DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Priority
Receipt is acknowledged of certified copies of papers required by 37 CFR 1.55.
Drawings
Figure 7 is objected to because the figure is blurry. Corrected drawing sheets in compliance with 37 CFR 1.121(d) are required in reply to the Office action to avoid abandonment of the application. Any amended replacement drawing sheet should include all of the figures appearing on the immediate prior version of the sheet, even if only one figure is being amended. The figure or figure number of an amended drawing should not be labeled as “amended.” If a drawing figure is to be canceled, the appropriate figure must be removed from the replacement sheet, and where necessary, the remaining figures must be renumbered and appropriate changes made to the brief description of the several views of the drawings for consistency. Additional replacement sheets may be necessary to show the renumbering of the remaining figures. Each drawing sheet submitted after the filing date of an application must be labeled in the top margin as either “Replacement Sheet” or “New Sheet” pursuant to 37 CFR 1.121(d). If the changes are not accepted by the examiner, the applicant will be notified and informed of any required corrective action in the next Office action. The objection to the drawings will not be held in abeyance.
Specification
The disclosure is objected to because of the following informalities:
In Paragraphs [0003]-[0011], the description of the figures is all the same.
Appropriate correction is required.
Claim Objections
Claim 15 is objected to because of the following informalities:
In Claim 15, “respective packets of the plurality of packets comprising a header and a payload” should read “respective packets of the plurality of packets comprising a respective header and a respective payload”, to maintain consistency across the claims.
Appropriate correction is required.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
Claims 1-7 rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Re Claim 1. The claims recite “encrypt the payloads” and “encrypt the headers”. There is insufficient antecedent basis for the term “the payloads” and “the headers”, therefore, the claim is rendered indefinite. For the purpose of examination, the claim will be interpreted as “encrypt payloads of the plurality of packets” and “encrypt headers of the plurality of packets.” Claims 2-7 inherit this rejection.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-20 have been rejected under 35 U.S.C. § 101 under the 2019 PEG framework. The claim recites a judicial exception (an abstract idea falling within the “mental processes” grouping) that is not integrated into a practical application.
Step 1: Statutory Category. Claims 1, 8 and 15 satisfy the statutory category requirement because it is directed to an “apparatus” and “process” under 35 U.S.C. § 101(a). The claims recite a system/series of steps, including at least receiving a plurality of packets, determining to encrypt the plurality of packets, and encrypting the payloads and headers.
Step 2A, Prong 1: Identification of Judicial Exception Claims 1-20 recite judicial exceptions within the abstract idea category. The independent claims (1, 8, 15) recite “determine… to encrypt the plurality of packets in parallel”, which constitutes a mental process that could be performed in the human mind and “encrypt payloads” and “encrypt headers”, which could be performed using pen and paper and is a mathematical concept. The dependent claims recite encrypting the headers and payloads using an accelerator (Claims 2, 3, 9, 10), a definition of an accelerator device (Claims 4, 11), encryption using a key (Claims 5, 12, 18), encryption using a mask (Claims 6, 13, 19), generation of a mask (7, 14, 20), and encryption through a function call (Claims 16, 17). The dependent claims recite encryption which is a mathematical concept, and could also be performed using pen and paper.
Step 2A, Prong 2: Integration into a Practical Application. Claims 1-20 fail the integration analysis. The claims recite “receive, via an application programming interface”, “determine, by a QUIC protocol stack”, “encrypted using the accelerator device” which merely uses a computer as a tool to perform an abstract idea. The claims recite encrypting the payloads and encrypting the headers, however, these are insignificant extra-solution activities because there is no action being performed using the encrypted payload and the encrypted headers. The encrypted payload/headers could appear to be additional generation of data.
Step 2B: Significantly More / WURC Analysis. The additional elements of encrypting payload/headers in parallel are merely data manipulation/generation operations which are well-understood, routine, and conventional in the field of cybersecurity. The additional element of “receive, via an application programming interface”, “determine, by a QUIC protocol stack”, and “encrypted using the accelerator device” merely uses a computer as a tool to perform an abstract idea. Therefore, the claims do not recite additional elements that amount to significantly more than the abstract idea.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention.
