DETAILED NON-FINAL OFFICE ACTION
This action is responsive to the filing of a Reissue Application on 11/25/2022.
The instant application is a reissue application of U.S. Patent No. 10,848,460, hereinafter “the ‘460 Patent”. Based upon Applicant’s statements as set forth in the instant application and after the Examiner's independent review of the ‘460 Patent itself and its prosecution history, the Examiner finds that he cannot locate any ongoing proceeding before the Office or current ongoing litigation involving the ‘460 Patent. Furthermore, based upon the Examiner's independent review of the ‘460 Patent itself and the prosecution history, the Examiner cannot locate any previous reexaminations, supplemental examinations, or certificates of correction.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Reissue
For reissue applications filed on or after September 16, 2012, all references to 35 U.S.C. 251 and 37 CFR 1.172, 1.175, and 3.73 are to the current provisions. This reissue application was filed 11/25/2022. Thus, all references to 35 U.S.C. 251 and 37 CFR 1.172, 1.175, and 3.73 made in this application are to the current provisions.
Applicant is reminded of the continuing obligation under 37 CFR 1.178(b), to timely apprise the Office of any prior or concurrent proceed-ing in which the ‘460 Patent is or was involved. These proceedings would include interferences, reissues, reexaminations, and litigation.
Applicant is further reminded of the continuing obligation under 37 CFR 1.56, to timely apprise the Office of any information which is mate-rial to patentability of the claims under consideration in this reissue appli-cation.
These obligations rest with each individual associated with the filing and prosecution of this application for reissue. See also MPEP §§ 1404, 1442.01 and 1442.04.
Applicant is notified that any subsequent amendment to the specification and/or claims must comply with 37 CFR 1.173(b).
Response to Amendment
All amended claims have been reviewed. The amendments filed in the Response do not comply with 37 CFR 1.173 (d)(1), (g).
Claims
All amended claims have been amended with double brackets instead of single brackets. These are not compliant to the format required in reissue as stated in the MPEP. Please use example ‘A(2)’ as stated in MPEP 1453 for guidance in amending the claims.
“A. Original Patent Description or Patent Claim Amended
Example (2)
For changes to the claims, one must submit a copy of the entire patent claim with the amendments shown by underlining and bracketing, e.g.,
Amend claim 6 as follows:
Claim 6 (Amended). The apparatus of claim [5] 1 wherein the [first] second piezoelectric element is parallel to the [second] third piezoelectric element.
If the dependency of any original patent claim is to be changed by amendment, it is proper to make that original patent claim dependent upon a later filed higher numbered claim.”
Furthermore, the claims are not amended in reference to the patented claims.
(g) Amendments made relative to the patent. All amendments must be made relative to the patent specification, including the claims, and drawings, which are in effect as of the date of filing of the reissue application.
Example, Claim 1 is attempting to amend out the “a first system in a first part of the controlled interface”. However, the actual patented claims read, “a first controller in a first part of the controlled interface”. There are multiple instances of these issues that need addressing.
Rejection Under U.S.C. 251
The reissue oath/declaration filed with this application is defective (see 37 CFR 1.175 and MPEP § 1414) because of the following:
The reissue oath/declaration filed with this application is defective because it fails to contain the statement(s) required under 37 CFR 1.175 as to applicant’s belief that the original patent is wholly or partly inoperative or invalid. It is noted that the Oath/ Declaration is missing any statement as to what is in the claims are wholly or partly inoperative or invalid and if the Application is a broadening Application. Applicant is asked to submit a new Oath/ Declaration with the correct error statement.
Claims 1 – 19 are rejected as being based upon a defective reissue Oath/ Declaration under 35 U.S.C. 251 as set forth above. See 37 CFR 1.175.
The nature of the defect(s) in the Oath/ Declaration is set forth in the discussion above in this Office action.
