DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Amendment/Remarks
This communication is considered fully responsive to the amendment filed on 09/18/2025.
Claims 1-20 are pending and are examined in this office action.
Claims 1, 3, 10, 14, 16, 19 have been amended.
No new claim has been added and no claim has been canceled.
Response to Arguments
Applicant’s arguments, filed on 09/18/2025, with respect to claims have been considered but are moot because the arguments do not apply to any of the references being used in the current rejection. The Examiner found features modified to claims, i.e claim 1 as “1. (Currently amended) A method of forwarding control plane messages and data plane messages in an SD-PMN (software-defined private mobile network, comprising:
Providing the SD-PMN with a split control plane architecture, wherein a first set of control plane components comprising a UPF (user plane function), a security gateway, an AMF (access and mobility management function), and an SMF (session management function) is deployed to each branch site in a plurality of branch sites connected by the SD-PMN and a second set of control plane components comprising a UDM (unified data management) is deployed to each SD- WAN (software-defined wide area network) PoP (point of presence) in a plurality of SD-WAN PoPs connected by the SD-PMN; and
at a particular security gateway deployed to a particular branch site in the plurality of branch sites:
receiving a first data message originating from a first user device of a plurality of user devices operating at the particular branch site and a second data message from a second user device of the plurality of user devices;
determining (i) that the first data message comprises a control plane first data message and (ii) that the second data message comprises a data plane second data message; and
based on the determinations, (i) forwarding the control plane first data message to the AMF deployed to the particular branch site for user authentication by a particular UDM at a particular SD- WAN PoP, and (ij forwarding the data plane second data message to the UPF deployed to the particular branch site.”
that have changed the scope of the invention, Therefore, Applicant’s remarks regarding rejection under 35 U.S.C 103 for the claims are moot. Applicant's remarks are considered as forward looking statement for the newly reconstructed claims.
In view of the applicant’s amendment to the claims, the examiner has clarified and remapped the rejection to the argued claim limitations in details, using the prior art of record in the current prosecution of the claims as well a new prior art. See OSWAL et al. (US 20220141254 A1; hereinafter as “OSWAL”) in view of ALNÅS et al. (US 20230140789 A1; hereinafter as “ALNÅS”).
Information Disclosure Statement
The information disclosure statements (IDS) submitted on 09/18/2025 have been placed in record and considered by the examiner.
Allowable Subject Matter
Claims 10-13, 19-20 is objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13.
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying -online/eterminal-disclaimer.
Claims 1-20 rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1-20 of US Patent US 12356191 B2.
Although the conflicting claims are not identical, they are not patentably distinct from each other in light of the following evidences to compare independent claims only:
Current application’s claims: 18071537
US Patent US 12356191 B2.
1. (Currently amended) A method of forwarding control plane messages and data plane messages in an SD-PMN (software-defined private mobile network, comprising:
Providing the SD-PMN with a split control plane architecture, wherein a first set of control plane components comprising a UPF (user plane function), a security gateway, an AMF (access and mobility management function), and an SMF (session management function) is deployed to each branch site in a plurality of branch sites connected by the SD-PMN and a second set of control plane components comprising a UDM (unified data management) is deployed to each SD- WAN (software-defined wide area network) PoP (point of presence) in a plurality of SD-WAN PoPs connected by the SD-PMN; and
at a particular security gateway deployed to a particular branch site in the plurality of branch sites:
receiving a first data message originating from a first user device of a plurality of user devices operating at the particular branch site and a second data message from a second user device of the plurality of user devices;
determining (i) that the first data message comprises a control plane first data message and (ii) that the second data message comprises a data plane second data message; and
based on the determinations, (i) forwarding the control plane first data message to the AMF deployed to the particular branch site for user authentication by a particular UDM at a particular SD- WAN PoP, and (ij forwarding the data plane second data message to the UPF deployed to the particular branch site.
