and then writing down, using pen and paper, an identifier, a starting count, and a time of receipt i.e. an observation, evaluation, judgment, opinion” which could be performed as a mental process. See MPEP § 2106.04(a)(2)(III)(A).);
recording in a table, referred to as an illicit IP address table, an identifier of the device using the illicit source IP address, in association with a received-packet counter initialised to an initial value, and in association with a time of reception of the received packet, referred to as a first reception time, if the identifier is absent from the table of illicit IP addresses (a person observing that an entry is not yet present in a list and then writing down, using pen and paper, an identifier, a starting count, and a time of receipt i.e. an observation, evaluation, judgment, opinion” which could be performed as a mental process. See MPEP § 2106.04(a)(2)(III)(A).);
updating the table of illicit IP addresses if the identifier of the device is present in the table of illicit IP addresses, wherein a first period being defined with a first predefined duration, the first period being counted as from a time of disconnection of said device, wherein a second period being defined with a second predefined duration, the second predefined duration being shorter than the first predefined duration and terminating at the same time as the first period, and wherein updating the table of illicit IP addresses comprises incrementing the received-packet counter for each packet received during the second period, if the time of disconnection of the device is given in the table of illicit IP addresses (counting/tallying occurrences during a defined time window and comparing time periods. Counting, tallying, and comparing durations (the “first period,” “second period,” and their relative lengths) are mental evaluations and simple mathematical operations i.e an observation, evaluation, judgment, opinion” which could be performed as a mental process and/or mathematical relation. See MPEP § 2106.04(a)(2)(III)(A).); and
preventing, during a configured quarantine duration, any communication with the device when the first period has elapsed, if a time of disconnection of a network interface of the device is given in the table, and if the received-packet counter is different from the initial value (an observation, evaluation, judgment, opinion” which could be performed as a mental process. See MPEP § 2106.04(a)(2)(III)(A).),
wherein the configured quarantine duration either: increases at each new quarantine, a quarantine being a period during which any communication with the device prevented, or is equal to n*Dt where n is a number of quarantines and Dt is an initial quarantine duration (comparing the counter to the initial value and evaluating whether a period has elapsed) and forming a decision, and further recites a mathematical concept in that the quarantine duration is expressly defined as being “equal to n*Dt where n is a number of quarantines and Dt is an initial quarantine duration” (a mathematical relationship/calculation), or as a value that “increases at each new quarantine i.e. an observation, evaluation, judgment, opinion” which could be performed as a mental process and/or Mathematical relationships See MPEP § 2106.04(a)(2)(III)(A).).
The claim limitations fall within the Mental concepts – an observation, evaluation, judgment, opinion” which could be performed as a mental process and/or Mathematical relationships (see MPEP § 2106.04(a)(2), subsection I) groupings of abstract ideas. The performance of the claim limitations using generic computing components (i.e., router) does not preclude the claim limitations from being in the certain Mental concepts – an observation, evaluation, judgment, opinion” which could be performed as a mental process and/or Mathematical relationships. Under its broadest reasonable interpretation when read in light of the specification, the limitation in bold encompasses mental processes practically performed in the human mind by observation, evaluation, judgment, and opinion and/or mathematical relations. See MPEP 2106.04(a)(2), subsection III. Thus, the claimed invention is directed to a judicial exception.
Part I: Step 2A, prong two: additional elements that integrate the judicial exception into a practical application
Under step 2A, Prong Two of the Alice framework, the claims are analyzed to determine whether the claims recite additional elements that integrate the judicial exception into a practical application. In particular, the claims are evaluated to determine if there are additional elements or a combination of elements that apply, rely on, or use the judicial exception in a manner that imposes a meaningful limit on the judicial exception, such that the claims are more than a drafting effort designed to monopolize the judicial exception (PEG 2019, Pg. 54).
As a whole, the additional elements of claims 1, 13, 21 recite:
receiving a packet from at least one device belonging to the local communication network, said received packet comprising an illicit source IP address
This judicial exception is not integrated into a practical application. The claims as a whole merely describe how to generally mere data gathering, and output recited at a high level of generality, and thus are insignificant extra-solution activity. See MPEP 2106.05(g) (“whether the limitation is significant”). In addition, all uses of the recited judicial exceptions require such data gathering and output, and, as such, these limitations do not impose any meaningful limits on the claim. These limitations amount to necessary data gathering and outputting. See MPEP 2106.05. The router in the steps is recited at a high-level of generality such that it amounts no more than mere instructions to apply the exception using a generic computer component. Accordingly, this additional element does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. The claim is directed to an abstract idea.
Dependent claims when analyzed as a whole are held to be patent ineligible under 35 U.S.C. 101 because the additional recited limitations fail to establish that the claims are not directed to an abstract idea. Since these claims are directed to an abstract idea, the Office must determine whether the remaining limitations “do significantly more” than describe the abstract idea.