Claim Rejections - 35 USC § 251 (Recapture)
Claims 9 – 19 are rejected under 35 U.S.C. 251 as being an impermissible recapture of broadened claimed subject matter surrendered in the application for the patent upon which the present reissue is based. See Greenliant Systems, Inc. et al v. Xicor LLC, 692 F.3d 1261, 103 USPQ2d 1951 (Fed. Cir. 2012); In re Shahram Mostafazadeh and Joseph O. Smith, 643 F.3d 1353, 98 USPQ2d 1639 (Fed. Cir. 2011); North American Container, Inc. v. Plastipak Packaging, Inc., 415 F.3d 1335, 75 USPQ2d 1545 (Fed. Cir. 2005); Pannu v. Storz Instruments Inc., 258 F.3d 1366, 59 USPQ2d 1597 (Fed. Cir. 2001); Hester Industries, Inc. v. Stein, Inc., 142 F.3d 1472, 46 USPQ2d 1641 (Fed. Cir. 1998); In re Clement, 131 F.3d 1464, 45 USPQ2d 1161 (Fed. Cir. 1997); Ball Corp. v. United States, 729 F.2d 1429, 1436, 221 USPQ 289, 295 (Fed. Cir. 1984). The reissue application contains claim(s) that are broader than the issued patent claims. The record of the application for the patent shows that the broadening aspect (in the reissue) relates to claimed subject matter that applicant previously surrendered during the prosecution of the application. Accordingly, the narrow scope of the claims in the patent was not an error within the meaning of 35 U.S.C. 251, and the broader scope of claim subject matter surrendered in the application for the patent cannot be recaptured by the filing of the present reissue application.
It is noted that the following is the three step test for determining recapture in reissue applications (see: MPEP 1412.02(I)):
“(1) first, we determine whether, and in what respect, the reissue claims are broader in scope than the original patent claims;
(2) next, we determine whether the broader aspects of the reissue claims relate to subject matter surrendered in the original prosecution; and
(3) finally, we determine whether the reissue claims were materially narrowed in other respects, so that the claims may not have been enlarged, and hence avoid the recapture rule.”
(Step 1: MPEP 1412.02(A)) In the instant case and by way of the preliminary amendment, Applicant seeks to broaden previously allowed claims in this reissue at least by deleting/omitting the patent claim 11 language requiring, “storing a first low-level protocol address in a first part of the controlled interface and a second low-level protocol address in a second part of the controlled interface, “high-level address”, “third low-level addressed”, which was specifically stated as one of a reasons for allowance in a Quayle Action dated 02/05/2020. Claim 19 is missing most of part (1) and almost all of part (2) of the allowed claim 1, which was the reasons for allowance dated 09/09/2020. Claim 9 has the “storing a first low-level protocol address for the first device in the first part of the controlled interface and the second low-level protocol address for the second device in the second part of the control interface” completely deleted.
(Step 2: MPEP 1412.02(B)) The record of the prior 16/693,477 application prosecution indicates that in the reasons for Quayle Action dated 02/05/2020 and the Allowance dated 09/09/2020 are specifically stated as one of the reasons for allowance with the prior art not teaching the stated above. Subject matter is previously surrendered during the prosecution of the original application by reliance on an argument/statement made by the Examiner that a of the claim(s) defines over the art. It is noted that a patent owner (reissue applicant) is bound by the argument that applicant relied upon to overcome an art rejection in the original application for the patent to be reissued, regardless of whether the Office adopted the argument in allowing the claims. Therefore, in the instant application the claimed are surrendered subject matter and the broadening of the reissue claims, as noted above, are clearly in the area of the surrendered subject matter, (See above “Step 1” for fully amended claim language that is underlined and specifically determined as the surrendered subject matter.).
(Step 3: MPEP 1412.02(C)) It is noted that the surrendered subject matter has been entirely eliminated from independent claims 9, 11, 18, and 19 in this reissue application. If surrendered subject matter has been entirely eliminated from a claim present in the reissue application, then a recapture rejection under 35 U.S.C. 251 is proper. Additionally, reissue claims 9, 11, 18, and 19 were not materially narrowed in other respects that relate to the surrendered subject matter to avoid recapture.
Therefore, improper recapture of broadened claimed subject matter surrendered in the application is clearly present in the instant reissue application.
APPLICATION DATA SHEET/FILING RECEIPT
The Applicant Data Sheet filed with the present reissue application filed on 11/25/2022 (hereinafter the “2022 ADS”) is objected to because it does not contain the proper Domestic Benefit information. The 2022 ADS should does not recite any of the continuity that is found on the ‘460 Patent. Examiners note that stating the present application is a "reissue continuation of" is not proper according to the guidelines outlined in the Reissue Application Filing Guide for Applications filed on or after September 16, 2012.1
Examiners also find that the Filing Receipt mailed 11/25/2022 (hereinafter the “2022 Filing Receipt”) reflects the improper/missing notation in the 2022 ADS. Accordingly, Applicant is also required in response to this action to file a request for a corrected filing receipt to reflect the changed/corrected Domestic Benefit/National Stage information. See MPEP §601.05(a)(II).
The ADS also does not have all the inventors listed. Applicant is asked to resubmit the ADS with the corrections needed.
