DETAILED ACTION
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Amendment
This office action is in response to applicant’s amendment and RCE filed, 27 May 2026, of application filed, with the above serial number, on 24 August 2022 in which claims 1, 3-4 have been amended, claim 18 has been cancelled, and claims 19-20 added. Claims 1, 3-8, 11-16, 19-20 are pending in the application.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1, 3-6, 11-16, 19-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Rooney et al (hereinafter “Rooney”, 2020/0403875) in view of Choukir et al (hereinafter “Choukir”, 2021/0092021).
As per Claim 1, Rooney discloses a method for onboarding a device in a multi-tenant virtual network of an industrial network, the method comprising:
deploying the onboarding network in the industrial network, wherein the deploying comprises: generating the onboarding network and an authentication module; connecting the onboarding network to the authentication module; extending the onboarding network to an access point of the industrial network, wherein the access point is an electronic device that provides a link between the onboarding network and the device to be onboarded to the multi-tenant virtual network of the industrial network (at least paragraph 28; the repeater device 120 can connect to the onboarding network 190 and the router 160 via the first repeater 140 which acts as a virtual access point (VAP) for the onboarding network 190); generating a separate access network that is separate from the onboarding network and the multi-tenant virtual network; and connecting the separate access network to the onboarding network via the access point (at least paragraph 28-33; establish an onboarding network 190. For example, the back end server 110 configures the Wi-Fi Router 160 with configuration commands via a RESTful protocol to add the onboarding network SSID from the onboarding network credential 126 so the repeater device 120 can connect to the onboarding network 190. For example, the repeater device 120 can connect to the onboarding network 190 and the router 160 via the first repeater 140 which acts as a virtual access point (VAP) for the onboarding network 190);
receiving an onboarding request from the device regarding access to the multi-tenant virtual network of the industrial network, wherein the onboarding request is received in the separate access network of the industrial network assigned to the onboarding network (at least Fig. 1C; paragraph 24-31; step 126);
identifying and verifying the device using the authentication module (at least Fig. 1C; paragraph 24-31; step 128; the Wi-Fi router 160 uses the received onboarding network credential 126 to establish an onboarding network 190. For example, the back end server 110 configures the Wi-Fi Router 160 with configuration commands via a RESTful protocol to add the onboarding network SSID from the onboarding network credential 126 so the repeater device 120 can connect to the onboarding network 190. For example, the repeater device 120 can connect to the onboarding network 190 and the router 160 via the first repeater 140 which acts as a virtual access point (VAP) for the onboarding network 190);
sending a configuration file to the device when a verification result is positive, wherein the configuration file comprises data regarding an access authorization of the device to the multi-tenant virtual network (at least paragraph 28, 31; Besides the Wi-Fi network provisioning credential 128, the repeater device 120 may receive other configuration parameters via the onboarding network 190 and/or the Wi-Fi network 180);
configuring the device according to the configuration file (at least paragraph 28, 31; Besides the Wi-Fi network provisioning credential 128, the repeater device 120 may receive other configuration parameters via the onboarding network 190 and/or the Wi-Fi network 180);
verifying the access authorization of the device in the access point of the industrial network (at least paragraph 28-33; When the repeater device 120 detects that it can talk to the back end server 110 via the onboarding network 190 the repeater device 120 can be fully managed by the back end server 110. The back end server 110 sends the new configuration for the repeater device 120 which includes the network credential 128 and as when the repeater device 120 receives that configuration it applies it and restarts its network so it immediately leaves the onboarding network 190 and joins the Wi-Fi network 180.); and
granting the device access to the multi-tenant virtual network when the verification result is positive (at least paragraph 33; When the repeater device 120 detects that it can talk to the back end server 110 via the onboarding network 190 the repeater device 120 can be fully managed by the back end server 110. The back end server 110 sends the new configuration for the repeater device 120 which includes the network credential 128 and as when the repeater device 120 receives that configuration it applies it and restarts its network so it immediately leaves the onboarding network 190 and joins the Wi-Fi network 180.).
