DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Summary
This action is a responsive to the amendment filed on 4/8/2026.
Claims 5-6, 12-13, 19-20 have been canceled.
Claims 1-4, 7-11 and 14-18 are pending and have been examined.
Claims 1-4, 7-11 and 14-18 are rejected.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 3/12/2026. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Response to Arguments
Rejection of Claims under 35 USC 101
Applicant’s Response:
The Office Action rejects Claims 1-4, 7-11, and 14-18 under 35 U.S.C. § 101 because the claimed invention is directed to an abstract idea without significantly more. Applicant respectfully disagrees, and respectfully submits that the pending claims represent patentable subject matter. Independent claim 1, as amended, recites the following claim elements, among others: obtaining, by an electronic device that is connected to a local area network (LAN), a subnet mask of the LAN; determining, by the electronic device, whether the LAN meets a security condition, wherein the determining whether the LAN meets a security condition comprises: determining whether an Internet Protocol (IP) address of a reference server in a security list is included in a range indicated by the subnet mask of the LAN; and determining whether a hostname of a device at the IP address of the reference server matches a hostname corresponding to the reference server in the security list; determining whether a Virtual Private Network (VPN) connection is used to transmit packets to a remote server based on whether the IP address of the reference server in the security list is included in the range indicated by the subnet mask of the LAN and whether the hostname of the device at the IP address matches the hostname corresponding to the reference server in the security list; and in response to determining that the LAN does not meet the security condition based at least on the address of the reference server in the security list not being included in the range indicated by the subnet mask of the LAN or the hostname of the device at the IP address not matching the hostname corresponding to the reference server in the security list: initiating the VPN connection and transmitting packets to the remote server using the VPN connection to improve a security of a communication; or in response to determining that the LAN meets the security condition based at least on the address of the reference server in the security list being included in the range indicated by the subnet mask of the LAN and the hostname of the device at the IP address matching the hostname corresponding to the reference server in the security list: transmitting the packets to the remote server without using a VPN connection to increase a speed of the communication. As an initial matter, based on the discussions during the Interview, Applicant has amended the claims to recite "obtaining, by an electronic device that is connected to a local area network (LAN), a subnet mask of the LAN", "transmitting packets to the remote server using the VPN connection to improve a security of a communication," "transmitting the packets to the remote server without using a VPN connection to increase a speed of the communication." Accordingly, the present claims, as amended, recite operations that cannot be performed in the mind or just using pen/pencil, while also demonstrating a distinct technical advantage in the practical field of telecommunication industry. Therefore, Applicant respectfully requests withdrawal of the 101 rejection. The rejection should be withdrawn because the claims are not directed to any one of the groups of abstract ideas identified by the USPTO. In the 2019 Revised Patent Subject Matter Eligibility Guidance (issued in January, 2019 and updated in October, 2019, hereinafter, "Guidance"), the USPTO listed the following groups of abstract idea: mathematical concepts, methods of organizing human activity, and mental process. The instant claims are directed to secure data transmission in a telecommunications network. In particular, the Office Action states that the claimed invention belongs to the mental process because the claims include "determining" step. Applicant respectfully disagrees. Specifically, Applicant respectfully submits that the claim further recites, in addition to the "determining" step, steps of obtaining the subnet mask of the LAN and transmitting data to remote server in a LAN (by using or not using VPN connection). In summary, claim 1 recites an operation that cannot be performed in the mind or just using pen/pencil. Therefore, the Prong One analysis fails and the 101 rejection should be withdrawn. Furthermore, the Present Application describes the technology improvement of the LAN operation by using the claimed methods, including reducing resources and improving security for the operation. For example, the Application states the following: [0009] In some implementations, an electronic device can use secured connection techniques, such as a Virtual Private Network (VPN), to provide security for network operations. In some cases, an enterprise may further require that these techniques be used before the device can access resources of the enterprise network, e.g., transmitting and receiving files between the device and an enterprise server. [0010] On the other hand, it may not be efficient to always require these secured connection techniques to be used. For example, VPN uses VPN Gateway resources and slows down connection performance due to traffic encapsulation. In some scenarios, it may not be necessary to require a VPN connection, for example, if the device is located within the campus of the enterprise and uses a LAN of the enterprise to connect to the network. Since the LAN of the enterprise on campus is within the control of enterprise, it is likely to be secure. Requiring such a device to further use a VPN to connect causes a waste of resources and degradation of performance. [0011] In another example, a user may be concerned about the security of public network when the user's device is using a LAN of a shop or a restaurant for network connection. In these cases, the user may prefer using additional security mechanisms for the network operation. Examples of the security mechanisms including using a VPN, using a secure connection established based on Secure Shell Protocol (SSH), opening a home firewall. On the other hand, the user may consider that the user's home LAN is secure and prefer not to use a connection with these additional security mechanisms when the device is using home LAN. [0012] In some operations, the electronic device can determine whether the current LAN meets a pre-configured security condition. The security condition can include verifying that there is a legitimate reference server with an address on the current LAN and a preconfigured hostname. If the current LAN does not meet the security condition, the device automatically uses additional secure network techniques such as VPN to protect the network operation. If the current LAN does meet the security condition, the device proceeds to perform the network operations without these additional secure network techniques. FIGS. 1-5 and associated descriptions provide additional details of these implementations. [0013] Techniques described herein produce one or more technical effects. For example, this approach reduces resource utilization and improves the speed of network performance while providing security to the network operation. In summary, the present Application demonstrates a distinct technical advantage in the practical field of telecommunication industry, and is not directed to an abstract idea at least under Prong Two analysis. Accordingly, independent claim 1 and other claims are eligible for allowance. Such action is respectfully requested. Should the rejections be maintained, Applicant kindly requests the Examiner to contact the undersigned attorney to discuss the rejection in further detail.
Examiner’s Response:
Applicant’s arguments, see remarks, filed 4/8/26, with respect to claims 1-4, 7-11 and 14-18 have been fully considered and are persuasive. The rejection of 1/15/26 has been withdrawn.