35 U.S.C. 251 New Matter Rejection
Claims 1 - 8 and 19 are rejected under 35 U.S.C. 251 as being based upon new matter added to the patent for which reissue is sought. The added material which is not supported by the prior patent is as follows:
Claims 1, 5, 6, and 19 are rejected under 35 U.S.C. § 112(a) (and 35 U.S.C. § 251 for New Matter) because the newly added is reciting that the "second component causes IP (Internet Protocol) metadata... to be stripped" and that the "second component assigns a different protocol" lack written description support in the original patent specification (U.S. Patent No. 10,848,460). In the specification, the "second component" (element 210/222) is described as a media converter or network interface port (e.g., an RJ45/fiber physical converter), whereas the active stripping of metadata and assignment of low-level addresses was exclusively performed by the "first controller" or "first system" (element 208/226). The specification contains no disclosure of a media converter/network interface ("second component") independently executing higher-layer protocol stripping or protocol assignment logic.
All dependent claims are rejected because of their dependency on the above rejected independent claims.
Claim Rejections - 35 USC § 112
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112:
The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention.
Claims 1 - 8 and 19 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention.
Claims 1, 5, 6, and 19 are rejected under 35 U.S.C. § 112(a) (and 35 U.S.C. § 251 for New Matter) because the newly added s reciting that the "second component causes IP (Internet Protocol) metadata... to be stripped" and that the "second component assigns a different protocol" lack written description support in the original patent specification (U.S. Patent No. 10,848,460). In the specification, the "second component" (element 210/222) is described as a media converter or network interface port (e.g., an RJ45/fiber physical converter), whereas the active stripping of metadata and assignment of low-level addresses was exclusively performed by the "first controller" or "first system" (element 208/226). The specification contains no disclosure of a media converter/network interface ("second component") independently executing higher-layer protocol stripping or protocol assignment logic.
All dependent claims are rejected because of their dependency on the above rejected independent claims.
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1 – 17 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor, or for pre-AIA the applicant regards as the invention.
Claim 1 is rejected under 35 U.S.C. § 112(b) as indefinite in 1[a] for reciting "a first part of the controlled interface", which lacks clear structural boundaries given the deletion of the defining "first system" / "first controller" framework, creating ambiguity as to where the "first part" begins and ends relative to external network boundaries.
Claim 17 is rejected under 35 U.S.C. § 112(b) as indefinite for grammatical ambiguity and lack of antecedent basis in the phrase "a first connection and a second connection between the first part of the controlled interface and the second low-level protocol address are one of wired, fiber optic or wireless." A physical connection cannot structurally exist between a physical component and a logical "low-level protocol address."
All dependent claims are rejected because of their dependency on the above rejected independent claims.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of pre-AIA 35 U.S.C. 103(a) which forms the basis for all obviousness rejections set forth in this Office action:
(a) A patent may not be obtained though the invention is not identically disclosed or described as set forth in section 102, if the differences between the subject matter sought to be patented and the prior art are such that the subject matter as a whole would have been obvious at the time the invention was made to a person having ordinary skill in the art to which said subject matter pertains. Patentability shall not be negatived by the manner in which the invention was made.
Claims1–10 and 18–19 is/are rejected under pre-AIA 35 U.S.C. 103(a) as being unpatentable over Schaeffer U.S. Pat. No. 7,260,833, hereinafter “Schaeffer”, in view of McArdle et al. U.S. Pat. No. 7,587,759, hereinafter “McArdle”.
The Examiner will use the shorthand notation of “1:1 – 5” for Column 1, lines 1 – 5.
Claim 1
1[pre]: A controlled interface for managing data communicated between a first device and a second device, the controlled interface comprising:
Schaeffer discloses an interface apparatus for managing communications between computer systems,
"The present invention provides a sensitive network isolation apparatus that permits data to be sent to a remote computer or network without a return path so that the remote computer or network is not able to compromise the isolated sensitive network." (Schaeffer, Col. 2:3–7).
1[a]: a first component configured in a first part of the controlled interface, the first component communicating with the first device via a first network connection;
Schaeffer discloses an ingress media converter communicating with a sensitive workstation/network:
"The invention has a first media converter for receiving data from a workstation on a sensitive network..." (Schaeffer, Col. 2:9–11).
"In operation the workstation 10, usually part of a network or control station, transmits data on line 32 to a first media converter 26." (Schaeffer, Col. 3:10–13).
1[b]: a second component communicating with the first component;
Schaeffer discloses an internal signal transmission line linking media converter components within the isolation interface:
"The data packet is then transmitted over a short span of cable 30, such as ten (10) base T or other suitable cable, to a second media converter 28..." (Schaeffer, Col. 3:16–18).