Claim(s) 1-5, 8-12, and 15-18 is/are rejected under 35 U.S.C. 103 as being unpatentable over Balasubramanian et al. (US Pat. Pub. No. 20190229903 A1, herein “Bala”).
Re Claim 1. Bala teaches an apparatus, comprising: an interface to memory (Bala [0100], e.g., Computer executable instructions may be provided using any computer-readable media that are accessible by the computing apparatus 1102. Computer-readable media may include, for example, computer storage media such as a memory 1114 and communications media); and a processor to execute one or more instructions (Bala [0099], e.g., one or more processors 1104 which may be microprocessors, controllers or any other suitable type of processors for processing computer executable instructions to control the operation of the electronic device) to cause the processor to: receive, via an application programming interface (API), indications of a plurality of packets (Bala [0026], e.g., the computer 200 is used in applications that require the computer 200 to send or receive numerous data packets over the network, including larger sized data packets), respective packets of the plurality of packets comprising a respective header and a respective payload (Bala [0037], e.g., FIG. 3 illustrates an example of a data structure 300 (defining a data packet) that may exist in the memory of the computer 200 following receipt of a data received packet by the network interface card 202. The data structure 300 includes fields that store information used for processing the packet. In this example, the data structure 300 generally includes an Ethernet header 302, an IP header 304, a UDP header 306 and a body defined by a QUIC payload 308); determine, by a QUIC protocol stack, to encrypt the plurality of packets in parallel (Bala [0084], e.g., At 906, the hardware of the network interface card performs one of a receive and decrypt operation or an encrypt and transmit operation on the one or more QUIC data packets using the independent symmetric key and crypto algorithm); encrypt [the payloads of] the plurality of packets in parallel (Bala [0090], e.g., For example, a single call to UDP is made that results in splitting/chopping a larger data packet into smaller data packets before encryption and transmission as UDP QUIC packets at 1016; [0091], e.g., With QUIC, each of the smaller data packets is individually encrypted based on the single call to UDP. It should be appreciated that the splitting/chopping operation to generate smaller packets does not use IP fragmentation, but instead chops the larger packet into smaller predefined sized packets (e.g., predetermined byte size packets)); and encrypt [the headers of] the plurality of packets in parallel (Bala [0090], [0091], e.g., For example, a single call to UDP is made that results in splitting/chopping a larger data packet into smaller data packets before encryption and transmission as UDP QUIC packets at 1016. With QUIC, each of the smaller data packets is individually encrypted based on the single call to UDP).
Bala does not explicitly teach encrypting the payload and the headers parallel, however, it would have been obvious to one of ordinary skill in the art to have modified Bala to explicitly teach encrypting the payload in parallel and headers in parallel because Bala encrypts the entire QUIC packet. The structure of QUIC packets includes a header and payload, so by encrypting the entire QUIC packet, the header and payload are also encrypted.
Re Claim 2. Bala teaches the apparatus of claim 1, further comprising an accelerator device, wherein the processor causes the payloads to be encrypted using the accelerator device (Bala [0084], e.g., At 906, the hardware of the network interface card performs one of a receive and decrypt operation or an encrypt and transmit operation on the one or more QUIC data packets using the independent symmetric key and crypto algorithm; [0103], e.g., the functionality described herein can be performed, at least in part, by one or more hardware logic components… illustrative types of hardware logic components that can be used include… Graphics Processing Units (GPUs); Note a QUIC data packet includes a payload).
Re Claim 3. Bala teaches the apparatus of claim 2, wherein the processor causes the headers to be encrypted using the accelerator device (Bala [0084], e.g., At 906, the hardware of the network interface card performs one of a receive and decrypt operation or an encrypt and transmit operation on the one or more QUIC data packets using the independent symmetric key and crypto algorithm; [0103], e.g., the functionality described herein can be performed, at least in part, by one or more hardware logic components… illustrative types of hardware logic components that can be used include… Graphics Processing Units (GPUs); Note a QUIC data packet includes a header).
Re Claim 4. Bala teaches the apparatus of claim 2, wherein the accelerator device is a hardware accelerator, a graphics processing unit (GPU), a data processing unit (DPU), an infrastructure processing unit (IPU), or a network interface controller (NIC) (Bala [0084], e.g., At 906, the hardware of the network interface card performs one of a receive and decrypt operation or an encrypt and transmit operation on the one or more QUIC data packets using the independent symmetric key and crypto algorithm; [0103], e.g., the functionality described herein can be performed, at least in part, by one or more hardware logic components… illustrative types of hardware logic components that can be used include… Graphics Processing Units (GPUs)).