Rejection of Claims under 35 USC 103
Applicant’s Response:
In summary, the cited portions of Lee discuss the following operations: if the application is on the list to be authorized or allowed to use the virtual network, then virtual network is used. Otherwise, the virtual network is not used. The Office Action offers the virtual network as teaching the VPN. As an initial matter, the Office Action fails to cite any passages in Lee teaching or suggesting obtaining the subnet mask of the LAN, and determining whether the IP address of the reference server in the security list is included in the range indicated by the subnet mask of the LAN. Nor has Lee been shown to teach or suggest determining whether the hostname of the device at the IP address matches the hostname corresponding to the reference server in the security list. Moreover, as discussed during the Interview, in Lee, if the application is on the list, then virtual connection (offered to teach VPN in the claim) is used. This is opposite to the operation recited in the claim, where if both conditions are satisfied, including 1) the IP address of the reference server in the security list is included in the range indicated by the subnet mask of the LAN; and 2) whether the hostname of the device at the IP address matches the hostname corresponding to the reference server in the security list, then the VPN is not used. Accordingly, not only Lee fails to teach the above-cited limitations, Lee teaches away from the claimed invention because Lee's operation is the opposite to the claimed limitation.
Examiner’s Response:
Applicant's arguments filed 4/8/26 have been fully considered but they are not persuasive. The limitations states:
determining whether a Virtual Private Network (VPN) connection is used to transmit packets to a remote server based on whether the IP address of the reference server in the security list is included in the range indicated by the subnet mask of the LAN and whether the hostname of the device at the IP address matches the hostname corresponding to the reference server in the security list;
and in response to determining that the LAN does not meet the security condition based at least on the address of the reference server in the security list not being included in the range indicated by the subnet mask of the LAN or the hostname of the device at the IP address not matching the hostname corresponding to the reference server in the security list: initiating the VPN connection and transmitting packets to the remote server using the VPN connection to improve a security of a communication;
or in response to determining that the LAN meets the security condition based at least on the address of the reference server in the security list being included in the range indicated by the subnet mask of the LAN and the hostname of the device at the IP address matching the hostname corresponding to the reference server in the security list: transmitting the packets to the remote server without using a VPN connection to increase a speed of the communication
In other words, if the subnet and the hostname are in the list, then the device is to use a non-VPN connection. Otherwise, the device is to use a VPN connection. Using a list to control a connection is well known technique called access control list (ACL). Two common lists are whitelist and blacklist. A whitelist only allows those on the list access. Whereas, a blacklist rejects those on the list access. The limitation is applying an ACL, specifically a whitelist, to the non-VPN connection. Lee (US 20140244851 A1) teaches
In a step 615, a determination is made as to whether the connection should be provided through a virtual network that connects the first network domain with a second network domain, different or separate from the first network domain…. In a specific implementation, the system stores a list of applications that are authorized or allowed to use the virtual network. This list may be referred to as a white list. In various other specific implementations, the system stores a list of applications that are not authorized or allowed to use the virtual network. This list may be referred to as a black list. In a specific implementation, an application not listed in the black list is allowed to use the virtual network. ¶¶ [0093]-[0097]
In other words, Lee teaches the overall concept of applying an ACL to decide when to use a VPN connection or a non-VPN connection. As there are only two options (a VPN connection or a non-VPN connection), using Lee’s concept of applying an ACL to the VPN connection would have been obvious to try on the non-VPN connection. Panse et al. (US 20200162467 A1) teaches the details of what can be included in the ACL. Thus, the combination of Lee and Panse et al. teaches the language of the limitation.
Applicant’s Response:
Applicant submits that the cited references fail to teach the newly added limitations.
Examiner’s Response:
Applicant’s arguments with respect to claims 4/8/26 have been considered but are moot because the arguments are directed to amended subject matter properly addressed with the newly cited reference of Panse et al. (US 20200162467 A1) and Liu et al. (US 20110173692 A1).
The combination of Lee (US 20140244851 A1) and Panse et al. (US 20200162467 A1) and Liu et al. (US 20110173692 A1) teaches the language of the independent claims.
All remaining arguments are now moot in regards to the new rejection.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 1, 8, 15 are rejected under 35 U.S.C. 103 as being unpatentable over Lee (US 20140244851 A1) and further in view of Panse et al. (US 20200162467 A1) and Liu et al. (US 20110173692 A1).