1[c]: a third component configured in a second part of the controlled interface, the third component communicating with the second device via a second network connection;
Schaeffer discloses a second media converter output stage communicating with a destination remote computer/network:
" ...and then over transmission line 36, preferably fiber for better isolation, to a remote workstation 40. This workstation 40 may be a standalone unit or part of a network." (Schaeffer, Col. 3:18–22).
1[d]: "a fourth component configured in the second part of the controlled interface, the fourth component communicating with the third component, wherein:"
Schaeffer discloses interface egress logic receiving data at the output side of the interface for delivery to the receiving computer:
"The second media converter 28 must also be spoofed by the signal generator 22 that sends an idle signal over fiber 38 to the receive port of the second media converter 28." (Schaeffer, Col. 3:33–37).
1[e]: (1) the second component and the fourth component are directly connected via a first connection and a second connection such that a first unidirectional flow of data occurs on the first connection between the second component and the fourth component and a second unidirectional flow of data occurs on the second connection between the second component and the fourth component;
Schaeffer discloses direct unidirectional connections established by optical fibers between the interface modules:
"FIG. 3 is a further embodiment of the present invention 20 showing a decoupled transmission path 30 to provide additional isolation to the data line 32 from the sensitive network 10 to the remote network 40." (Schaeffer, Col. 2:66–Col. 3:3).
"The return path would physically not exist from the external network back to the control system..." (Schaeffer, Col. 6:9–11).
1[f]: (2) the first component receives first data from the first device
Schaeffer discloses receiving data from a sending workstation:
"The invention has a first media converter for receiving data from a workstation on a sensitive network..." (Schaeffer, Col. 2:9–11).
1[g]: (3) the second component causes IP (Internet Protocol) metadata used for a data transfer protocol associated with the first data to be stripped from the first data to terminate use of the data transfer protocol for the first data;
Schaeffer discloses using a proxy workstation/operator station to terminate connection-oriented transport protocols (such as SNMP/TCP) before passing raw data across the unidirectional link:
"The workstation can also act as a proxy for the broadcast to the isolation box 20 by gathering the SNMP data, gathering other monitoring data (periodically), and packaging the SNMP and other data in a UDP format." (Schaeffer, Col. 6:53–58).
To the extent that Schaeffer does not explicitly recite stripping higher-layer IP header metadata during proxy conversion, McArdle teaches evaluating incoming network traffic against rule conditions in a network gateway to filter out and strip unwanted packet header metadata, thereby terminating higher-layer transport protocol handling:
"System 100 applies a filter 103 based on the active networked applications 105 to a full ruleset 107 so only those intrusion rules corresponding to the active networked applications are used to evaluate 101 incoming and outgoing network traffic." (McArdle, Col. 2:42–46).
1[h]: (4) the second component assigns a different protocol than the data transfer protocol to the first data;
Schaeffer teaches converting connection-oriented protocols to connectionless broadcast datagram protocols:
"The workstation can also act as a proxy for the broadcast to the isolation box 20 by gathering the SNMP data, gathering other monitoring data (periodically), and packaging the SNMP and other data in a UDP format." (Schaeffer, Col. 6:53–58).
1[i]:"(5) the second component transmits the first data to the fourth component on the first connection according to the different protocol for communication to the fourth component.
Schaeffer discloses transmitting the converted connectionless data across the isolation link to the destination:
"The compiled data can be sent by a broadcast UDP transmission from the operator station to the network switch and then externally via the isolation box 20 and single fiber 36 transmission." (Schaeffer, Col. 6:58–61).
It would have been obvious to a PHOSITA at the time of the invention to combine the unidirectional proxy gateway of Schaeffer with the traffic filtering and header stripping techniques of McArdle. Motivation arises from standard network security practice: stripping higher-layer IP protocol metadata and converting connection-oriented packets to connectionless UDP frames across a proxy boundary prevents unauthorized return-channel exploitation, eliminates covert channel vulnerabilities, and enforces true protocol isolation across unidirectional security gates.
Claim 2
The controlled interface of claim 1, wherein there is no other connection or communication between the first part of the controlled interface and the second part of the controlled interface other than the first connection and the second connection.
Schaeffer explicitly discloses physical isolation where no other physical connection exists:
"No physical connection exists for the remote computer workstation to compromise the sensitive network." (Schaeffer, Col. 2:17–18).
"The return path would physically not exist from the external network back to the control system, so connection oriented protocols would not be able to use the link..." (Schaeffer, Col. 6:9–13).
Claim 3
The controlled interface of claim 1,wherein the first connection and the second connection are one of wired, fiber optic or wireless.