Re Claim 5. Bala teaches the apparatus of claim 1, wherein the payloads of the plurality of packets are encrypted in parallel using a common key (Bala [0084], e.g., At 906, the hardware of the network interface card performs one of a receive and decrypt operation or an encrypt and transmit operation on the one or more QUIC data packets using the independent symmetric key and crypto algorithm).
Re Claim 8. Bala teaches a non-transitory computer-readable storage medium (Bala [0100], e.g., Computer-readable media may include, for example, computer storage media such as a memory 1114 and communications media) comprising one or more instructions (Bala [0100], e.g., Computer executable instructions may be provided using any computer-readable media that are accessible by the computing apparatus 1102), which when executed by one or more processors (Bala [0099], e.g., one or more processors 1104 which may be microprocessors, controllers or any other suitable type of processors for processing computer executable instructions). The rest of the claim recites a non-transitory computer-readable medium of the apparatus of claim 1, and is similarly analyzed.
Re Claims 9-12. The claims recite similar features to those in claims 2-5 respectively, therefore, it is rejected in a similar manner.
Re Claim 15. Bala teaches a computer-implemented method comprising: receiving, by a processor, indications of a plurality of packets to be transmitted (Bala [0026], e.g., the computer 200 is used in applications that require the computer 200 to send or receive numerous data packets over the network, including larger sized data packets), respective packets of the plurality of packets comprising a header and a payload (Bala [0037], e.g., FIG. 3 illustrates an example of a data structure 300 (defining a data packet) that may exist in the memory of the computer 200 following receipt of a data received packet by the network interface card 202. The data structure 300 includes fields that store information used for processing the packet. In this example, the data structure 300 generally includes an Ethernet header 302, an IP header 304, a UDP header 306 and a body defined by a QUIC payload 308); and causing, by the processor, encryption of the plurality of packets (Bala [0084], e.g., At 906, the hardware of the network interface card performs one of a receive and decrypt operation or an encrypt and transmit operation on the one or more QUIC data packets using the independent symmetric key and crypto algorithm), the encryption comprising: encrypting payloads of the plurality of packets in parallel (Bala [0090], [0091], e.g., For example, a single call to UDP is made that results in splitting/chopping a larger data packet into smaller data packets before encryption and transmission as UDP QUIC packets at 1016. With QUIC, each of the smaller data packets is individually encrypted based on the single call to UDP); and encrypting headers of the plurality of packets in parallel (Bala [0090], [0091], e.g., For example, a single call to UDP is made that results in splitting/chopping a larger data packet into smaller data packets before encryption and transmission as UDP QUIC packets at 1016. With QUIC, each of the smaller data packets is individually encrypted based on the single call to UDP).
Bala does not explicitly teach encrypting the payload and the headers parallel, however, it would have been obvious to one of ordinary skill in the art to have modified Bala to explicitly teach encrypting the payload in parallel and headers in parallel because Bala encrypts the entire QUIC packet. The structure of QUIC packets includes a header and payload, so by encrypting the entire QUIC packet, the header and payload are also encrypted.
Re Claim 16, Bala teaches the computer-implemented method of claim 15, wherein the encrypting [the payloads of] the plurality of packets in parallel comprises a single function call (Bala [0091], e.g., With QUIC, each of the smaller data packets is individually encrypted based on the single call to UDP).
Bala does not explicitly teach encrypting the payloads of the plurality of packets, however, it would have been obvious to one of ordinary skill in the art to have modified Bala to explicitly teach encrypting the payloads of the plurality of packets because Bala encrypts the entire QUIC packet. The structure of QUIC packets include the payload, so by encrypting the entire QUIC packet, the payload would also be encrypted.
Re Claim 17, Bala teaches the computer-implemented method of claim 15, wherein the encrypting [the headers of] the plurality of packets in parallel comprises a single function call (Bala [0091], e.g., With QUIC, each of the smaller data packets is individually encrypted based on the single call to UDP).