Rooney fails to explicitly disclose wherein the separate access network is open to any device for requesting access to the multi-tenant virtual network where the device does not require any password to access the separate access network to carry out the onboarding request. However, the use and advantages for using such a system was well known to one skilled in the art before the effective filing date of the claimed invention as evidenced by the teachings of Choukir. Choukir discloses, in an analogous onboarding art, any device including wireless client 120 may send an onboarding request to an AP to access a network, the client is mapped to connect to onboarding VNID network 105A in order to then authenticate the client in order to have the client be connected to the virtual network 105 they are attempting to connect to, once they are authenticated a destination VNID network is determined (at least paragraph 19-21, 67-72). Therefore, it would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to incorporate the use of Choukir’s onboarding with Rooney as Choukir teaches this allows the device to freely connect up to authentication resources and connections only, and not the actual networks in order to then authenticate the device to actually be onboarded, thus enhancing the security of the network as is well known in onboarding, as well as addressing other shortcomings Choukir identifies in par. 12-16.
As per Claim 3. The method of claim 1, wherein the separate access network is only made available to receive onboarding requests for a limited period of time (at least paragraph 27; onboarding network password for a (temporary) onboarding network 190).
As per Claim 4, Rooney discloses an industrial network comprising:
a multi-tenant virtual network (at least paragraph 30-31l WiFi network); an onboarding network (at least paragraph 27, onboarding network); an authentication module configured to identify and verify a device to be onboarded to the multi-tenant virtual network (at least paragraph 27; onboarding network credential 126, onboarding network SSID, and onboarding network password of router); a separate access network that is separate from the onboarding network and the multi-tenant virtual network, wherein the separate access network is assigned to the onboarding network, wherein the separate access network is configured to receive an onboarding request from the device regarding access to the multi-tenant virtual network; and an access point to which the onboarding network extends, wherein the access point is an electronic device that provides a link between the onboarding network and the device configured to be onboarded to the multi-tenant virtual network (at least paragraph 28; the repeater device 120 can connect to the onboarding network 190 and the router 160 via the first repeater 140 which acts as a virtual access point (VAP) for the onboarding network 190); wherein the access point is configured to verify an access authorization of the device and grant the device access to the multi-tenant virtual network when a verification result is positive (at least paragraph 28-33; establish an onboarding network 190. For example, the back end server 110 configures the Wi-Fi Router 160 with configuration commands via a RESTful protocol to add the onboarding network SSID from the onboarding network credential 126 so the repeater device 120 can connect to the onboarding network 190. For example, the repeater device 120 can connect to the onboarding network 190 and the router 160 via the first repeater 140 which acts as a virtual access point (VAP) for the onboarding network 190),
wherein the onboarding network is configured to be deployed in the industrial network in a multi-stage deployment process by generating the onboarding network and the authentication module, connecting the onboarding network to the authentication module, extending the onboarding network to the access point of the industrial network, generating the separate access network, and connecting the separate access network to the onboarding network via the access point (at least paragraph 28-33; establish an onboarding network 190. For example, the back end server 110 configures the Wi-Fi Router 160 with configuration commands via a RESTful protocol to add the onboarding network SSID from the onboarding network credential 126 so the repeater device 120 can connect to the onboarding network 190. For example, the repeater device 120 can connect to the onboarding network 190 and the router 160 via the first repeater 140 which acts as a virtual access point (VAP) for the onboarding network 190);
wherein a configuration file comprises data regarding the access authorization of the device to the multi-tenant virtual network, and wherein the device is configured according to the configuration file (at least Fig. 1C; paragraph 24-33, 47; step 128; the Wi-Fi router 160 uses the received onboarding network credential 126 to establish an onboarding network 190. For example, the back end server 110 configures the Wi-Fi Router 160 with configuration commands via a RESTful protocol to add the onboarding network SSID from the onboarding network credential 126 so the repeater device 120 can connect to the onboarding network 190. For example, the repeater device 120 can connect to the onboarding network 190 and the router 160 via the first repeater 140 which acts as a virtual access point (VAP) for the onboarding network 190; Besides the Wi-Fi network provisioning credential 128, the repeater device 120 may receive other configuration parameters via the onboarding network 190 and/or the Wi-Fi network 180; When the repeater device 120 detects that it can talk to the back end server 110 via the onboarding network 190 the repeater device 120 can be fully managed by the back end server 110. The back end server 110 sends the new configuration for the repeater device 120 which includes the network credential 128 and as when the repeater device 120 receives that configuration it applies it and restarts its network so it immediately leaves the onboarding network 190 and joins the Wi-Fi network 180; only the serial number or MAC address of repeater device being used by mobile app 135; unique ID is associated with a temporary network credential; mobile app 135 sends the ID (via scanning or inputting serial number/MAC) to the backend server which allows repeater device to log into onboarding network using only the ID)).