Schaeffer discloses optical fiber physical transmission lines:
"An optical signal generator sends signals to the workstation to imitate a standard transmit and receive connection, and also sends signals to the second media converter to imitate a standard transmit and receive connection." (Schaeffer, Col. 2:12–16).
"The backbone physical media is either multimode optical fiber for OC-3c installations or single mode optical fiber for OC-12c or gigabit Ethernet." (Schaeffer, Col. 4:37–40).
Claim 4
The controlled interface of claim 1, wherein the third component receives second data from the second device, the second system causes IP protocol metadata associated with the second data to be stripped from the second data, the second system assigns a second low-level address to the second data according to the addressing protocol, and the fourth component transmits the second data to the second component on the second connection according to the second low-level address for communication to the second component.
Schaeffer discloses signal paths linking interconnected workstations and network switches across physical channels (Schaeffer, Col. 3:10–38). McArdle teaches symmetrical traffic processing in network nodes wherein return packets are filtered, stripped of high-level protocol headers, and assigned low-level destination addresses for transmission across isolated channels (McArdle, Col. 2:48–58).
Claim 5
The controlled interface of claim 1, wherein when a receive port on the second component detects a rise in voltage indicating an intent to transmit data on the receive port, the first component or the second component performs a corrective action.
Schaeffer discloses line monitoring and signal spoofing mechanisms that detect line state and enforce one-way transmission integrity:
"In order for such transmissions to be sent normally, the sensitive workstation 10 must be fooled into recognizing a connection that does not in fact exist. This is accomplished by having a signal generator 22 send an idle signal on a data line 34 to the receive port of the workstation 10." (Schaeffer, Col. 2:53–57).
Claim 6
The controlled interface of claim 1, wherein at least one of the first component or the second component stores low-level hardware addresses configured to identify at least one or more of an address, a protocol type or port, and a device name.
Schaeffer discloses storing source/destination addresses, software ports, and network device parameters in header processing tables:
"The UDP datagram includes the digital data plus overhead information including 16 bit source and 16 bit destination software 'ports', a 16 bit field with the length of the UDP datagram, and a 16 bit checksum." (Schaeffer, Col. 5:7–11).
"Each networked DAU has an IP address that identifies it as the source of the information." (Schaeffer, Col. 5:1–2).
Claim 7
The controlled interface of claim 6, wherein the protocol type comprises at least one or more of Ethernet, TCP, UDP, UDP multicast, or other web service.
Schaeffer explicitly discloses handling Ethernet, TCP, UDP, and SNMP protocol types:
"The UDP datagram is then encapsulated by the system software into an Internet Protocol (IP) datagram per RFC 791." (Schaeffer, Col. 5:21–23).
"The ISC network switches 12 have 10 megabit per second, 10 Base FL, interface ports for workstations and DAU's." (Schaeffer, Col. 7:6–8).
Claim 8
The controlled interface of claim 6, wherein the address comprises an address used to communicate a data stream from the second component to the fourth component through one or more of the first connection and the second connection.
Schaeffer discloses using broadcast destination addresses to transmit data streams across isolation lines:
"The IP broadcast destination is the network # with the node identified as all 1's; in the case of ISC which has a class C address, the broadcast address is the network#.255..." (Schaeffer, Col. 5:34–37).
Claim 9
A method of communicating signals between a first device and a second device via a controlled interface, wherein the controlled interface comprises:
a first component configured in the first part of the controlled interface, the first component communicating with the first device via a first network connection; a second component communicating with the first component;
a third component configured in a second part of the controlled interface, the third component communicating with the second device via a second network connection;
a fourth component configured in the second part of the controlled interface, the fourth component communicating with the third component, the method comprising:
Schaeffer discloses an interface apparatus and method for managing communications between computer systems:
"The present invention provides a sensitive network isolation apparatus that permits data to be sent to a remote computer or network without a return path so that the remote computer or network is not able to compromise the isolated sensitive network." (Schaeffer, Col. 2:3–7).
9[a]: receiving a first signal from the first device at the first component;
Schaeffer discloses receiving data from a sending workstation:
"The invention has a first media converter for receiving data from a workstation on a sensitive network..." (Schaeffer, Col. 2:9–11).
9[b]: communicating the first signal to the second component;
Schaeffer discloses passing data to a second media converter:
" ...this data is then passed to a second media converter..." (Schaeffer, Col. 2:11).
9[c]: transmitting, via the first network connection from the second component to the fourth component, the first signal according to a first low-level protocol address;
Schaeffer discloses transmitting data framed according to link/broadcast addresses across the isolation line:
"The IP datagram is then encapsulated in an Ethernet packet and sent out on the network." (Schaeffer, Col. 5:38–39).