Part II. Determine whether any Element, or Combination, Amounts to“Significantly More” than the Abstract Idea itself
Under Part II, the steps of the claimed invention, when considered individually and as an ordered combination, do not improve another technology or technical field, do not improve the As explained with respect to Step 2A, Prong Two, the additional elements. The additional element of “router” and “local communication network” in limitations are at best mere instructions to “apply” the abstract ideas, which cannot provide an inventive concept. See MPEP 2106.05(f). Additional elements were both found to be insignificant extra-solution activity in Step 2A, Prong Two, because they were determined to be insignificant limitations as necessary data gathering and outputting. However, a conclusion that an additional element is insignificant extra solution activity in Step 2A, Prong Two should be re-evaluated in Step 2B. See MPEP 2106.05, subsection I.A. At Step 2B, the evaluation of the insignificant extra-solution activity consideration takes into account whether or not the extra-solution activity is well understood, routine, and conventional in the field. See MPEP 2106.05(g). functioning of the computer itself, and are not enough to qualify as "significantly more". MPEP 2106.05(d)(II) states that “The courts have recognized the following computer functions as well‐understood, routine, and conventional functions when they are claimed in a merely generic manner: Storing and retrieving information in memory, Versata Dev. Group, Inc. v. SAP Am., Inc., 793 F.3d 1306, 1334, 115 USPQ2d 1681, 1701 (Fed. Cir. 2015); OIP Techs., 788 F.3d at 1363, 115 USPQ2d at 1092-93; Receiving or transmitting data over a network, e.g., using the Internet to gather data, OIP Techs., Inc., v. Amazon.com, Inc., 788 F.3d 1359, 1363, 115 USPQ2d 1090, 1093 (Fed. Cir. 2015) (sending messages over a network); buySAFE, Inc. v. Google, Inc., 765 F.3d 1350, 1355, 112 USPQ2d 1093, 1096 (Fed. Cir. 2014) (computer receives and sends information over a network)). Therefore, based on the two-part Mayo analysis, there are no meaningful limitations in the claim that transform the exception into a patent eligible application such that the claim amounts to significantly more than the exception itself. Claims 1, 3-18 and 20-21, when considered individually and as an ordered combination, are rejected as ineligible subject matter under 35 U.S.C. 101.
Dependent claims when analyzed as a whole are held to be patent ineligible under 35 U.S.C. 101 because the additional claims do no recite significantly more than an abstract idea. Claim 3 further recites recording in a table an identifier of the device in association with a received-packet counter initialized to an initial value and a first reception time (if the identifier is absent), and updating the table if the identifier is present. These limitations further recite the abstract idea, as they encompass mental processes / recordkeeping — a person observing whether an entry exists in a list and, using pen and paper, writing down an identifier, a starting count, and a time of receipt, or updating an existing entry. The “table” is a generic data structure, adding no meaningful limitation. Claim 4 further recites defining a first period and a shorter second period (terminating at the same time), and incrementing the received-packet counter for each packet received during the second period (if no disconnection time is given). These limitations further recite the abstract idea as a mental process / mathematical concept — counting/tallying occurrences within a defined time window and comparing durations. Claim 5 further recites limitations substantially similar to claim 4, but with the first period counted from a time of disconnection and incrementing the counter for packets received during the second period if the disconnection time is given. These are likewise mental processes / mathematical concepts (counting and comparing time periods). Claim 6 further recites deleting the identifier from the table where the first period has elapsed and the received-packet counter equals the initial value. This encompasses a mental process — evaluating whether a period has elapsed and whether a count equals a starting value, then removing a record (an act of recordkeeping). Claim 7 further recites forcing the device to reinitialize its network interface by disconnecting it, recording the disconnection time, and reinitializing the counter, where the first period has elapsed and the counter differs from the initial value. The evaluation/decision steps (comparing the period and counter) further recite a mental process; the “forcing … to reinitialise … by disconnecting” and “recording”/“reinitialising” are, to the extent additional elements, insignificant extra-solution activity / generic apply-it limitations performed by the generic router, and are well-understood, routine, and conventional. Claim 8 further recites preventing, during a configured quarantine duration, any communication with the device when the first period has elapsed, if a disconnection time is given and the counter differs from the initial value. The conditional evaluation is a mental process; the “preventing communication” is a generic apply-it/extra-solution limitation. Claim 9 further recites that the quarantine duration increases at each new quarantine. This recites a mathematical concept / mental process (increasing a value based on a count). Claim 10 further recites that the quarantine duration… this limitation expressly recites a mathematical concept (a mathematical relationship/calculation. Claim 11 further recites that the quarantine duration is equal to… recites a mathematical concept (a mathematical relationship/calculation. Claim 12 further recites that the first communication network and the other communication network use the IPv6 communication protocol. This limitation merely generally links the use of the judicial exception to a particular technological environment (a specific network protocol) and recites a well-understood, routine, and conventional communication protocol. Specifying a particular protocol does not impose a meaningful limit on the abstract idea and does not integrate it into a practical application (MPEP §§ 2106.05(h), 2106.05(d)).