As to claim 1, Lee teaches a method, comprising: determining, by the electronic device, whether the LAN meets a security condition (See ¶¶ [0093]-[0097], Fig. 6, Teaches that a determination is made as to whether the connection should be provided through a virtual network that connects the first network domain with a second network domain, different or separate from the first network domain. If the connection should be provided through the virtual network, a virtual network connection is established between the first end point in the first network domain and the destination, the destination being at a second end point in the second network domain. If the connection should not be provided through the virtual network, the data packet is passed outside the virtual network. The system stores a list of applications that are authorized or allowed to use the virtual network. This list may be referred to as a white list. In various other specific implementations, the system stores a list of applications that are not authorized or allowed to use the virtual network. This list may be referred to as a black list. In a specific implementation, an application not listed in the black list is allowed to use the virtual network);
determining whether a Virtual Private Network (VPN) connection is used to transmit packets to a remote server based on whether the IP address of the reference server in the security list is included in the range indicated by the subnet mask of the LAN and whether the hostname of the device at the IP address matches the hostname corresponding to the reference server in the security list (See ¶¶ [0093]-[0097], Fig. 6, Teaches that a determination is made as to whether the connection should be provided through a virtual network that connects the first network domain with a second network domain, different or separate from the first network domain. If the connection should be provided through the virtual network, a virtual network connection is established between the first end point in the first network domain and the destination, the destination being at a second end point in the second network domain. If the connection should not be provided through the virtual network, the data packet is passed outside the virtual network. The system stores a list of applications that are authorized or allowed to use the virtual network. This list may be referred to as a white list. In various other specific implementations, the system stores a list of applications that are not authorized or allowed to use the virtual network. This list may be referred to as a black list. In a specific implementation, an application not listed in the black list is allowed to use the virtual network);
and in response to determining that the LAN does not meet the security condition based at least on the address of the reference server in the security list not being included in the range indicated by the subnet mask of the LAN or the hostname of the device at the IP address not matching the hostname corresponding to the reference server in the security list: initiating VPN connection and transmitting packets to the remote server using the VPN connection to improve a security of a communication (See ¶¶ [0093]-[0097], Fig. 6, Teaches that a determination is made as to whether the connection should be provided through a virtual network that connects the first network domain with a second network domain, different or separate from the first network domain. If the connection should be provided through the virtual network, a virtual network connection is established between the first end point in the first network domain and the destination, the destination being at a second end point in the second network domain. If the connection should not be provided through the virtual network, the data packet is passed outside the virtual network. The system stores a list of applications that are authorized or allowed to use the virtual network. This list may be referred to as a white list. In various other specific implementations, the system stores a list of applications that are not authorized or allowed to use the virtual network. This list may be referred to as a black list. In a specific implementation, an application not listed in the black list is allowed to use the virtual network);
or in response to determining that the LAN meets the security condition based at least on the address of the reference server in the security list being included in the range indicated by the subnet mask of the LAN and the hostname of the device at the IP address matching the hostname corresponding to the reference server in the security list: transmitting the packets to the remote server without using a VPN connection to increase a speed of the communication (See ¶¶ [0093]-[0097], Fig. 6, Teaches that a determination is made as to whether the connection should be provided through a virtual network that connects the first network domain with a second network domain, different or separate from the first network domain. If the connection should be provided through the virtual network, a virtual network connection is established between the first end point in the first network domain and the destination, the destination being at a second end point in the second network domain. If the connection should not be provided through the virtual network, the data packet is passed outside the virtual network. The system stores a list of applications that are authorized or allowed to use the virtual network. This list may be referred to as a white list. In various other specific implementations, the system stores a list of applications that are not authorized or allowed to use the virtual network. This list may be referred to as a black list. In a specific implementation, an application not listed in the black list is allowed to use the virtual network).
However, it does not expressly teach the details of obtaining, by an electronic device that is connected to a local area network (LAN), a subnet mask of the LAN; wherein the determining whether the LAN meets a security condition comprises: determining whether an Internet Protocol (IP) address of a reference server in a security list is included in a range indicated by the subnet mask of the LAN; and determining whether a hostname of a device at the IP address of the reference server matches a hostname corresponding to the reference server in the security list; based on whether the IP address of the reference server in the security list is included in the range indicated by the subnet mask of the LAN and whether the hostname of the device at the IP address matches the hostname corresponding to the reference server in the security list; based on whether the IP address of the reference server in the security list is included in the range indicated by the subnet mask of the LAN and whether the hostname of the device at the IP address matches the hostname corresponding to the reference server in the security list; based on whether the IP address of the reference server in the security list is included in the range indicated by the subnet mask of the LAN and whether the hostname of the device at the IP address matches the hostname corresponding to the reference server in the security list.
Panse et al., from analogous art, teaches wherein the determining whether the LAN meets a security condition comprises: determining whether an Internet Protocol (IP) address of a reference server in a security list is included in a range indicated by the subnet mask of the LAN (See ¶¶ [0024]-[0025], Teaches that Some embodiments of the present technology are directed to an offline method and tool for converting a conventional IP based Access Control List (ACL) to Object Group-based ACL. A network object group may contain a single object (such as a single IP address, a hostname, another network object group, or a subnet) or multiple objects (such as a combination of multiple IP addresses, hostnames, a range of IP addresses, other object network groups, or subnets). Object Groups may be used with an Access Control List (ACL) in a network object group-based ACL, to create access control policies for the objects. Accordingly, Object Groups for ACLs enable consolidation of users, devices, or protocols into groups which can then be applied to access control lists (ACLs) to thereby create access control policies for the aforementioned groups. This feature enables the use of object groups instead of individual IP addresses, protocols, and ports, which are used in conventional ACLs. Although an Object-Group based ACL may have multiple Access Control Entries (ACEs), each single ACE in an Object-Group-based ACL may define an access control policy for an entire group of users to access a group of servers or services or to deny them from doing so. Lee teaches checking the ACL list and Panse et al. teaches that the list can include subnet and hostname );
and determining whether a hostname of a device at the IP address matches a hostname corresponding to the reference server in the security list (See ¶¶ [0024]-[0025], Teaches that Some embodiments of the present technology are directed to an offline method and tool for converting a conventional IP based Access Control List (ACL) to Object Group-based ACL. A network object group may contain a single object (such as a single IP address, a hostname, another network object group, or a subnet) or multiple objects (such as a combination of multiple IP addresses, hostnames, a range of IP addresses, other object network groups, or subnets). Object Groups may be used with an Access Control List (ACL) in a network object group-based ACL, to create access control policies for the objects. Accordingly, Object Groups for ACLs enable consolidation of users, devices, or protocols into groups which can then be applied to access control lists (ACLs) to thereby create access control policies for the aforementioned groups. This feature enables the use of object groups instead of individual IP addresses, protocols, and ports, which are used in conventional ACLs. Although an Object-Group based ACL may have multiple Access Control Entries (ACEs), each single ACE in an Object-Group-based ACL may define an access control policy for an entire group of users to access a group of servers or services or to deny them from doing so. Lee teaches checking the ACL list and Panse et al. teaches that the list can include subnet and hostname);
based on whether the IP address of the reference server in the security list is included in the range indicated by the subnet mask of the LAN and whether the hostname of the device at the IP address matches the hostname corresponding to the reference server in the security list; based on whether the IP address of the reference server in the security list is included in the range indicated by the subnet mask of the LAN and whether the hostname of the device at the IP address matches the hostname corresponding to the reference server in the security list; based on whether the IP address of the reference server in the security list is included in the range indicated by the subnet mask of the LAN and whether the hostname of the device at the IP address matches the hostname corresponding to the reference server in the security list (See ¶¶ [0024]-[0025], Teaches that Some embodiments of the present technology are directed to an offline method and tool for converting a conventional IP based Access Control List (ACL) to Object Group-based ACL. A network object group may contain a single object (such as a single IP address, a hostname, another network object group, or a subnet) or multiple objects (such as a combination of multiple IP addresses, hostnames, a range of IP addresses, other object network groups, or subnets). Object Groups may be used with an Access Control List (ACL) in a network object group-based ACL, to create access control policies for the objects. Accordingly, Object Groups for ACLs enable consolidation of users, devices, or protocols into groups which can then be applied to access control lists (ACLs) to thereby create access control policies for the aforementioned groups. This feature enables the use of object groups instead of individual IP addresses, protocols, and ports, which are used in conventional ACLs. Although an Object-Group based ACL may have multiple Access Control Entries (ACEs), each single ACE in an Object-Group-based ACL may define an access control policy for an entire group of users to access a group of servers or services or to deny them from doing so. Lee teaches checking the ACL list and Panse et al. teaches that the list can include subnet and hostname).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Panse et al. into Lee in order to create access control policies for the objects (See Panse et al. ¶ [0024]).