1. A method of forwarding control plane messages and data plane messages in an SD-PMN (software-defined PMN), the SD-PMN comprising a split control plane architecture, wherein a first set of control plane components comprising a UPF (user plane function) is deployed to each branch site in a plurality of branch sites connected by the SD-PMN and a second set of control plane components comprising a security gateway, an AMF (access and mobility management function), an SMF (session management function), and a UDM (unified data management) is deployed to each SD-WAN PoP in a plurality of SD-WAN PoPs connected by the SD-PMN, the method comprising: at a particular UPF deployed to a particular branch site in the plurality of branch sites: establishing a GTP (GPRS (general packet radio service) tunneling protocol) tunnel with each physical access point in a set of physical access points deployed to the particular branch site; receiving a first data message from a particular physical access point in the set of physical access points, the first data message encapsulated with a GTP header; removing the GTP header from the first data message and converting the first data message to IP (internet protocol) traffic; and forwarding the first data message as IP traffic toward a destination of the first data message; wherein an SD-WAN edge router forwards the data message to a particular SD-WAN PoP in the plurality of SD-WAN PoPs connected by the SD-PMN for processing by a service chain at the particular SD-WAN PoP, the particular SD-WAN PoP comprising a SASE (secure access service edge) PoP and the service chain comprises a SASE service chain located at the SASE PoP.
14. (Currently amended) A non-transitory machine readable medium storing program for execution by a set of processing units, the program for a security gateway for forwarding control plane messages and data plane messages in an SD-PMN (software-defined private mobile network, the program comprising sets of instructions for:
receiving a first data message originating from a first user device of a plurality of user devices operating at a particular branch site of a plurality of branch sites connected by the SD-PMN and a second data message from a second user device of the plurality of user devices,
the particular branch site including a first set of control plane components that includes a UPF (user plane function), a security gateway, an AMF (access and mobility management function), and an SMF (session management function);
determining (i) that the first data message comprises a control plane first data message and (ii) that the second data message comprises a data plane second data message; and
based on the determinations,
(i) forwarding the control plane first data message to the AMF deployed to the particular branch site for user authentication by a particular UDM (unified data management) at a particular SD-WAN (software-defined wide area network) PoP (point of presence) in a plurality of SD-WAN PoPs connected to the SD-PMN, and
(ii) forwarding the data plane second data message to the UPF deployed to the particular branch sites wherein the particular UDM belongs to a second set of control plane components which, together with the first set of control plane components, provides a split control plane architecture.
10. A non-transitory machine readable medium storing a program for execution by a set of processing units, the program for a particular UPF (user plane function) for forwarding control plane messages and data plane messages in an SD-PMN (software-defined PMN), the SD-PMN comprising a split control plane architecture, wherein a first set of control plane components comprising a UPF (user plane function) is deployed to each branch site in a plurality of branch sites connected by the SD-PMN and a second set of control plane components comprising a security gateway, an AMF (access and mobility management function), an SMF (session management function), and a UDM (unified data management) is deployed to each SD-WAN PoP in a plurality of SD-WAN PoPs connected by the SD-PMN, the particular UPF deployed to a particular branch site in the plurality of branch sites, the program comprising sets of instructions for: establishing a GTP (GPRS (general packet radio service) tunneling protocol) tunnel with each physical access point in a set of physical access points deployed to the particular branch site; receiving a first data message from a particular physical access point in the set of physical access points, the first data message encapsulated with a GTP header; removing the GTP header from the first data message and converting the first data message to IP (internet protocol) traffic; and forwarding the first data message as IP traffic toward a destination of the first data message; wherein the destination of the first data message is located at the particular branch site and the set of instructions for forwarding the first data message as IP traffic toward the destination of the first data message comprises a set of instructions for forwarding the first data message as IP traffic directly to the destination at the particular branch site.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-2, 9, 14-15, 18 are rejected under 35 U.S.C. 103 as being unpatentable over OSWAL et al. (US 20220141254 A1; hereinafter as “OSWAL”) in view of ALNÅS et al. (US 20250211564 A1; hereinafter as “ALNÅS”).