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1, 13 and 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Grosse (US 2005/0177717 A1), in view of Chittigala et al. (US 2017/0374020 A1), hereinafter “Chittigala”.
As to claim 1, Grosse discloses a method for indicating a use of an illicit IP address in a local communication network (Grosse, ¶ 0001-0007, 0018-0019, fig. 2), the local communication network being connected to another communication network by means of a router, wherein the method comprises the steps, performed by the router (Grosse, ¶ 0001-0007, 0018-0019, 0022-0023, fig. 2), of:
receiving a packet from at least one device belonging to the local communication network, said received packet comprising an illicit source IP address (receiving a packet at a network edge router, the packet comprising an indicated IP source address, where the source address may be forged/“spoofed” — e.g., “smurfed” packets sent by a malicious smurfer having fake source addresses) (Grosse, ¶ 0016-0019, 0022-0023, fig. 3);
marking the packet received with the predefined mark and rejecting the packet received (performing a Reverse Path Forwarding (RPF) test on the source address and, based on the result, setting a predetermined data field — e.g., the Type-of-Service (TOS) field — of the packet to a predefined value (zero for unverified/illicit; non-zero for verified and a packet whose source address has not been verified — i.e., TOS field equal to zero — is rejected and discarded ) (Grosse, ¶ 0016-0019, 0025-0026, fig. 4).
However Grosse, does not explicitly disclose generating an error message packet and marking the error message packet with a predefined mark; and transmitting the error message packet marked with the predefined mark to the at least one device to inform said at least one device of its use of an illicit IP address by using an additional routing table comprising a single route that directs each packet by default to the local communication network and a routing rule applying the additional routing table to each error message packet marked with the predefined mark.
In an analogous art, Chittigala discloses generating an error message packet and marking the error message packet with a predefined mark (DHCP program 32 invalidates the IP lease (step 250). In an embodiment, DHCP program 32 invalidates the IP lease of node 50-1 by setting the parity bit (not shown) of node 50-1 to zero. A parity bit is a bit added to the end of a string of binary code. The parity bit indicates whether the number of bits in the string are an odd or an even number of bits. In an embodiment, parity bits are used to identify errors. In an embodiment, a parity bit of zero indicates an invalid IP lease, an unreachable node, and/or a faulty node. In another embodiment, a parity bit of one indicates a valid IP lease and/or a properly functioning node.) (Chittigala, ¶0028, 0030-0031); and
transmitting the error message packet marked with the predefined mark to the at least one device to inform said at least one device of its use of an illicit IP address by using an additional routing table comprising a single route that directs each packet by default to the local communication network and a routing rule applying the additional routing table to each error message packet marked with the predefined mark. (nodes in network 20 can detect if another node in network 20 is faulty by identifying the parity bit of another node; Node A loses contact with the server, Node B, and Node C in network 20. DHCP program 32 no longer detects a heartbeat from Node A and sets the parity bit of Node A to zero. Node A is no longer able to request IP lease time renewal. DHCP program 32 transfers resource ownership that belonged to Node A to Node B and Node C, which have their parity bits set to one. Node A returns to the network and discovers Node A has an expired IP lease time and also that Node A has a parity bit of zero. Node A reboots; For example, node 50-1, node 50-2, and node 50-n are in network 20. Node 50-1 is the resource owner of data written to information repository 46. Node 50-1, node 50-2, node 50-n lose contact and can no longer communicate with one another. Node 50-1 requests DHCP program 32 to set the respective parity bits of node 50-2 and node 50-n to zero to prevent node 50-2 and node 50-n from writing to information repository 46. In an embodiment, DHCP program 32 and node 50-1 invalidate IP leases to prevent data corruption. For example, if node 50-1, node 50-2, and node 50-3 lose contact with one another, each node will assume the other nodes are faulty. As a result, each node writes data to information repository 46, resulting in corruption of the data i.e. using nodes routing table and rules based on the parity bit) (Chittigala, ¶ 0028, 0030-0035).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention was made to implement’s Chittigala teachings into Grosse’s teaching of generating an error message packet and marking the error message packet with a predefined mark; and transmitting the error message packet marked with the predefined mark to the at least one device to inform said at least one device of its use of an illicit IP address by using an additional routing table comprising a single route that directs each packet by default to the local communication network and a routing rule applying the additional routing table to each error message packet marked with the predefined mark. This combination effectively provides invalidating the least time of one or more nodes prevents the node(s) from writing to information repository, and thus, preventing corruption of data.
Claim 13 list all the same elements of claim 1, but in a router connecting a local communication network to another communication network, the router comprising electronic circuitry (Grosse, ¶ 0001-0007, 0018-0019, fig. 2) to carry out method steps of the system form. Therefore, the supporting rationale of the rejection to claim 1 applies equally as well to claim 13.