However, it does not expressly teach the details of obtaining, by an electronic device that is connected to a local area network (LAN), a subnet mask of the LAN.
Liu et al., from analogous art, teaches obtaining, by an electronic device that is connected to a local area network (LAN), a subnet mask of the LAN (See ¶ [0045], Teaches that An exemplary method for computing network reachability in a computer network is further described in relation to FIG. 4. The method begins by identifying at 41 each of the subnetworks that comprise a computer network. While the exemplary method may be used to computer reachability for the entire network, it may also be applied to computer reachability between any arbitrary pair of subnetworks.).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Liu et al. into the combination of Lee and Panse et al. in order to prevent security holes that will allow malicious traffic to sneak into a private network or blocks legitimate traffic and disrupts normal businesses (See Liu et al. ¶ [0004]).
As to claim 8, Lee teaches one or more non-transitory computer-readable media containing instructions which, when executed, cause a computing device to perform operations comprising: determining, by the electronic device, whether the LAN meets a security condition (See ¶¶ [0093]-[0097], Fig. 6, Teaches that a determination is made as to whether the connection should be provided through a virtual network that connects the first network domain with a second network domain, different or separate from the first network domain. If the connection should be provided through the virtual network, a virtual network connection is established between the first end point in the first network domain and the destination, the destination being at a second end point in the second network domain. If the connection should not be provided through the virtual network, the data packet is passed outside the virtual network. The system stores a list of applications that are authorized or allowed to use the virtual network. This list may be referred to as a white list. In various other specific implementations, the system stores a list of applications that are not authorized or allowed to use the virtual network. This list may be referred to as a black list. In a specific implementation, an application not listed in the black list is allowed to use the virtual network);
determining whether a Virtual Private Network (VPN) connection is used to transmit packets to a remote server based on whether the IP address of the reference server in the security list is included in the range indicated by the subnet mask of the LAN and whether the hostname of the device at the IP address matches the hostname corresponding to the reference server in the security list (See ¶¶ [0093]-[0097], Fig. 6, Teaches that a determination is made as to whether the connection should be provided through a virtual network that connects the first network domain with a second network domain, different or separate from the first network domain. If the connection should be provided through the virtual network, a virtual network connection is established between the first end point in the first network domain and the destination, the destination being at a second end point in the second network domain. If the connection should not be provided through the virtual network, the data packet is passed outside the virtual network. The system stores a list of applications that are authorized or allowed to use the virtual network. This list may be referred to as a white list. In various other specific implementations, the system stores a list of applications that are not authorized or allowed to use the virtual network. This list may be referred to as a black list. In a specific implementation, an application not listed in the black list is allowed to use the virtual network);
and in response to determining that the LAN does not meet the security condition based at least on the address of the reference server in the security list not being included in the range indicated by the subnet mask of the LAN or the hostname of the device at the IP address not matching the hostname corresponding to the reference server in the security list: initiating the VPN connection and transmitting packets to the remote server using the VPN connection to improve a security of a communication (See ¶¶ [0093]-[0097], Fig. 6, Teaches that a determination is made as to whether the connection should be provided through a virtual network that connects the first network domain with a second network domain, different or separate from the first network domain. If the connection should be provided through the virtual network, a virtual network connection is established between the first end point in the first network domain and the destination, the destination being at a second end point in the second network domain. If the connection should not be provided through the virtual network, the data packet is passed outside the virtual network. The system stores a list of applications that are authorized or allowed to use the virtual network. This list may be referred to as a white list. In various other specific implementations, the system stores a list of applications that are not authorized or allowed to use the virtual network. This list may be referred to as a black list. In a specific implementation, an application not listed in the black list is allowed to use the virtual network);
or in response to determining that the LAN meets the security condition based at least on the address of the reference server in the security list being included in the range indicated by the subnet mask of the LAN or the hostname of the device at the IP address matching the hostname corresponding to the reference server in the security list: transmitting the packets to the remote server without using a VPN connection to increase a speed of the communication (See ¶¶ [0093]-[0097], Fig. 6, Teaches that a determination is made as to whether the connection should be provided through a virtual network that connects the first network domain with a second network domain, different or separate from the first network domain. If the connection should be provided through the virtual network, a virtual network connection is established between the first end point in the first network domain and the destination, the destination being at a second end point in the second network domain. If the connection should not be provided through the virtual network, the data packet is passed outside the virtual network. The system stores a list of applications that are authorized or allowed to use the virtual network. This list may be referred to as a white list. In various other specific implementations, the system stores a list of applications that are not authorized or allowed to use the virtual network. This list may be referred to as a black list. In a specific implementation, an application not listed in the black list is allowed to use the virtual network).