Rooney fails to explicitly disclose wherein the access network is open to any device for requesting access to the multi-tenant virtual network where the device does not require any password to access the access network to carry out the onboarding request. However, the use and advantages for using such a system was well known to one skilled in the art before the effective filing date of the claimed invention as evidenced by the teachings of Choukir. Choukir discloses, in an analogous onboarding art, any device including wireless client 120 may send an onboarding request to an AP to access a network, the client is mapped to connect to onboarding VNID network 105A in order to then authenticate the client in order to have the client be connected to the virtual network 105 they are attempting to connect to, once they are authenticated a destination VNID network is determined (at least paragraph 19-21, 67-72). Therefore, it would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to incorporate the use of Choukir’s onboarding with Rooney as Choukir teaches this allows the device to freely connect up to authentication resources and connections only, and not the actual networks in order to then authenticate the device to actually be onboarded, thus enhancing the security of the network as is well known in onboarding, as well as addressing other shortcomings Choukir identifies in par. 12-16.
As per Claim 5. The industrial network of claim 4, wherein the industrial network comprises at least one additional multi-tenant virtual network (at least Fig. 1c; par. 27, 32; temporary onboarding network 190 and after done disabling and reactivating).
As per Claim 6. The industrial network of claim 5, wherein the onboarding network is configured to act as a common onboarding network for onboarding devices to the multi-tenant virtual network and to the additional multi-tenant virtual network (at least paragraph 27).
As per Claim 11. The industrial network of claim 4, wherein the industrial network comprises at least one additional access point, and wherein the onboarding network extends to the access point and the at least one additional access point (at least Fig. 1a).
As per Claim 12. The industrial network of claim 11, wherein the access point and the at least one additional access point are spatially separated (at least Fig. 1a).
As per Claim 13. The industrial network of claim 11, wherein the access point and the at least one additional access point are configured for different access technologies (at least Rooney paragraph 2; eg. Bluetooth and wifi).
As per Claim 14. The method of claim 1, wherein a communication interface of the device is configured according to the configuration file (at least paragraph 26; repeater device 120 is configured to communicate with the Wi-Fi network 180).
As per Claim 15. The method of claim 1, wherein the authentication module is connected to a database, and wherein the database comprises information used in the identifying and the verifying of the device making the onboarding request (at least paragraph 35, Fig. 1a; manufacturer of the repeater device 120 maps the unique identifier 124 to a unique onboarding network credential 126, and adds a mapping of the unique identifier 124 and onboarding network credential 126 to a lookup table of mappings, for example, a database accessible to the back end server 110; database and back end server on WAN).
As per Claim 16. The industrial network of claim 4, further comprising: a database connected to the authentication module, wherein the database comprises information used in the identification and the verification of the device making the onboarding request (at least paragraph 35, Fig. 1a; manufacturer of the repeater device 120 maps the unique identifier 124 to a unique onboarding network credential 126, and adds a mapping of the unique identifier 124 and onboarding network credential 126 to a lookup table of mappings, for example, a database accessible to the back end server 110; database and back end server on WAN).
As per Claim 19. The industrial network of claim 4, further comprising: a single computer storing the multi-tenant virtual network, the onboarding network, and the authentication module, wherein the separate access network is separate from the single computer (at least paragraph 28-33; router computer 160 with separate repeater 140 access network).
As per Claim 20. The industrial network of claim 19, wherein the single computer of the industrial network comprises a physical interface that is connected to the access point of the industrial network (at least Fig. 1C; Wifi Router 160 connected to first repeater 140).
Claim(s) 7-8 is/are rejected under 35 U.S.C. 103 as being unpatentable over Rooney in view of Choukir, further in view of Schatzmann et al (hereinafter “Schatzmann”, 2015/0373001).
As per Claim 7. Rooney/ Choukir fail to explicitly disclose wherein the industrial network comprises at least one additional onboarding network, wherein the onboarding network is configured to onboard devices to the multi-tenant virtual network, and wherein the additional onboarding network is configured to onboard devices to the additional multi-tenant virtual network. However, the use and advantages for using such a system was well known to one skilled in the art before the effective filing date of the claimed invention as evidenced by the teachings of Schatzmann. Schatzmann discloses, in an analogous art, an onboarding controller having a plurality of onboarding networks each belonging to a different network management system (at least Schatzmann paragraph 28-32). Therefore, it would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to incorporate the use of Schatzmann’s onboarding controller with Rooney/ Choukir as Schatzmann teaches such ensures that network equipment of a particular customer is onboarded to the correct system for that customer's network and would allow Rooney’s system to have multiple SSID’s to onboard devices for different customers.