As to claim 20, Grosse discloses a non-transitory information storage medium, which stores a computer program comprising instructions for implementing, by a processor, the method according to claim 1, when the program is executed by the processor (Grosse, ¶ 0001-0007, 0018-0019, fig. 2).
Claim(s) 3-6, 8-9, 12-17 and 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Grosse (US 2005/0177717 A1), in view of Chittigala et al. (US 2017/0374020 A1), hereinafter “Chittigala” as applied above in further view of Milliken (US 2006/0184690 A1).
As to claim 3, Grosse- Chittigala discloses the method according to claim 1, but does not explicitly the method further comprising: recording in a table, referred to as an illicit IP address table, an identifier of the device using the illicit source IP address, in association with a received-packet counter initialized to an initial value, and in association with a time of reception of the received packet, referred to as a first reception time, if the identifier is absent from the table of illicit IP addresses; updating the table of illicit IP addresses if the identifier of the device is present in the table of illicit IP addresses.
In an analogous art, Milliken discloses recording in a table, referred to as an illicit IP address table, an identifier of the device using the illicit source IP address, in association with a received-packet counter initialized to an initial value, and in association with a time of reception of the received packet, referred to as a first reception time, if the identifier is absent from the table of illicit IP addresses (If the routing table lacks a default entry, one special entry may be added for use by the traceback process for when the lookup match fails, and the associated use bit would be set on this entry. Normally this would indicate use of an unroutable (unassigned) or illegal IP address. Of course, with some embodiments of the methods described herein, such as one that uses a simple table indexed by a fixed number of upper address bits, there is always a usable table entry, and thus there would be no default entry or lookup failure) (Milliken, ¶ 0056-0060); updating the table of illicit IP addresses if the identifier of the device is present in the table of illicit IP addresses (If the subnet prefix of the incoming packet is found within the lookup table 20 then the use bit is set, populating the bit field 42 with the binary number 1. If it is determined that the subnet prefix of the incoming IP packet is not found within the lookup table 20, then a binary 1 is set or written into a default entry field (prefix of zero length) provided within the lookup table 20) (Milliken, ¶0056-0060).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention was made to implement’s Milliken teachings into Grosse- Chittigala teaching of recording in a table, referred to as an illicit IP address table, an identifier of the device using the illicit source IP address, in association with a received-packet counter initialized to an initial value, and in association with a time of reception of the received packet, referred to as a first reception time, if the identifier is absent from the table of illicit IP addresses; updating the table of illicit IP addresses if the identifier of the device is present in the table of illicit IP addresses. This combination effectively indicate use of an unroutable or illegal IP address.
As to claim 4, Grosse- Chittigala-Milliken discloses the method according to claim 3, wherein a first period being defined with a first predefined duration, the first period being counted as from the time of first reception (The second embodiment described here includes a timestamp with the data. This timestamp would typically indicate the period over which the data was collected (such as a specific 15-minute interval of a single day) (Milliken, ¶0056-0060, 0068, 100-101), wherein a second period being defined with a second predefined duration, the second predefined duration being shorter than the first predefined duration and terminating at the same time as the first period (Periodically, the router's main control processor collects the "use" or "used" bits and records them, along with a timestamp. The collection interval can be varied, and would probably be configured for each router; a typical value might be to collect the "used" bits for each prefix in the forwarding table once every 15 minutes, which is a typical measurement interval for collecting traffic statistics (i.e. second collection interval is the second period)) (Milliken, ¶0056-0060, 0068, 100-101), and wherein updating the table of illicit IP addresses comprises incrementing the received-packet counter for each packet received during the second period if a time of disconnection of the device is not given in the table of illicit IP addresses (This timestamp would typically indicate the period over which the data was collected (such as a specific 15-minute interval of a single day). It is used primarily for historical tracebacks when an attack packet needs to be traced hours or days after the actual attack, and is used to determine which set of "use" bits should be queried in an archive at the NOC corresponding to the time period of the attack (i.e. bits are used to record the illegal IP addresses) (Milliken, ¶0056-0060, 0068, 100-101). The Examiner supplies the same rationale for the combination of references Grosse- Chittigala-Milliken as in Claim 3 above.