However, it does not expressly teach the details of obtaining, by an electronic device that is connected to a local area network (LAN), a subnet mask of the LAN; wherein the determining whether the LAN meets a security condition comprises: determining whether an Internet Protocol (IP) address of a reference server in a security list is included in a range indicated by the subnet mask of the LAN; and determining whether a hostname of a device at the IP address of the reference server matches a hostname corresponding to the reference server in the security list; based on whether the IP address of the reference server in the security list is included in the range indicated by the subnet mask of the LAN and whether the hostname of the device at the IP address matches the hostname corresponding to the reference server in the security list; based on whether the IP address of the reference server in the security list is included in the range indicated by the subnet mask of the LAN and whether the hostname of the device at the IP address matches the hostname corresponding to the reference server in the security list; based on whether the IP address of the reference server in the security list is included in the range indicated by the subnet mask of the LAN and whether the hostname of the device at the IP address matches the hostname corresponding to the reference server in the security list.
Panse et al., from analogous art, teaches wherein the determining whether the LAN meets a security condition comprises: determining whether an Internet Protocol (IP) address of a reference server in a security list is included in a range indicated by the subnet mask of the LAN (See ¶¶ [0024]-[0025], Teaches that Some embodiments of the present technology are directed to an offline method and tool for converting a conventional IP based Access Control List (ACL) to Object Group-based ACL. A network object group may contain a single object (such as a single IP address, a hostname, another network object group, or a subnet) or multiple objects (such as a combination of multiple IP addresses, hostnames, a range of IP addresses, other object network groups, or subnets). Object Groups may be used with an Access Control List (ACL) in a network object group-based ACL, to create access control policies for the objects. Accordingly, Object Groups for ACLs enable consolidation of users, devices, or protocols into groups which can then be applied to access control lists (ACLs) to thereby create access control policies for the aforementioned groups. This feature enables the use of object groups instead of individual IP addresses, protocols, and ports, which are used in conventional ACLs. Although an Object-Group based ACL may have multiple Access Control Entries (ACEs), each single ACE in an Object-Group-based ACL may define an access control policy for an entire group of users to access a group of servers or services or to deny them from doing so. Lee teaches checking the ACL list and Panse et al. teaches that the list can include subnet and hostname );
and determining whether a hostname of a device at the IP address of the reference server matches a hostname corresponding to the reference server in the security list (See ¶¶ [0024]-[0025], Teaches that Some embodiments of the present technology are directed to an offline method and tool for converting a conventional IP based Access Control List (ACL) to Object Group-based ACL. A network object group may contain a single object (such as a single IP address, a hostname, another network object group, or a subnet) or multiple objects (such as a combination of multiple IP addresses, hostnames, a range of IP addresses, other object network groups, or subnets). Object Groups may be used with an Access Control List (ACL) in a network object group-based ACL, to create access control policies for the objects. Accordingly, Object Groups for ACLs enable consolidation of users, devices, or protocols into groups which can then be applied to access control lists (ACLs) to thereby create access control policies for the aforementioned groups. This feature enables the use of object groups instead of individual IP addresses, protocols, and ports, which are used in conventional ACLs. Although an Object-Group based ACL may have multiple Access Control Entries (ACEs), each single ACE in an Object-Group-based ACL may define an access control policy for an entire group of users to access a group of servers or services or to deny them from doing so. Lee teaches checking the ACL list and Panse et al. teaches that the list can include subnet and hostname);
based on whether the IP address of the reference server in the security list is included in the range indicated by the subnet mask of the LAN and whether the hostname of the device at the IP address matches the hostname corresponding to the reference server in the security list; based on whether the IP address of the reference server in the security list is included in the range indicated by the subnet mask of the LAN and whether the hostname of the device at the IP address matches the hostname corresponding to the reference server in the security list; based on whether the IP address of the reference server in the security list is included in the range indicated by the subnet mask of the LAN and whether the hostname of the device at the IP address matches the hostname corresponding to the reference server in the security list (See ¶¶ [0024]-[0025], Teaches that Some embodiments of the present technology are directed to an offline method and tool for converting a conventional IP based Access Control List (ACL) to Object Group-based ACL. A network object group may contain a single object (such as a single IP address, a hostname, another network object group, or a subnet) or multiple objects (such as a combination of multiple IP addresses, hostnames, a range of IP addresses, other object network groups, or subnets). Object Groups may be used with an Access Control List (ACL) in a network object group-based ACL, to create access control policies for the objects. Accordingly, Object Groups for ACLs enable consolidation of users, devices, or protocols into groups which can then be applied to access control lists (ACLs) to thereby create access control policies for the aforementioned groups. This feature enables the use of object groups instead of individual IP addresses, protocols, and ports, which are used in conventional ACLs. Although an Object-Group based ACL may have multiple Access Control Entries (ACEs), each single ACE in an Object-Group-based ACL may define an access control policy for an entire group of users to access a group of servers or services or to deny them from doing so. Lee teaches checking the ACL list and Panse et al. teaches that the list can include subnet and hostname).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Panse et al. into Lee in order to create access control policies for the objects (See Panse et al. ¶ [0024]).
However, it does not expressly teach the details of obtaining, by an electronic device that is connected to a local area network (LAN), a subnet mask of the LAN.
Liu et al., from analogous art, teaches obtaining, by an electronic device that is connected to a local area network (LAN), a subnet mask of the LAN (See ¶ [0045], Teaches that An exemplary method for computing network reachability in a computer network is further described in relation to FIG. 4. The method begins by identifying at 41 each of the subnetworks that comprise a computer network. While the exemplary method may be used to computer reachability for the entire network, it may also be applied to computer reachability between any arbitrary pair of subnetworks.).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Liu et al. into the combination of Lee and Panse et al. in order to prevent security holes that will allow malicious traffic to sneak into a private network or blocks legitimate traffic and disrupts normal businesses (See Liu et al. ¶ [0004]).