9[d]: receiving the first signal at the fourth component to yield a first received signal;
Schaeffer discloses receiving data at the egress media converter output stage (Schaeffer, Col. 3:18–37).
9[e]: communicating the first received signal to the third component; and
Schaeffer discloses passing received signals through the egress interface to the destination network (Schaeffer, Col. 3:18–22).
9[f]: transmitting the first received signal from the third component to the second device according to a second low-level protocol address.
Schaeffer in view of McArdle teaches delivering data from the output interface to the destination device formatted with destination link layer addressing (Schaeffer, Col. 3:18–22; McArdle, Col. 2:42–58). It would have been obvious to a person skill in the art to combine the prior art of McArdle with Schaeffer because of similar reasons stated above.
Claim 10
The method of claim 9, further comprising: receiving a second signal from the second device at the third component; communicating the second signal to the fourth component; transmitting, via the second network connection from the fourth component to the second component, the second signal according to the second low-level protocol address; receiving the second signal at the second component to yield a second received signal; communicating the second received signal to the first component; and transmitting the second received signal from the first component to the first device according to the first low-level protocol address.
Schaeffer in view of McArdle discloses symmetrical reverse method steps for routing return signals across an isolated channel using low-level protocol addressing (Schaeffer, Col. 3:10–38; McArdle, Col. 2:48–58). It would have been obvious to a person skill in the art to combine the prior art of McArdle with Schaeffer because of similar reasons stated above.
Claim 18
18[pre]: A system for managing data communicated between a first device and a second device, the system comprising: at least one processor; and a computer-readable storage device storing instructions which, when executed by the at least one processor, cause the at least one processor to perform operations comprising:
Schaeffer discloses a processor and computer performing instructions, (e.g., Schaeffer, Figs. 2 – 4 and supporting sections of the specification.). McArdle also teaches a computer-readable medium and processor executing stored security instructions:
"The computer system 51 includes a processing unit 55, which can be a conventional microprocessor such as an Intel Pentium microprocessor or Motorola Power PC microprocessor. Memory 59 is coupled to the processor 55 by a bus 57." (McArdle, Col. 5:55–58).
"One of skill in the art will immediately recognize that the term 'computer-readable medium' includes any type of storage device that is accessible by the processor 55..." (McArdle, Col. 6:14–17).
18[a]: receiving a first payload from the first device at the first part of the controlled interface, the first payload having first high-level addressing data;
Schaeffer discloses receiving IP datagram payloads containing high-level destination addresses:
"The IP datagram can be broken into two parts, the header and the data." (Schaeffer, Col. 5:23–24).
18[b]: stripping the first high-level addressing data associated with the first payload to yield a second payload;
McArdle in view of Schaeffer teaches evaluating packet headers and stripping higher-layer IP addressing data to yield raw payload data (McArdle, Col. 2:42–50; Schaeffer, Col. 6:53–58).
18[c]: associating a first low-level protocol address with the second payload to yield a third payload;
Schaeffer discloses attaching local Ethernet link headers to UDP datagram payloads:
"The IP datagram is then encapsulated in an Ethernet packet and sent out on the network." (Schaeffer, Col. 5:38–39).
18[d]: transmitting the third payload over a first direct network connection between the first part of the controlled interface and a second part of the controlled interface, wherein the first part of the controlled interface and the second part of the controlled interface are only connected via one or more direct connections for communicating low-level protocol addressed data;
Schaeffer discloses transmitting framed data over direct optical lines where no return path exists:
"No physical connection exists for the remote computer workstation to compromise the sensitive network." (Schaeffer, Col. 2:17–18).
"The return path would physically not exist from the external network back to the control system..." (Schaeffer, Col. 6:9–11).
18[e]: stripping, at the second part of the controlled interface, the first low-level protocol address associated with the third payload to yield a fourth payload;
Schaeffer in view of McArdle teaches stripping link-layer Ethernet headers at the receiving interface module to extract the raw payload (Schaeffer, Col. 3:18–22; McArdle, Col. 2:42–50). McArdle teaches evaluating incoming network traffic against rule conditions in a network gateway to filter out and strip unwanted packet header metadata, thereby terminating higher-layer transport protocol handling:
"System 100 applies a filter 103 based on the active networked applications 105 to a full ruleset 107 so only those intrusion rules corresponding to the active networked applications are used to evaluate 101 incoming and outgoing network traffic." (McArdle, Col. 2:42–46).
It would have been obvious to a person skill in the art to combine the prior art of McArdle with Schaeffer because of similar reasons stated above.