As to claim 5, Grosse- Chittigala-Milliken discloses the method according to claim 3, wherein a first period being defined with a first predefined duration, the first period being counted as from a time of disconnection of said device (The second embodiment described here includes a timestamp with the data. This timestamp would typically indicate the period over which the data was collected (such as a specific 15-minute interval of a single day) (Milliken, ¶0056-0060, 0068, 100-101), wherein a second period being defined with a second predefined duration, the second predefined duration being shorter than the first predefined duration and terminating at the same time as the first period (Periodically, the router's main control processor collects the "use" or "used" bits and records them, along with a timestamp. The collection interval can be varied, and would probably be configured for each router; a typical value might be to collect the "used" bits for each prefix in the forwarding table once every 15 minutes, which is a typical measurement interval for collecting traffic statistics (i.e. second interval is the second period) (Milliken, ¶0056-0060, 0068, 100-101), and wherein updating the table of illicit IP addresses comprises incrementing the received-packet counter for each packet received during the second period, if the time of disconnection of the device is given in the table of illicit IP addresses (This timestamp would typically indicate the period over which the data was collected (such as a specific 15-minute interval of a single day). It is used primarily for historical tracebacks when an attack packet needs to be traced hours or days after the actual attack, and is used to determine which set of "use" bits should be queried in an archive at the NOC corresponding to the time period of the attack (i.e. bits are used to record the illegal IP addresses during different interval) (Milliken, ¶0056-0060, 0068, 100-101). The Examiner supplies the same rationale for the combination of references Grosse- Chittigala-Milliken as in Claim 3 above.
As to claim 6, Grosse- Chittigala-Milliken discloses the method according to claim 4, further comprising the step of deleting the identifier from the table of illicit IP addresses in the case where the first period has elapsed and the received-packet counter is equal to the initial value (The method compiles a partial list of use bits at specified time intervals, and may reset the use bits at specified time intervals) (Milliken, ¶0020, 0068, 100-101). The Examiner supplies the same rationale for the combination of references Grosse- Chittigala-Milliken as in Claim 4 above.
As to claim 8, Grosse- Chittigala-Milliken discloses the method according to claim 5, further comprising: preventing, during a configured quarantine duration, any communication with the device when the first period has elapsed, if a time of disconnection of a network interface of the device is given in the table, and if the received-packet counter is different from the initial value (DHCP program 32 invalidates the IP lease (step 250). In an embodiment, DHCP program 32 invalidates the IP lease of node 50-1 by setting the parity bit (not shown) of node 50-1 to zero. A parity bit is a bit added to the end of a string of binary code. The parity bit indicates whether the number of bits in the string are an odd or an even number of bits. In an embodiment, parity bits are used to identify errors. In an embodiment, a parity bit of zero indicates an invalid IP lease, an unreachable node, and/or a faulty node. In another embodiment, a parity bit of one indicates a valid IP lease and/or a properly functioning node. Node A returns to the network and discovers Node A has an expired IP lease time and also that Node A has a parity bit of zero. Node A reboots. For example, the IP lease for node 50-1 expired. Node 50-1 cannot connect to network 20 with the expired lease. To rejoin network 20, node 50-1 requests a new IP lease from DHCP program 32. In an embodiment, DHCP assigns a new IP lease or renews an existing IP lease if DHCP program 32 receives an IP lease request from a node with a parity bit of one.) (Chittigala, ¶0026-28, 0030-0035).
As to claim 9, Grosse- Chittigala-Milliken discloses the method according to claim 8, wherein the configured quarantine duration increases at each new quarantine, a quarantine being a period during which any communication with the device prevented (DHCP program 32 invalidates the IP lease (step 250). In an embodiment, DHCP program 32 invalidates the IP lease of node 50-1 by setting the parity bit (not shown) of node 50-1 to zero. A parity bit is a bit added to the end of a string of binary code. The parity bit indicates whether the number of bits in the string are an odd or an even number of bits. In an embodiment, parity bits are used to identify errors. In an embodiment, a parity bit of zero indicates an invalid IP lease, an unreachable node, and/or a faulty node. In another embodiment, a parity bit of one indicates a valid IP lease and/or a properly functioning node. Node A returns to the network and discovers Node A has an expired IP lease time and also that Node A has a parity bit of zero. Node A reboots. For example, the IP lease for node 50-1 expired. Node 50-1 cannot connect to network 20 with the expired lease. To rejoin network 20, node 50-1 requests a new IP lease from DHCP program 32. In an embodiment, DHCP assigns a new IP lease or renews an existing IP lease if DHCP program 32 receives an IP lease request from a node with a parity bit of one.) (Chittigala, ¶0026-28, 0030-0035).
As to claim 12, Grosse- Chittigala discloses the method according to claim 1, but does not explicitly disclose wherein the first communication network and the other communication network use the IPv6 communication protocol.
In an analogous art, Milliken discloses wherein the first communication network and the other communication network use the IPv6 communication protocol (For longer addresses, such as those used in IPv6, the source address might be hashed, instead, and stored in a Bloom filter similar to those used by the above referenced SPIE system SPIE) (Milliken, ¶ 136-137, fig. 5).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention was made to implement’s Milliken teachings into Grosse- Chittigala teaching of wherein the first communication network and the other communication network use the IPv6 communication protocol. This combination effectively indicate use of an unroutable or illegal IP address.
Claims 14-17 list all the same elements of claims 3-6, but in a router connecting a local communication network to another communication network, the router comprising electronic circuitry (Grosse, ¶ 0001-0007, 0018-0019, fig. 2) to carry out method steps of the system form. Therefore, the supporting rationale of the rejection to claims 3-6 applies equally as well to claims 14-17.