As to claim 15, Lee teaches a system, comprising: one or more computers; and one or more computer memory devices interoperably coupled with the one or more computers and having tangible, non-transitory, machine-readable media storing one or more instructions that, when executed by the one or more computers, perform one or more operations comprising: determining, by the system, whether the LAN meets a security condition (See ¶¶ [0093]-[0097], Fig. 6, Teaches that a determination is made as to whether the connection should be provided through a virtual network that connects the first network domain with a second network domain, different or separate from the first network domain. If the connection should be provided through the virtual network, a virtual network connection is established between the first end point in the first network domain and the destination, the destination being at a second end point in the second network domain. If the connection should not be provided through the virtual network, the data packet is passed outside the virtual network. The system stores a list of applications that are authorized or allowed to use the virtual network. This list may be referred to as a white list. In various other specific implementations, the system stores a list of applications that are not authorized or allowed to use the virtual network. This list may be referred to as a black list. In a specific implementation, an application not listed in the black list is allowed to use the virtual network);
determining whether a Virtual Private Network (VPN) connection is used to transmit packets to a remote server based on whether the IP address of the reference server in the security list is included in the range indicated by the subnet mask of the LAN and whether the hostname of the device at the IP address matches the hostname corresponding to the reference server in the security list (See ¶¶ [0093]-[0097], Fig. 6, Teaches that a determination is made as to whether the connection should be provided through a virtual network that connects the first network domain with a second network domain, different or separate from the first network domain. If the connection should be provided through the virtual network, a virtual network connection is established between the first end point in the first network domain and the destination, the destination being at a second end point in the second network domain. If the connection should not be provided through the virtual network, the data packet is passed outside the virtual network. The system stores a list of applications that are authorized or allowed to use the virtual network. This list may be referred to as a white list. In various other specific implementations, the system stores a list of applications that are not authorized or allowed to use the virtual network. This list may be referred to as a black list. In a specific implementation, an application not listed in the black list is allowed to use the virtual network);
and in response to determining that the LAN does not meet the security condition based at least on the address of the reference server in the security list not being included in the range indicated by the subnet mask of the LAN or the hostname of the device at the IP address not matching the hostname corresponding to the reference server in the security list: initiating the VPN connection and transmitting packets to the remote server using the VPN connection to improve a security of a communication (See ¶¶ [0093]-[0097], Fig. 6, Teaches that a determination is made as to whether the connection should be provided through a virtual network that connects the first network domain with a second network domain, different or separate from the first network domain. If the connection should be provided through the virtual network, a virtual network connection is established between the first end point in the first network domain and the destination, the destination being at a second end point in the second network domain. If the connection should not be provided through the virtual network, the data packet is passed outside the virtual network. The system stores a list of applications that are authorized or allowed to use the virtual network. This list may be referred to as a white list. In various other specific implementations, the system stores a list of applications that are not authorized or allowed to use the virtual network. This list may be referred to as a black list. In a specific implementation, an application not listed in the black list is allowed to use the virtual network);
or in response to determining that the LAN meets the security condition based at least on the address of the reference server in the security list being included in the range indicated by the subnet mask of the LAN or the hostname of the device at the IP address matching the hostname corresponding to the reference server in the security list: transmitting the packets to the remote server without using a VPN connection to increase a speed of the communication (See ¶¶ [0093]-[0097], Fig. 6, Teaches that a determination is made as to whether the connection should be provided through a virtual network that connects the first network domain with a second network domain, different or separate from the first network domain. If the connection should be provided through the virtual network, a virtual network connection is established between the first end point in the first network domain and the destination, the destination being at a second end point in the second network domain. If the connection should not be provided through the virtual network, the data packet is passed outside the virtual network. The system stores a list of applications that are authorized or allowed to use the virtual network. This list may be referred to as a white list. In various other specific implementations, the system stores a list of applications that are not authorized or allowed to use the virtual network. This list may be referred to as a black list. In a specific implementation, an application not listed in the black list is allowed to use the virtual network).
However, it does not expressly teach the details of obtaining, by the system that is connected to a local area network (LAN), a subnet mask of the LAN; wherein the determining whether the LAN meets a security condition comprises: determining whether an Internet Protocol (IP) address of a reference server in a security list is included in a range indicated by the subnet mask of the LAN; and determining whether a hostname of a device at the IP address of the reference server matches a hostname corresponding to the reference server in the security list; based on whether the IP address of the reference server in the security list is included in the range indicated by the subnet mask of the LAN and whether the hostname of the device at the IP address matches the hostname corresponding to the reference server in the security list; based on whether the IP address of the reference server in the security list is included in the range indicated by the subnet mask of the LAN and whether the hostname of the device at the IP address matches the hostname corresponding to the reference server in the security list; based on whether the IP address of the reference server in the security list is included in the range indicated by the subnet mask of the LAN and whether the hostname of the device at the IP address matches the hostname corresponding to the reference server in the security list.