18[f]: associating a second high-level addressing data to the fourth payload to yield a fifth payload; and
Schaeffer discloses re-encapsulating payloads with new IP addressing data for delivery to external destination networks (Schaeffer, Col. 6:53–61).
18[g]: transmitting the fifth payload from the second part of the controlled interface to the second device.
Schaeffer discloses transmitting the re-addressed payload to the remote destination workstation (Schaeffer, Col. 3:18–22).
Claim 19
19[pre]: A controlled interface for managing data communicated between a first device and a second device, the controlled interface comprising:
Schaeffer discloses a controlled interface managing data between devices (Schaeffer, Col. 2:3–7; Col. 7:41–45).
19[a]: a first network interface configured in a first part of the controlled interface, the first network interface communicating with the first device via a first network connection to receive first data from the first device;
Schaeffer discloses a first media converter receiving data from a workstation on a network (Schaeffer, Col. 2:9–11).
19[b]: a first component configured in the first part of the controlled interface and communicating with the first network interface, wherein the first component is configured to terminate use of a data transfer protocol for the first data and to assign a different protocol than the data transfer protocol to the first data to yield modified first data;
Schaeffer in view of McArdle teaches an interface proxy component configured to terminate connection-oriented protocols and assign a different connectionless protocol to yield modified data:
"The workstation can also act as a proxy for the broadcast to the isolation box 20 by gathering the SNMP data, gathering other monitoring data (periodically), and packaging the SNMP and other data in a UDP format." (Schaeffer, Col. 6:53–58).
19[c]: a second network interface configured in a second part of the controlled interface, the second network interface communicating with the second device via a second network connection; and
Schaeffer discloses an output interface stage communicating with a remote workstation (Schaeffer, Col. 3:18–22).
19[d]: a second component configured in the second part of the controlled interface, the second component communicating with the second network interface, wherein the first component and the second component are directly connected such that a first unidirectional flow of data occurs via a first connection between the first component and the second component and a second unidirectional flow of data occurs via a second connection between the first component and the second component, wherein the first component transmits the modified first data to the second component on the first connection according to the different protocol.
Schaeffer discloses interface modules connected via optical fiber lines establishing unidirectional data flow (Schaeffer, Col. 2:12–18; Col. 3:10–38). McArdle teaches evaluating incoming network traffic against rule conditions in a network gateway to filter out and strip unwanted packet header metadata, thereby terminating higher-layer transport protocol handling:
"System 100 applies a filter 103 based on the active networked applications 105 to a full ruleset 107 so only those intrusion rules corresponding to the active networked applications are used to evaluate 101 incoming and outgoing network traffic." (McArdle, Col. 2:42–46).
It would have been obvious to a person skill in the art to combine the prior art of McArdle with Schaeffer because of similar reasons stated above.
Claims 11–17 is/are rejected under pre-AIA 35 U.S.C. 103(a) as being unpatentable over Schaeffer and McArdle, in further view of Booth 7,984,187, hereinafter “Booth”.
Claim 11
11[pre]: A method of using a controlled interface for managing data communicated between a first device and a second device, the method comprising:
Schaeffer in view of McArdle discloses a method of using a controlled interface for managing data between devices (see Ground 1 mapping for Claims 1 and 9; Schaeffer, Col. 2:3–7).
11[a]: receiving a first payload from the first device at the first part of the controlled interface, the first payload having first high-level addressing data;
Schaeffer discloses receiving IP datagram payloads containing high-level destination addresses (Schaeffer, Col. 5:23–24).
11[b]: stripping the first high-level addressing data associated with the first payload to yield a second payload;
McArdle in view of Schaeffer teaches stripping higher-layer IP addressing headers from the payload (McArdle, Col. 2:42–50; Schaeffer, Col. 6:53–58).
It would have been obvious to a person skill in the art to combine the prior art of McArdle with Schaeffer because of similar reasons stated above.
11[c]: associating a first low-level protocol address with the second payload to yield a third payload;
Schaeffer discloses attaching local Ethernet link addressing to UDP payloads (Schaeffer, Col. 5:38–39).
11[d]: transmitting the third payload over a first direct network connection between the first part of the controlled interface and a second part of the controlled interface, wherein the first part of the controlled interface and the second part of the controlled interface are only connected via one or more direct connections for communicating low-level protocol addressed data;
Schaeffer discloses transmitting framed data over direct optical connections (Schaeffer, Col. 2:17–18). Booth further teaches establishing automated network request connections between network interfaces according to locator rules and parsing heuristics:
"In the illustrative embodiment, electronic interface 21 connects system CPU 12 with at least one content provider 23 accessible, for example, from a communications network such as the internet." ( Booth, Col. 1:37–40).