As to 21, Grosse discloses a method for indicating a use of an illicit IP address in a local communication network (Grosse, ¶ 0001-0007, 0018-0019, fig. 2), the local communication network being connected to another communication network by means of a router (Grosse, ¶ 0001-0007, 0018-0019, 0022-0023, fig. 2), wherein the method comprises the steps, performed by the router, of: receiving a packet from at least one device belonging to the local communication network, said received packet comprising an illicit source IP address (receiving a packet at a network edge router, the packet comprising an indicated IP source address, where the source address may be forged/“spoofed” — e.g., “smurfed” packets sent by a malicious smurfer having fake source addresses) (Grosse, ¶ 0016-0019, 0022-0023, fig. 3).
However Grosse, does not explicitly disclose generating an error message packet and marking the error message packet with a predefined mark; and returning the marked error message packet to the at least one device using an additional routing table redirecting each packet to the local communication network and a routing rule applying the additional routing table to each packet marked with the predefined mark; recording in a table, referred to as an illicit IP address table, an identifier of the device using the illicit source IP address, in association with a received-packet counter initialised to an initial value, and in association with a time of reception of the received packet, referred to as a first reception time, if the identifier is absent from the table of illicit IP addresses; updating the table of illicit IP addresses if the identifier of the device is present in the table of illicit IP addresses, wherein a first period being defined with a first predefined duration, the first period being counted as from a time of disconnection of said device, wherein a second period being defined with a second predefined duration, the second predefined duration being shorter than the first predefined duration and terminating at the same time as the first period, and wherein updating the table of illicit IP addresses comprises incrementing the received-packet counter for each packet received during the second period, if the time of disconnection of the device is given in the table of illicit IP addresses; and preventing, during a configured quarantine duration, any communication with the device when the first period has elapsed, if a time of disconnection of a network interface of the device is given in the table, and if the received-packet counter is different from the initial value, wherein the configured quarantine duration either: increases at each new quarantine, a quarantine being a period during which any communication with the device prevented, or is equal to n*Dt where n is a number of quarantines and Dt is an initial quarantine duration.
In an analogous art, Chittigala discloses generating an error message packet and marking the error message packet with a predefined mark (DHCP program 32 invalidates the IP lease (step 250). In an embodiment, DHCP program 32 invalidates the IP lease of node 50-1 by setting the parity bit (not shown) of node 50-1 to zero. A parity bit is a bit added to the end of a string of binary code. The parity bit indicates whether the number of bits in the string are an odd or an even number of bits. In an embodiment, parity bits are used to identify errors. In an embodiment, a parity bit of zero indicates an invalid IP lease, an unreachable node, and/or a faulty node. In another embodiment, a parity bit of one indicates a valid IP lease and/or a properly functioning node.) (Chittigala, ¶0028, 0030-0031); and
returning the marked error message packet to the at least one device using an additional routing table redirecting each packet to the local communication network and a routing rule applying the additional routing table to each packet marked with the predefined mark (nodes in network 20 can detect if another node in network 20 is faulty by identifying the parity bit of another node; Node A loses contact with the server, Node B, and Node C in network 20. DHCP program 32 no longer detects a heartbeat from Node A and sets the parity bit of Node A to zero. Node A is no longer able to request IP lease time renewal. DHCP program 32 transfers resource ownership that belonged to Node A to Node B and Node C, which have their parity bits set to one. Node A returns to the network and discovers Node A has an expired IP lease time and also that Node A has a parity bit of zero. Node A reboots; For example, node 50-1, node 50-2, and node 50-n are in network 20. Node 50-1 is the resource owner of data written to information repository 46. Node 50-1, node 50-2, node 50-n lose contact and can no longer communicate with one another. Node 50-1 requests DHCP program 32 to set the respective parity bits of node 50-2 and node 50-n to zero to prevent node 50-2 and node 50-n from writing to information repository 46. In an embodiment, DHCP program 32 and node 50-1 invalidate IP leases to prevent data corruption. For example, if node 50-1, node 50-2, and node 50-3 lose contact with one another, each node will assume the other nodes are faulty. As a result, each node writes data to information repository 46, resulting in corruption of the data i.e. using nodes routing table and rules based on the parity bit) (Chittigala, ¶ 0028, 0030-0035); preventing, during a configured quarantine duration, any communication with the device when the first period has elapsed, if a time of disconnection of a network interface of the device is given in the table, and if the received-packet counter is different from the initial value (DHCP program 32 invalidates the IP lease (step 250). In an embodiment, DHCP program 32 invalidates the IP lease of node 50-1 by setting the parity bit (not shown) of node 50-1 to zero. A parity bit is a bit added to the end of a string of binary code. The parity bit indicates whether the number of bits in the string are an odd or an even number of bits. In an embodiment, parity bits are used to identify errors. In an embodiment, a parity bit of zero indicates an invalid IP lease, an unreachable node, and/or a faulty node. In another embodiment, a parity bit of one indicates a valid IP lease and/or a properly functioning node. Node A returns to the network and discovers Node A has an expired IP lease time and also that Node A has a parity bit of zero. Node A reboots. For example, the IP lease for node 50-1 