Panse et al., from analogous art, teaches wherein the determining whether the LAN meets a security condition comprises: determining whether an Internet Protocol (IP) address of a reference server in a security list is included in a range indicated by the subnet mask of the LAN (See ¶¶ [0024]-[0025], Teaches that Some embodiments of the present technology are directed to an offline method and tool for converting a conventional IP based Access Control List (ACL) to Object Group-based ACL. A network object group may contain a single object (such as a single IP address, a hostname, another network object group, or a subnet) or multiple objects (such as a combination of multiple IP addresses, hostnames, a range of IP addresses, other object network groups, or subnets). Object Groups may be used with an Access Control List (ACL) in a network object group-based ACL, to create access control policies for the objects. Accordingly, Object Groups for ACLs enable consolidation of users, devices, or protocols into groups which can then be applied to access control lists (ACLs) to thereby create access control policies for the aforementioned groups. This feature enables the use of object groups instead of individual IP addresses, protocols, and ports, which are used in conventional ACLs. Although an Object-Group based ACL may have multiple Access Control Entries (ACEs), each single ACE in an Object-Group-based ACL may define an access control policy for an entire group of users to access a group of servers or services or to deny them from doing so. Lee teaches checking the ACL list and Panse et al. teaches that the list can include subnet and hostname );
and determining whether a hostname of a device at the IP address of the reference server matches a hostname corresponding to the reference server in the security list (See ¶¶ [0024]-[0025], Teaches that Some embodiments of the present technology are directed to an offline method and tool for converting a conventional IP based Access Control List (ACL) to Object Group-based ACL. A network object group may contain a single object (such as a single IP address, a hostname, another network object group, or a subnet) or multiple objects (such as a combination of multiple IP addresses, hostnames, a range of IP addresses, other object network groups, or subnets). Object Groups may be used with an Access Control List (ACL) in a network object group-based ACL, to create access control policies for the objects. Accordingly, Object Groups for ACLs enable consolidation of users, devices, or protocols into groups which can then be applied to access control lists (ACLs) to thereby create access control policies for the aforementioned groups. This feature enables the use of object groups instead of individual IP addresses, protocols, and ports, which are used in conventional ACLs. Although an Object-Group based ACL may have multiple Access Control Entries (ACEs), each single ACE in an Object-Group-based ACL may define an access control policy for an entire group of users to access a group of servers or services or to deny them from doing so. Lee teaches checking the ACL list and Panse et al. teaches that the list can include subnet and hostname);
based on whether the IP address of the reference server in the security list is included in the range indicated by the subnet mask of the LAN and whether the hostname of the device at the IP address matches the hostname corresponding to the reference server in the security list; based on whether the IP address of the reference server in the security list is included in the range indicated by the subnet mask of the LAN and whether the hostname of the device at the IP address matches the hostname corresponding to the reference server in the security list; based on whether the IP address of the reference server in the security list is included in the range indicated by the subnet mask of the LAN and whether the hostname of the device at the IP address matches the hostname corresponding to the reference server in the security list (See ¶¶ [0024]-[0025], Teaches that Some embodiments of the present technology are directed to an offline method and tool for converting a conventional IP based Access Control List (ACL) to Object Group-based ACL. A network object group may contain a single object (such as a single IP address, a hostname, another network object group, or a subnet) or multiple objects (such as a combination of multiple IP addresses, hostnames, a range of IP addresses, other object network groups, or subnets). Object Groups may be used with an Access Control List (ACL) in a network object group-based ACL, to create access control policies for the objects. Accordingly, Object Groups for ACLs enable consolidation of users, devices, or protocols into groups which can then be applied to access control lists (ACLs) to thereby create access control policies for the aforementioned groups. This feature enables the use of object groups instead of individual IP addresses, protocols, and ports, which are used in conventional ACLs. Although an Object-Group based ACL may have multiple Access Control Entries (ACEs), each single ACE in an Object-Group-based ACL may define an access control policy for an entire group of users to access a group of servers or services or to deny them from doing so. Lee teaches checking the ACL list and Panse et al. teaches that the list can include subnet and hostname).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Panse et al. into Lee in order to create access control policies for the objects (See Panse et al. ¶ [0024]).
However, it does not expressly teach the details of obtaining, by the system that is connected to a local area network (LAN), a subnet mask of the LAN.
Liu et al., from analogous art, teaches obtaining, by the system that is connected to a local area network (LAN), a subnet mask of the LAN (See ¶ [0045], Teaches that An exemplary method for computing network reachability in a computer network is further described in relation to FIG. 4. The method begins by identifying at 41 each of the subnetworks that comprise a computer network. While the exemplary method may be used to computer reachability for the entire network, it may also be applied to computer reachability between any arbitrary pair of subnetworks.).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Liu et al. into the combination of Lee and Panse et al. in order to prevent security holes that will allow malicious traffic to sneak into a private network or blocks legitimate traffic and disrupts normal businesses (See Liu et al. ¶ [0004]).
Claims 2, 9, 16 are rejected under 35 U.S.C. 103 as being unpatentable Lee (US 20140244851 A1) and Panse et al. (US 20200162467 A1) and Liu et al. (US 20110173692 A1) and further in view of Fuh et al. (US 6609154 B1).
As to claim 2, the combination of Lee and Panse et al. and Liu et al. teaches the method according to claim 1 above. However, it does not expressly teach the details of wherein the determining whether the LAN meets a security condition further comprises: transmitting a connection request to the device at the IP address; receiving authentication information from the device; and determining that the LAN meets the security condition based on the authentication information.
Fuh et al., from analogous art, teaches wherein the determining whether the LAN meets a security condition further comprises: transmitting a connection request to the device at the IP address (See Col. 10 Ln 28, Teaches that User 302 uses browser 304 to send an HTTP request from client 306 for an electronic document, application or resource available at target server 222.);
receiving authentication information from the device; and determining that the LAN meets the security condition based on the authentication information (See Col. 10 Ln 47, Fig. 7a Teaches that then control passes to block 708 in which the authentication caches are searched for the source IP address. In block 710, the process tests whether the source IP address is found. For example, if Authentication Proxy 400 determines that the source IP address matches at least one IP address stored in the filtering mechanism 219, then the Authentication Proxy 400 attempts to authenticate the user 302. In the preferred embodiment, Authentication Proxy 400 searches authentication caches 432, 434 for the source IP address. The goal of this search is to determine if the source IP address of the HTTP packet corresponds to an entry in any of the authentication caches 432, 434.).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Fuh et al. into the combination of Lee and Panse et al. and Liu et al. in order to guard against unwanted network traffic or access by unauthorized users (See Fuh et al. See Col. 1 Ln 30).
As to claim 9, the combination of Lee and Panse et al. and Liu et al. teaches the one or more computer-readable media according to claim 8 above. However, it does not expressly teach the details of wherein the determining whether the LAN meets a security condition further comprises: transmitting a connection request to the device at the IP address; receiving authentication information from the device; and determining that the LAN meets the security condition based on the authentication information.
Fuh et al., from analogous art, teaches wherein the determining whether the LAN meets a security condition further comprises: transmitting a connection request to the device at the IP address (See Col. 10 Ln 28, Teaches that User 302 uses browser 304 to send an HTTP request from client 306 for an electronic document, application or resource available at target server 222.);
receiving authentication information from the device; and determining that the LAN meets the security condition based on the authentication information (See Col. 10 Ln 47, Fig. 7a Teaches that then control passes to block 708 in which the authentication caches are searched for the source IP address. In block 710, the process tests whether the source IP address is found. For example, if Authentication Proxy 400 determines that the source IP address matches at least one IP address stored in the filtering mechanism 219, then the Authentication Proxy 400 attempts to authenticate the user 302. In the preferred embodiment, Authentication Proxy 400 searches authentication caches 432, 434 for the source IP address. The goal of this search is to determine if the source IP address of the HTTP packet corresponds to an entry in any of the authentication caches 432, 434.).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Fuh et al. into the combination of Lee and Panse et al. and Liu et al. in order to guard against unwanted network traffic or access by unauthorized users (See Fuh et al. See Col. 1 Ln 30).