Examiner’s note: in what follows, references are drawn to OSWAL unless otherwise mentioned.
Regarding claim 1, OSWAL teaches, A method of forwarding control plane messages and data plane messages in an SD-PMN (software-defined private mobile network (see fig. 1B where Software Device network with Branch Office (s) and Region Data Center/Hub/POP are shown and they are connected with IPSec tunnels for exchange control and data : [0058[; aforesaid SD-WAN separate control plane and data plane traffic where control plane stay within headquarter /branch office and data plane traffic a remote/POP which are connected to each other by secure IPSec Tunnel: “ SD-WAN technology generally uses the principles of software-defined networking (SDN) and separates the control plane and the data plane. Based on this principle, SD-WAN deployments generally include the following components: (1) a controller that administrators use to centrally configure WAN topologies and define traffic path rules; and (2) SD-WAN edge devices, either physical or virtual, that reside at every site and act as the connection and termination points of the SD-WAN fabric”: [0051]-[0056]); SD-WAN private network: [0057], comprising;
PNG
media_image1.png
560
726
media_image1.png
Greyscale
PNG
media_image2.png
597
729
media_image2.png
Greyscale
Providing the SD-PMN with a split control plane architecture
(see fig SD-WAN Fabric with branch office and Regional Data Center/HUB for split data with IPSec tunnel: [0058]; “ FIGS. 1A-1B are system environment diagrams including example SD-WAN architectures and a security service in accordance with some embodiments. These example system diagrams generally illustrate a security service for securing branch office and headquarter sites with SD-WAN connections in communication with a security service (e.g., a cloud-based security service).” (==split control of architecture ): [0051]; Fig. 3 ‘ “ SD-WAN device or VPN client is in the data plane and performs the function of split tunneling. As such, the SD-WAN device or VPN client can determine which flows are being sent to the cloud, Internet, or another enterprise site, thereby bypassing the cloud security service, and therefore, the SD-WAN device or VPN client can be intelligently configured for collecting data (e.g., in varying levels of granularity) for the traffic routed over these example different paths to facilitate consistent monitoring and analytics for security insights for network and security functions for a cloud-based security service solution.”: [0047]),
at a particular security gateway (==on-prem GW in Fig. 2) deployed to a particular branch site in the plurality of branch sites (branch office with security check : “ FIGS. 1A and 1B as will be described below. : [0031]; “ SD-WAN Type 1 deployment (e.g., branches and headquarters deployment), at each branch site, organizations can deploy one or more SD-WAN edge devices (=a particular security gateway as shown in fig. 2) and connect them to form an SD-WAN fabric or SD-WAN overlay. Administrators use the SD-WAN controller, based either in the cloud or on the organization's premises, to manage and configure these edge devices and define the traffic forwarding policies at each site”: [0051]; [0052]; “ received at a network gateway (==a particular security gateway in claim ) of a security service from a software-defined wide area network (SD-WAN) device. For example, the security service can be a cloud-based security service”: [0093]; apply security policy at the SD-WAN gateway/device : [0095]; NOTE: Security check at Branch office or at Cloud ; [0062]-[0065]):
receiving a first data message originating from a first user device of a plurality of user devices operating at the particular branch site and a second data message from a second user device of the plurality of user devices (see fig. 3 where SD-WAN Branch Office 1 receives “YouTube” data from YouTube as shown in Fig. 3: “ Referring to FIG. 3, network traffic for a YouTube service 340 (==first data message ) is whitelisted and configured to be routed from branches/headquarters from SD-WAN devices/elements such as shown at 302A to the Internet and to bypass security service 320 as shown at 312a”: [0072]; “ In an enterprise network in which traffic engineering allows for policies to permit certain types of traffic to be white listed and allowed to exit a branch or an endpoint device (e.g., a split tunnel configuration, such as for certain types of traffic such as Netflix (==second data message from a second user device ) or YouTube (==a first data message from a first user device ) to be whitelisted), security monitoring can be impaired as the white listed traffic will bypass the cloud security function. Enterprises typically allow a subset of applications to exit, for example, the branch directly to the Internet, which can be performed using an SD-WAN traffic forwarding policy.”: [0072] );
While OSWAL teaches, “ Providing the SD-PMN with a split control plane architecture”,
OSWAL does not expressively disclose:
wherein a first set of control plane components comprising a UPF (user plane function), a security gateway, an AMF (access and mobility management function), and an SMF (session management function) is deployed to each branch site in a plurality of branch sites connected by the SD-PMN and
a second set of control plane components comprising a UDM (united data management ) is deployed to each SD-WAN (software-defined wide area network ) PoP in a plurality of SD-WAN PoPs (point of presence ) connected by the SD-PMN ; and
determining (i) that the first data message comprises a control plane first data message and (ii) that the second data message comprises a data plane second data message
based on the determinations, (i) forwarding the control plane first data message to the AMF deployed to the particular branch site for user authentication by a particular UDM at a particular SD- WAN PoP, and (ij forwarding the data plane second data message to the UPF deployed to the particular branch site.