expired. Node 50-1 cannot connect to network 20 with the expired lease. To rejoin network 20, node 50-1 requests a new IP lease from DHCP program 32. In an embodiment, DHCP assigns a new IP lease or renews an existing IP lease if DHCP program 32 receives an IP lease request from a node with a parity bit of one.) (Chittigala, ¶0026-28, 0030-0035); wherein the configured quarantine duration either: increases at each new quarantine, a quarantine being a period during which any communication with the device prevented (DHCP program 32 invalidates the IP lease (step 250). In an embodiment, DHCP program 32 invalidates the IP lease of node 50-1 by setting the parity bit (not shown) of node 50-1 to zero. A parity bit is a bit added to the end of a string of binary code. The parity bit indicates whether the number of bits in the string are an odd or an even number of bits. In an embodiment, parity bits are used to identify errors. In an embodiment, a parity bit of zero indicates an invalid IP lease, an unreachable node, and/or a faulty node. In another embodiment, a parity bit of one indicates a valid IP lease and/or a properly functioning node. Node A returns to the network and discovers Node A has an expired IP lease time and also that Node A has a parity bit of zero. Node A reboots. For example, the IP lease for node 50-1 expired. Node 50-1 cannot connect to network 20 with the expired lease. To rejoin network 20, node 50-1 requests a new IP lease from DHCP program 32. In an embodiment, DHCP assigns a new IP lease or renews an existing IP lease if DHCP program 32 receives an IP lease request from a node with a parity bit of one.) (Chittigala, ¶0026-28, 0030-0035),or is equal to n*Dt where n is a number of quarantines and Dt is an initial quarantine duration.
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention was made to implement’s Chittigala teachings into Grosse’s teaching of generating an error message packet and marking the error message packet with a predefined mark; and returning the marked error message packet to the at least one device using an additional routing table redirecting each packet to the local communication network and a routing rule applying the additional routing table to each packet marked with the predefined mark, preventing, during a configured quarantine duration, any communication with the device when the first period has elapsed, if a time of disconnection of a network interface of the device is given in the table, and if the received-packet counter is different from the initial value, wherein the configured quarantine duration either: increases at each new quarantine, a quarantine being a period during which any communication with the device prevented, or is equal to n*Dt where n is a number of quarantines and Dt is an initial quarantine duration. This combination effectively provides invalidating the least time of one or more nodes prevents the node(s) from writing to information repository, and thus, preventing corruption of data.
However Grosse- Chittigala, does not explicitly disclose recording in a table, referred to as an illicit IP address table, an identifier of the device using the illicit source IP address, in association with a received-packet counter initialised to an initial value, and in association with a time of reception of the received packet, referred to as a first reception time, if the identifier is absent from the table of illicit IP addresses; updating the table of illicit IP addresses if the identifier of the device is present in the table of illicit IP addresses, wherein a first period being defined with a first predefined duration, the first period being counted as from a time of disconnection of said device, wherein a second period being defined with a second predefined duration, the second predefined duration being shorter than the first predefined duration and terminating at the same time as the first period, and wherein updating the table of illicit IP addresses comprises incrementing the received-packet counter for each packet received during the second period, if the time of disconnection of the device is given in the table of illicit IP addresses.
In an analogous art, Milliken discloses recording in a table, referred to as an illicit IP address table, an identifier of the device using the illicit source IP address, in association with a received-packet counter initialised to an initial value, and in association with a time of reception of the received packet, referred to as a first reception time, if the identifier is absent from the table of illicit IP addresses (If the routing table lacks a default entry, one special entry may be added for use by the traceback process for when the lookup match fails, and the associated use bit would be set on this entry. Normally this would indicate use of an unroutable (unassigned) or illegal IP address. Of course, with some embodiments of the methods described herein, such as one that uses a simple table indexed by a fixed number of upper address bits, there is always a usable table entry, and thus there would be no default entry or lookup failure) (Milliken, ¶ 0056-0060); updating the table of illicit IP addresses if the identifier of the device is present in the table of illicit IP addresses (If the subnet prefix of the incoming packet is found within the lookup table 20 then the use bit is set, populating the bit field 42 with the binary number 1. If it is determined that the subnet prefix of the incoming IP packet is not found within the lookup table 20, then a binary 1 is set or written into a default entry field (prefix of zero length) provided within the lookup table 20) (Milliken, ¶0056-0060); wherein a first period being defined with a first predefined duration, the first period being counted as from a time of disconnection of said device (The second embodiment described here includes a timestamp with the data. This timestamp would typically indicate the period over which the data was collected (such as a specific 15-minute interval of a single day) (Milliken, ¶0056-0060, 0068, 100-101), wherein a second period being defined with a second predefined duration, the second predefined duration being shorter than the first predefined duration and terminating at the same time as the first period (Periodically, the router's main control processor collects the "use" or "used" bits and records them, along with a timestamp. The collection interval can be varied, and would probably be configured for each router; a typical