"Control and data information can be electronically executed and stored on computer-readable media, such as computer readable medium 27." ( Booth, Col. 6:65–68).
11[e]: stripping, at the second part of the controlled interface, the first low-level protocol address associated with the payload to yield a fourth payload;
Schaeffer in view of McArdle teaches stripping link-layer Ethernet headers at the receiving interface module (Schaeffer, Col. 3:18–22; McArdle, Col. 2:42–50).
11[f]: associating a second high-level addressing data to the fourth payload to yield a fifth payload; and
Schaeffer discloses re-encapsulating payloads with new IP addressing data (Schaeffer, Col. 6:53–61).
11[g]: transmitting the fifth payload from the second part of the controlled interface to the second device.
Schaeffer discloses transmitting the re-addressed payload to the remote destination device (Schaeffer, Col. 3:18–22).
It would have been obvious to a PHOSITA to combine Schaeffer, McArdle, and Booth. Booth teaches automated content request formulation and parsing heuristics across network interfaces. Incorporating Booth's automated request formulation into the unidirectional proxy interface of Schaeffer / McArdle enables automated, rule-driven formatting of low-level data frames across isolated hardware bridges, enhancing system throughput and operational efficiency without compromising physical layer security.
Claim 12
The method of claim 11, further comprising: receiving a sixth payload from the second device at the second part of the controlled interface, the sixth payload having second high-level addressing data; stripping the second high-level addressing data associated with the sixth payload to yield a seventh payload; associating the second low-level protocol address with the seventh payload to yield an eighth payload; transmitting the eighth payload over a second direct network connection between the second part of the controlled interface and the first part of the controlled interface; stripping, at the first part of the controlled interface, the second low-level protocol address associated with the eighth payload to yield a ninth payload; associating the first high-level addressing data to the ninth payload to yield a tenth payload; and transmitting the tenth payload from the first part of the controlled interface to the first device.
Schaeffer, McArdle, and Booth in combination disclose symmetrical reverse method steps for receiving return payload data from the second device, stripping high-level headers, attaching low-level protocol addresses, transmitting over a second direct unidirectional connection, stripping low-level addresses, re-associating high-level addresses, and delivering to the first device (Schaeffer, Col. 3:10–38; McArdle, Col. 2:48–58; Booth, Col. 1:31–55). It would have been obvious to a person skill in the art to combine the prior art of McArdle with Schaeffer because of similar reasons stated above.
Claim 13
The method of claim 11, wherein at least one of the first part of the controlled interface and the second part of the controlled interface stores low-level hardware addresses configured to identify at least one or more of an address, a protocol type, and a device name.
Schaeffer discloses storing source/destination IP addresses, software ports, and device identifiers (Schaeffer, Col. 5:1–11).
Claim 14
The method of claim 13, wherein the protocol type comprises at least one or more of Ethernet, TCP, UDP, UDP multicast, or other web service.
Schaeffer explicitly discloses Ethernet, TCP, UDP, and SNMP protocols (Schaeffer, Col. 5:21–23; Col. 7:6–8).
Claim 15
The method of claim 14, wherein the address comprises an address used to communicate a data stream from the first part of the controlled interface to the second part of the controlled interface.
Schaeffer teaches utilizing stored broadcast addresses to communicate data streams across internal interface connections (Schaeffer, Col. 5:34–37).
Claim 16
The method of claim 11, wherein the first part of the controlled interface is connected to the first device and the second part of the controlled interface is connected to the second device.
Schaeffer discloses the first part connected to the first workstation and the second part connected to the remote workstation (Schaeffer, Col. 2:3–18; Col. 3:10–22).
Claim 17
The method of claim 11, a first connection and a second connection between the first part of the controlled interface and the second low-level protocol address are one of wired, fiber optic or wireless.
Schaeffer discloses physical optical fiber signal lines connecting interface stages (Schaeffer, Col. 2:12–16; Col. 4:37–40).
Conclusion
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to DAVID E. ENGLAND whose telephone number is (571)272-3912. The examiner can normally be reached on M-F 8:00-5:00.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Michael Fuelling can be reached on 571-270-1367. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
DAVID E. ENGLAND
Primary Examiner
Art Unit 3992
/DAVID E ENGLAND/Primary Examiner, Art Unit 3992
Conferees:
/CHARLES R CRAVER/Reexamination Specialist, Art Unit 3992 /M.F/Supervisory Patent Examiner, Art Unit 3992
1 See http://www.uspto.gov/sites/default/files/forms/uspto_reissue_ads_guide_Sept2014.pdf