As per Claim 8. The industrial network of claim 7, wherein the industrial network comprises at least one additional authentication module configured to identify and verify a device that has made an onboarding request regarding access to the additional multi-tenant virtual network (at least Schatzmann paragraph 28-32; each new network equipment is added to a particular LANaaS system 2, 2′ be authorized to access that system/service).
Response to Arguments
Applicant's arguments filed 27 May 2026 have been fully considered but they are not persuasive.
Applicant argues on p. 9 that Rooney does not disclose the multi-stage process defined in claim 1 and ‘the Office's mapping fundamentally mischaracterizes the claimed intra-domain architecture’. It is assumed the ‘multi-stage’ process or deployment being argued to be, eg. onboarding network is created/generated before a device is onboarded, an access point being connected to the onboarded network so a device may connect to the onboarding network, and the method steps as outlined in claim 1.
In response to applicant's argument that the references fail to show certain features of the invention, it is noted that the features upon which applicant relies (i.e., intra-domain architecture and multi-stage deployment) are not recited in the rejected claim(s). Although the claims are interpreted in light of the specification, limitations from the specification are not read into the claims. See In re Van Geuns, 988 F.2d 1181, 26 USPQ2d 1057 (Fed. Cir. 1993). The specification, nor claims, recite this terminology and thus it is not clear precisely what is being argued outside of what the claim language itself is reciting.
It is important to note the terms as claimed and described in the specification, and their interpretation in comparison to the prior art. With respect to exemplary claim 1, a single onboarding network is deployed, such deployment including generating both the onboarding network and an access network. Claim 1 recites four networks, an industrial network, a multi-tenant virtual network and the aforementioned onboarding and access networks.
As Fig. 1 shows, industrial network may be likened to 10 as to include all the other networks, while node 11 contains ‘onboarding network 30’ and multi tenant network 20, thus these ‘networks’ are not networks in the typical sense in the art of connecting multiple devices but rather are merely acting as modules from interface 111 for authentication purposes via 40 and to run application 201, respectively.
Whereas the new device to be onboarded 90 is connecting to access point 60 via access network 50 and thus the more typical well known Wi-Fi type network.
The specification par. 20 as noted as support from the remarks p. 8 also supports this typical arrangement:
“An access point refers in particular to an interface between the industrial network and the onboarding device. The access point may be a piece of hardware in the form of an electronic device which, for example, is itself connected to a fixed communication network via a cable and acts as an interface for wireless communication terminals that may establish a wireless connection to the access point via a wireless adapter.”
Thus, as interpreted herein such ‘separate’ access network refers to the Wireless communication to terminals via the access point. In other words, using Fig. 1 as guidance, the access network 50 is the WiFi network from the access point 60 that is connected via cable to the unmarked oval circle to interface 11, or linked as claim 1 amended, to onboarding ‘network’ 30.
Par. 45 follows that “The onboarding network 30 is assigned an access network 50, which is located in particular at the access point 60.” The specification does not use the term ‘separate’ with regard to the access network and thus it is not clear how ‘separate’ the access network is from the onboarding network when they are connected and assigned to one another. Nevertheless it will be assumed to be separate as in not the Fig. 5 and par. 52 embodiment: ‘In Fig. 5, the onboarding network 30, 31 and the authentication module 40, 41 are located on the access point 50 or the additional access point Sl for both the multi-tenant virtual network 20 and the additional multi-tenant virtual network 21.’
The amendment and primary arguments of the amendment revolve around the generation of a ‘separate’ access network that is ‘structurally and logically distinct from both the onboarding network and the multi-tenant virtual network’, see p. 10. Applicant argues repeatedly that the Rooney configuration is a ‘monolithic’ Wi-Fi environment. Suggesting Rooney’s invention to be a ‘monolithic’ Wi-Fi environment is analogous to simplifying Applicant’s industrial network 10 as a monolithic network, while simplifying and discounting Rooney’s separate access point repeater 140, Rooney’s established onboarding network 190 and other devices and connections establishing the complex multi-network environment of Rooney.
Rooney discloses in par. 28 that the onboarding network 190 can connect via other devices or access points: “the repeater device 120 can connect to the onboarding network 190 and the router 160 via the first repeater 140 which acts as a virtual access point (VAP) for the onboarding network 190” (emphasis added). See also specification par. 20 that outlines the access point can be virtual. In other words, as is well known in the art, access points are simply typically wireless connection points to extend a network of a central gateway or router (that may also be wireless/ WiFi), and thus Rooney explicitly discloses that the router 160 creates/establishes such a temporary onboarding network, but that the access points using the router would allow the new device to be positioned in the new location which may use access points or repeaters to connect to that onboarding network.