ALNÅS, in the same field of endeavor, discloses:
PNG
media_image3.png
472
902
media_image3.png
Greyscale
wherein a first set of control plane components comprising a UPF (user plane function), a security gateway, an AMF (access and mobility management function), and an SMF (session management function) is deployed to each branch site in a plurality of branch sites connected by the SD-PMN (CN100A and CN100B are two branch sides connect with wireless network )( first set of control functions includes, UPF, a security gateway, AMF : [0029]; see fig. 1 : CN110B includes AMF, SMF, UPF and connect to CN110A using wireless network, VPLMN: “ CN 110A may e.g. comprise a UDM node (Unified data management), configured to manage network user data in a single, centralized element. CN 110A may further comprise a NEF (Network Exposure Function) node, a functional element that supports exposure of network capabilities and events provided by 3GPP Network Functions to an application function. The NEF may further be used for accessing untrusted EASs external to the network 100A. Further comprised is an AF (Application Function), which supports application influence on traffic routing, accessing NEF, interaction with policy framework for policy control. An SMF (Session Management function) supports session management, such as session establishment, modification, and release, UE IP address allocation & management, etc. A SEPP (Security Edge Protection Proxy) node enables secure interconnect between 5G networks. The wireless network 100A further comprises a UPF (User Plane Function), which is responsible for packet routing and forwarding, packet inspection, QoS handling, and external PDU (protocol data unit) session for interconnecting Data Network (DN) in the 5G architecture. In the context of 5G, the PDU Session provides a logical connection between applications on a UE and a data network (DN) such as the Internet or private corporate networks.”: [0029]) and
a second set of control plane components comprising a UDM (united data management ) is deployed to each SD-WAN (software-defined wide area network ) PoP in a plurality of SD-WAN PoPs (point of presence ) connected by the SD-PMN (see fig. 1 CN 110A (==second set of control plane ) may e.g. comprise a UDM node (Unified data management), configured to manage network user data in a single, centralized element: [0029]; “ Providing 603, by the network function (UDM) responsive to receiving the registration message, a local DNS server 62, 64, 60 of said data network with information identifying association of the EAS with the PDU Session, wherein said information is usable by the UE for identifying the PDU Session for accessing the Edge service. This corresponds to Step 402.”; [0064]; [0085]) ; and
determining (i) that the first data message comprises a control plane first data message and (ii) that the second data message comprises a data plane second data message ; (first data message comprise for policy control : [0029] and “ The wireless network 100A further comprises a UPF (User Plane Function), which is responsible for packet routing and forwarding, packet inspection, QoS handling, and external PDU (protocol data unit) session for interconnecting Data Network (DN) in the 5G architecture”: [0029]; [0029]; “ Receiving 602, by the network function (UDM), a registration message from at least one Edge application server, EAS, 61, 63 accessible from a data network comprised in the wireless network 100A and having an identified PDU Session”: [0062]-[0064]) ;and
based on the determinations, (i) forwarding the control plane first data message to the AMF deployed to the particular branch site for user authentication by a particular UDM at a particular SD- WAN PoP (see fig. UDM in CN100A, see CN100A traffic is forward using UDM for checking security check at CN100A : [0030]), and
(ij forwarding the data plane second data message to the UPF deployed to the particular branch site (see fig. 1: UPF connected with CN100A and CN100B for data messing: “ The wireless network 100A further comprises a UPF (User Plane Function), which is responsible for packet routing and forwarding, packet inspection, QoS handling, and external PDU (protocol data unit) session for interconnecting Data Network (DN)”: [0029]).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of OSWAL to include the above recited limitations as taught by ALNÅS. In particular, the proposed change would be to clarify that the tunnel of OSWAL would be included as part of the N32 interface of ALNÅS given ALNÅS teaches a split control plane architecture. The suggestion/motivation would be improvement in the art of controlling a UE with regard to Edge server access: (ALNÅS; [0006]) and also ensure that the tunnel is a secure tunnel.