value might be to collect the "used" bits for each prefix in the forwarding table once every 15 minutes, which is a typical measurement interval for collecting traffic statistics (i.e. second collection interval is the second period)) (Milliken, ¶0056-0060, 0068, 100-101), and wherein a second period being defined with a second predefined duration, the second predefined duration being shorter than the first predefined duration and terminating at the same time as the first period, and wherein updating the table of illicit IP addresses comprises incrementing the received-packet counter for each packet received during the second period, if the time of disconnection of the device is given in the table of illicit IP addresses (This timestamp would typically indicate the period over which the data was collected (such as a specific 15-minute interval of a single day). It is used primarily for historical tracebacks when an attack packet needs to be traced hours or days after the actual attack, and is used to determine which set of "use" bits should be queried in an archive at the NOC corresponding to the time period of the attack (i.e. bits are used to record the illegal IP addresses) (Milliken, ¶0056-0060, 0068, 100-101)
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention was made to implement’s Milliken teachings into Grosse- Chittigala teaching of recording in a table, referred to as an illicit IP address table, an identifier of the device using the illicit source IP address, in association with a received-packet counter initialized to an initial value, and in association with a time of reception of the received packet, referred to as a first reception time, if the identifier is absent from the table of illicit IP addresses; updating the table of illicit IP addresses if the identifier of the device is present in the table of illicit IP addresses. This combination effectively indicate use of an unroutable or illegal IP address.
Claim(s) 7 and 18 is/are rejected under 35 U.S.C. 103 as being unpatentable over Grosse (US 2005/0177717 A1), in view of Chittigala et al. (US 2017/0374020 A1), hereinafter “Chittigala” as applied above in further view of Croft (US 2007/0180449 A1).
As to claim 7, Grosse- Chittigala-Milliken discloses the method according to claim 4, but does not explicitly disclose further comprising the step of forcing the device to reinitialise its network interface by disconnecting it from the local communication network, recording the time of disconnection in the table of illicit IP addresses and reinitialising the received-packet counter to the initial value, in the case where the first period has elapsed and the received-packet counter is different from the initial value.
In an analogous art, Croft discloses the step of forcing the device to reinitialise its network interface by disconnecting it from the local communication network, recording the time of disconnection in the table of illicit IP addresses (The broker process disconnects the client computer from the identified computing environment in response to a received disconnect signal. In further embodiments, the broker process updates a data record associated with the identified computing environment to indicate the client machine is disconnected from the identified computing environment.) (Croft, ¶ 0020-0023) and reinitialising the received-packet counter to the initial value, in the case where the first period has elapsed and the received-packet counter is different from the initial value (The broker process disconnects the client computer from the identified computing environment in response to a received disconnect signal. In further embodiments, the broker process updates a data record associated with the identified computing environment to indicate the client machine is disconnected from the identified computing environment.) (Croft, ¶ 0020-0023).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention was made to implement’s Croft teachings into Grosse- Chittigala-Milliken teaching of the step of forcing the device to reinitialise its network interface by disconnecting it from the local communication network, recording the time of disconnection in the table of illicit IP addresses and reinitialising the received-packet counter to the initial value, in the case where the first period has elapsed and the received-packet counter is different from the initial value. This combination effectively indicate the client machine is disconnected.
Claim 18 list all the same elements of claim 7, but in a router connecting a local communication network to another communication network, the router comprising electronic circuitry (Grosse, ¶ 0001-0007, 0018-0019, fig. 2) to carry out method steps of the system form. Therefore, the supporting rationale of the rejection to claim 7 applies equally as well to claim 18.
Response to Arguments
Response to 103 rejections applicant’s amendments to the claim change the scope. Therefore, amended claims necessitated new ground(s) of rejections presented in this office action in view of Chittigala et al. (US 2017/0374020 A1), have been introduced to address amended. Applicant’s arguments have been considered but are moot because the arguments do not apply to any of the references being used in the current rejection.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. See PTO-892.
Yoshimura et al. (US 2011/0213866 A1) disclose a storage resource stores a plugin information package, which is an information package comprising definition information for plugging in a node device as a management target. The definition information is information denoting at the least one of a method for acquiring information from a node device and an item of information to be acquired from a node device. A processor references the plugin information package, which is stored in the storage resource, and accesses a node device via a communication interface device based on the referenced plugin information package. The node device comprising information that has been correctly acquired in accordance with this access is regarded as the management target.
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to HITESH R PATEL whose telephone number is (571)270-5442. The examiner can normally be reached Monday-Friday 7am-3pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, James Trammell can be reached at 571-272-6712. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/Hitesh Patel/Supervisory Patent Examiner, Art Unit 3667
7/22/26