Bala does not explicitly teach encrypting the headers of the plurality of packets, however, it would have been obvious to one of ordinary skill in the art to have modified Bala to explicitly teach encrypting the headers of the plurality of packets because Bala encrypts the entire QUIC packet. The structure of QUIC packets includes the header, so by encrypting the entire QUIC packet, the header would also be encrypted.
Re Claim 18. The claims recite similar features to those in claims 5, therefore, it is rejected in a similar manner.
Claim(s) 6, 7, 13, 14, 19 and 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Bala in view of Thomson et al. (“RFC 9001: Using TLS to Secure Quic: RFC Editor.” RFC RSS, 27 May 2021, www.rfc-editor.org/info/rfc9001/).
Re Claim 6, Bala teaches the apparatus of claim 5, wherein the [headers of the] plurality of packets are encrypted in parallel [using respective masks] (Bala [0091], e.g., With QUIC, each of the smaller data packets is individually encrypted based on the single call to UDP).
Bala does not explicitly teach encrypting the headers of the plurality of packets, however, it would have been obvious to one of ordinary skill in the art to have modified Bala to explicitly teach encrypting the headers of the plurality of packets because Bala encrypts the entire QUIC packet. The structure of QUIC packets includes the header, so by encrypting the entire QUIC packet, the header would also be encrypted.
Bala does not explicitly teach, but Thomson teaches wherein the headers of packets are encrypted using respective mask (Thomson [5.4.1], e.g., The output of this algorithm is a 5-byte mask that is applied to the protected header fields using exclusive OR. The least significant bits of the first byte of the packet are masked by the least significant bits of the first mask byte, and the packet number is masked with the remaining bytes).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention, to have modified the teachings of Bala with the teachings of Thomson with reasonable expectation of success. One of ordinary skill in the art would have been motivated to make the modification because Bala utilizes the QUIC protocol which is based on Thomson’s QUIC protocol specification.
Re Claim 7, Bala does not explicitly teach, but Thomson teaches the apparatus of claim 6, wherein the respective masks used to encrypt the headers are generated based on encrypted payloads of the respective plurality of packets (Thomson [5.4.1], e.g., Header protection is applied after packet protection is applied (see Section 5.3). The ciphertext of the packet is sampled and used as input to an encryption algorithm. The algorithm used depends on the negotiated AEAD. The output of this algorithm is a 5-byte mask that is applied to the protected header fields using exclusive OR).
The motivation to combine is the same as that of claim 6.
Re Claims 13, 14. The claims recite similar features to those in claims 6, 7, respectively, therefore, it is rejected in a similar manner.
Re Claim 19, 20. The claims recite similar features to those in claims 6, 7, respectively, therefore, it is rejected in a similar manner.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Piriyath et al. (US Pat. No. 10567284 B1) discloses a device may include one or more processors to receive, from at least one user device, multiple network packets. The device may identify, from the network packets, a set of individual network packets, the set including at least two of the received network packets that are destined for a particular destination device. The device may generate, based on the set of individual network packets, a batch packet, the batch packet including: the set of individual network packets, data identifying the number of individual network packets included in the set, and offset data for each of the individual network packets included in the batch packet. Based on the batch packet, the device may perform an action (such as encrypting the batch packet).
Shicht et al. (US Pat. Pub. No. 20240146703 A1) discloses in an embodiment the header encryption performed at operation 464 may be optional, but if performed, it provides an additional level of protection for the packet header, and thus provide integrity for the network packet as a whole. For example, encrypting the packet header can help prevent middleboxes attacks and vulnerabilities from interfering with delivery of a particular packet to an intended destination. Thus, while the block cipher circuit 166 encrypts the payload data of the network packet, a separate crypto block (e.g., the post-processing engine 268) may perform the header encryption illustrated at operation 464 so that both the payload data and the header can be encrypted in parallel or sequentially and by different keys in at least one embodiment.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to LAWRENCE TRUONG whose telephone number is (571)272-6973. The examiner can normally be reached Monday - Friday, 8:00 am - 4 pm ET.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Ali Shayanfar can be reached at (571) 270-1050. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/LAWRENCE TRUONG/Examiner, Art Unit 2434
/ALI SHAYANFAR/Supervisory Patent Examiner, Art Unit 2434