Regarding claim 14, OSWAL teaches, A non-transitory machine readable medium storing program for execution by a set of processing units, the program for a security gateway for forwarding control plane messages and data plane messages in an SD-PMN (software-defined private mobile network, the program comprising sets of instructions for:
receiving a first data message originating from a first user device of a plurality of user devices operating at a particular branch site of a plurality of branch sites connected by the SD-PMN and a second data message from a second user device of the plurality of user devices,
the particular branch site including a first set of control plane components that includes a UPF (user plane function), a security gateway, an AMF (access and mobility management function), and an SMF (session management function);
determining (i) that the first data message comprises a control plane first data message and (ii) that the second data message comprises a data plane second data message; and
based on the determinations,
(i) forwarding the control plane first data message to the AMF deployed to the particular branch site for user authentication by a particular UDM (unified data management) at a particular SD-WAN (software-defined wide area network) PoP (point of presence) in a plurality of SD-WAN PoPs connected to the SD-PMN, and
(ii) forwarding the data plane second data message to the UPF deployed to the particular branch sites wherein the particular UDM belongs to a second set of control plane components which, together with the first set of control plane components, provides a split control plane architecture. (Regarding claim 14, the claim is interpreted and rejected for the same reason as set forth in claim 1).
Regarding claim 2, OSWAL in view of ALNÅS teaches the invention of claim 1 as set forth above. Further, OSWAL teaches, The method of claim 1, wherein receiving the data plane second data message originating from the second user device comprises (i) receiving an encapsulated data plane second data message and (ii) decapsulating the received encapsulated data plane second data message ( “ Specifically, FIG. 2 illustrates an example mechanism for communicating flow meta data exchanges between network and security functions for a security service. As shown, packets are embedded with additional flow meta data information, such as APP ID information in this example. As shown, packet 208 includes an IP header 210, a UDP Header 212, an APP ID Encapsulation 214, an Inner IP Header 216, and an Inner UDP/TCP Header 218. Additional types of meta data information associated with a flow (e.g., User ID, Device ID, Content ID, and/or other meta data associated with a flow) can similarly be encapsulated and included in the packet header.”; [0064]).
Regarding claim 9, OSWAL in view of ALNÅS teaches the invention of claim 1 as set forth above. Further, ALNÅS teaches, The method of claim 1, wherein:
the AMF performs user authentication for the plurality of user devices operating at the particular branch site; and the control plane first data message comprises an authentication request for authenticating the second user device ( “ For this purpose, the CN 110B (and correspondingly the CN 100A) comprises an AMF (Access and Mobility Management function) which supports, inter alia, termination of NAS signaling, NAS ciphering & integrity protection, and manages registration, connection, mobility, access authentication and authorization, and security context.”: [0030]).
Regarding claim 15, the claim is interpreted and rejected for the same reason as set forth in claim 2.
Regarding claim 18, the claim is interpreted and rejected for the same reason as set forth in claim 9.