The access point/repeater 140 generates its own access network that is created by that access point and connected to the onboarding network 190. This would allow the onboarding network to not simply be in small radius of the wi-fi router but, for example in a large environment needing repeaters as Rooney is oriented to, would allow devices in a much larger area of combined radii of the wifi router and repeater/mesh nodes to be onboarded.
In other words, looking at Fig. 1C, 2 of Rooney, access point 140 has it’s own access network separate from 190, new device 120 connecting up to 140 (shown in figure 2 and described in par. 28 for example) has the access point connect up with the router 160 that is connected to and creates the onboarding network 190.
Thus, the Examiner is interpreting the claimed access network as the access network of access point 140 the device to be onboarded is connecting and accessing the industrial network with, and the claimed onboarding ‘network’ as an onboarding authentication system (onboarding network and authentication module generated as claimed).
Pages 3-6 of the specification supports this interpretation as the definitions include ‘onboarding’ (notably, not ‘onboarding network’), described as being a process, while ‘access network’ is defined as that in which onboarding requests are accepted. While p. 6 does describe that ‘onboarding network’ has the ‘function of supporting or enabling the onboarding of a device’. And further as the figures show the onboarding network as being a rectangular box 30, while access network 50 is an oval. And as node 11 contains onboarding network 30 only connecting from interface 111 to authentication module 40.
Rooney teaches in par. 28 that “the repeater device 120 can connect to the onboarding network 190 and the router 160 via the first repeater 140 which acts as a virtual access point (VAP) for the onboarding network 190.” Applicant remarks do not address Rooney’s access point 140 at all.
Applicant simply repetitively argues Rooney to teach a “standard Wi-Fi mesh network”, a “conventional Wi-Fi mesh network”, a “single, monolithic mesh network”, while the claims having a “multi-layer environment” and “multi-layer architecture” (see at least p. 11). There are no claimed layers but rather networks connected to networks inside of networks as is conventional. Rooney’s patent is not a standard network but a system and method for onboarding in the mesh network described.
Applicant argues that Choukir does not disclose the limitation Choukir is mapped to disclose in above claim 1. Applicant argues Choukir has the wireless client be authenticated using its assigned IP address and this to be a credential or password needed to gain access.
However, first, Applicant is conflating credential with password, claim 1 only requires a password not be required. Choukir par. 40 specifies it being well known ‘authenticator 118 may compare credentials 204, e.g., a password and user name combination’. Choukir’s IP address is not a credential nor password. Second, Choukir discloses, in an analogous onboarding art, any device including wireless client 120 may send an onboarding request to an AP to access a network, the client is mapped to connect to onboarding VNID network 105A in order to then authenticate the client in order to have the client be connected to the virtual network 105 they are attempting to connect to, once they are authenticated a destination VNID network is determined (at least paragraph 19-21, 67-72). There is no ‘password’ needed or used by the client to access the network to attempt to gain full access, the device simply connects to an open network, an identifier (eg Ip address) of the device is compared to devices that are authenticated and can move on and connect to a closed network, no password required.
Schatzmann discloses in par. 17-18 drawbacks of prior systems where logging into and authenticating network equipment is undesirable for onboarding, or dumb devices not equipped with hardware or software for onboarding. Schatzmann provides an onboarding solution (par. 28-32) so that the devices only issue a registration request and an invitation is sent back, to these problems and thus is also applicable to claims 1, 4.
Regarding claim 7, Applicant argues that Schatzmann not teach “wherein the industrial network comprises at least one additional onboarding network, wherein the onboarding network is configured to onboard devices to the multi-tenant virtual network, and wherein the additional onboarding network is configured to onboard devices to the additional multi-tenant virtual network”. Applicant argues that Schatzmann recites a cross-tenant onboarding controller not “multiple onboarding networks structurally tied to a single industrial/multi-tenant environment as defined in claim 7.” However, claim 7 recites the additional onboarding network be for an additional multi-tenant virtual network, not a single as argued, a different structure. The argument appears to not align with the claim terminology and is thus moot as it is not clear on the structure and/or the domains being argued.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to GREGORY TODD whose telephone number is (303)297-4763. The examiner can normally be reached 8:30-5 MST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Nicholas Taylor can be reached on 571-272-3889. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/GREGORY TODD/Primary Examiner, Art Unit 2443