Claims 3-8; 16-17 are rejected under 35 U.S.C. 103 as being unpatentable over OSWAL in view of ALNÅS and further in view of Murakami et al. (US 20240381093A1; hereinafter as “Murakami”).
Regarding claim 3, OSWAL in view of ALNÅS teaches the invention of claim 2 as set forth above. OSWAL in view of ALNÅS does not expressively teaches, wherein the decapsulated second data message comprises GPRS (general packet radio service) and GTP (GPRS tunneling protocol) traffic and includes a GTP header.
Murakami teaches:
wherein the decapsulated second data message comprises GPRS (general packet radio service) and GTP (GPRS tunneling protocol) traffic and includes a GTP header (router with GPRS tunneling protocol (GTP) packet : [0084]).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of OSWAL in view of ALNÅS to include the above recited limitations as taught by Murakami. The suggestion/motivation would be preventing subscriber identity module (SIM) spoofing within the mobile user plane.: (Murakami; [0001]).
Regarding claim 4, OSWAL in view of ALNÅS , Murakami teaches the invention of claim 3 as set forth above. Further, Murakami teaches, The method of claim 3, wherein when the UPF receives the data plane second data message comprising the GTP header, the UPF removes the GTP header from the data plane second data message in order to forward the data plane second data message as IP (Internet protocol) traffic to a destination of the data plane second data message (“The router 112 receives GTP (GPRS tunneling protocol) packets from the gNodeB 104. When the router 112 receives a GTP packet, the router 112 checks the inner packet encapsulated within the GTP packet. If there is no Type 1 Session Transformed (ST1) route corresponding to the source address in the inner packet, the router 112 discards the received packet as being received from an invalid user. ”: [0067]).
Regarding claim 5, OSWAL in view of ALNÅS , Murakami teaches the invention of claim 4 as set forth above. Further, OSWAL teaches, The method of claim 4, wherein the destination of the data plane second data message is located at the particular branch site, and the UPF forwards the data plane second data message as IP traffic directly to the destination at the particular branch site ([0016], [0032], [0038], [0054]-[0056] ).
Regarding claim 6, OSWAL in view of ALNÅS , Murakami teaches the invention of claim 4 as set forth above. Further, OSWAL teaches, The method of claim 4, wherein the destination of the data plane second data message is located at the particular branch site, and the UPF forwards the data plane second data message as IP traffic to an SD-WAN edge router deployed to the particular branch site for forwarding to the destination at the particular branch site (see fig. 3: SD-WAN branch with router/controller: [0075]-[0079]).
Regarding claim 7, OSWAL in view of ALNÅS , Murakami teaches the invention of claim 4 as set forth above. Further, OSWAL teaches, The method of claim 6, wherein before forwarding the data plane second data message to the destination at the particular branch site, the SD-WAN edge router forwards the data message to a particular SD-WAN PoP in the plurality of SD-WAN PoPs connected by the SD-PMN for processing by a service chain at the particular SD-WAN PoP (see fig. 1B: and Fig. 3).
Regarding claim 8, OSWAL in view of ALNÅS , Murakami teaches the invention of claim 4 as set forth above. Further, OSWAL teaches ,The method of claim 4, wherein the destination of the data plane second data message is external to the particular branch site, and the UPF forwards the data plane second data message as IP traffic to an SD-WAN edge router deployed to the particular branch site for forwarding to the external destination (fig. 1b, fig. 3: [0050]-[0060]).
Regarding claim 16, the claim is interpreted and rejected for the same reason as set forth in claim 3.
Regarding claim 17, the claim is interpreted and rejected for the same reason as set forth in claim 4.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to M MOSTAZIR RAHMAN whose telephone number is (571)272-4785. The examiner can normally be reached 8:30am-5:00pm PST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Derrick Ferris can be reached at 571-272-3123. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/M Mostazir Rahman/Examiner, Art Unit 2411
/DERRICK W FERRIS/Supervisory Patent Examiner, Art Unit 2411