As to claim 16, the combination of Lee and Panse et al. and Liu et al. teaches the system according to claim 15 above. However, it does not expressly teach the details of wherein the determining whether the LAN meets a security condition further comprises: transmitting a connection request to the device at the IP address; receiving authentication information from the device; and determining that the LAN meets the security condition based on the authentication information.
Fuh et al., from analogous art, teaches wherein the determining whether the LAN meets a security condition further comprises: transmitting a connection request to the device at the IP address (See Col. 10 Ln 28, Teaches that User 302 uses browser 304 to send an HTTP request from client 306 for an electronic document, application or resource available at target server 222.);
receiving authentication information from the device; and determining that the LAN meets the security condition based on the authentication information (See Col. 10 Ln 47, Fig. 7a Teaches that then control passes to block 708 in which the authentication caches are searched for the source IP address. In block 710, the process tests whether the source IP address is found. For example, if Authentication Proxy 400 determines that the source IP address matches at least one IP address stored in the filtering mechanism 219, then the Authentication Proxy 400 attempts to authenticate the user 302. In the preferred embodiment, Authentication Proxy 400 searches authentication caches 432, 434 for the source IP address. The goal of this search is to determine if the source IP address of the HTTP packet corresponds to an entry in any of the authentication caches 432, 434.).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Fuh et al. into the combination of Lee and Panse et al. and Liu et al. in order to guard against unwanted network traffic or access by unauthorized users (See Fuh et al. See Col. 1 Ln 30).
Claims 3, 10, 17 are rejected under 35 U.S.C. 103 as being unpatentable over Lee (US 20140244851 A1) and Panse et al. (US 20200162467 A1) and Liu et al. (US 20110173692 A1) and Fuh et al. (US 6609154 B1) and further in view of Wang et al. (US 20220070102 A1).
As to claim 3, the combination of Lee and Panse et al. and Liu et al. and Fuh et al. teaches the method according to claim 2 above. However, it does not expressly teach the details of wherein the connection request is transmitted using a secure network protocol that is configured in the security list.
Wang et al., from analogous art, teaches wherein the connection request is transmitted using a secure network protocol that is configured in the security list (See ¶ [0049], Fig. 8, Teaches that After extracting the header fields, the process 500 performs (at 525) a lookup on the appropriate ACL table associated with the logical router using the extracted set of header fields. The appropriate ACL table, as noted above, is the ACL table with rules for the direction of the data message (ingress or egress) as well as for the correct network layer protocol (e.g., IPv4 or IPv6).).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Wang et al. into the combination of Lee and Panse et al. and Liu et al. and Fuh et al. in order to use a table (e.g., an access control list (ACL) table) to determine whether the data message is subject to rate limiting controls defined for the logical router, and only if the data message is subject to such rate limiting controls, (ii) determines whether to allow the data message according to a rate limiting mechanism for the logical router (See Wang et al. ¶ [0002]).
As to claim 10, the combination of Lee and Panse et al. and Liu et al. and Fuh et al. teaches the one or more computer-readable media according to claim 9 above. However, it does not expressly teach the details of wherein the connection request is transmitted using a secure network protocol that is configured in the security list.
Wang et al., from analogous art, teaches wherein the connection request is transmitted using a secure network protocol that is configured in the security list (See ¶ [0049], Fig. 8, Teaches that After extracting the header fields, the process 500 performs (at 525) a lookup on the appropriate ACL table associated with the logical router using the extracted set of header fields. The appropriate ACL table, as noted above, is the ACL table with rules for the direction of the data message (ingress or egress) as well as for the correct network layer protocol (e.g., IPv4 or IPv6).).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Wang et al. into the combination of Lee and Panse et al. and Liu et al. and Fuh et al. in order to use a table (e.g., an access control list (ACL) table) to determine whether the data message is subject to rate limiting controls defined for the logical router, and only if the data message is subject to such rate limiting controls, (ii) determines whether to allow the data message according to a rate limiting mechanism for the logical router (See Wang et al. ¶ [0002]).
As to claim 17, the combination of Lee and Panse et al. and Liu et al. and Fuh et al. teaches the system according to claim 16 above. However, it does not expressly teach the details of wherein the connection request is transmitted using a secure network protocol that is configured in the security list.
Wang et al., from analogous art, teaches wherein the connection request is transmitted using a secure network protocol that is configured in the security list (See ¶ [0049], Fig. 8, Teaches that After extracting the header fields, the process 500 performs (at 525) a lookup on the appropriate ACL table associated with the logical router using the extracted set of header fields. The appropriate ACL table, as noted above, is the ACL table with rules for the direction of the data message (ingress or egress) as well as for the correct network layer protocol (e.g., IPv4 or IPv6).).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Wang et al. into the combination of Lee and Panse et al. and Liu et al. and Fuh et al. in order to use a table (e.g., an access control list (ACL) table) to determine whether the data message is subject to rate limiting controls defined for the logical router, and only if the data message is subject to such rate limiting controls, (ii) determines whether to allow the data message according to a rate limiting mechanism for the logical router (See Wang et al. ¶ [0002]).
Claims 4, 11, 18 are rejected under 35 U.S.C. 103 as being unpatentable over Lee (US 20140244851 A1) and Panse et al. (US 20200162467 A1) and Liu et al. (US 20110173692 A1) and further in view of Gourlay et al. (US 20140280846 A1).
As to claim 4, the combination of Lee and Panse et al. and Liu et al. teaches the method according to claim 1 above. However, it does not expressly teach the details of wherein the hostname is determined by using a reverse Domain Name System (DNS) lookup procedure.
Gourlay et al., from analogous art, teaches wherein the hostname is determined by using a reverse Domain Name System (DNS) lookup procedure (See ¶ [0043], Teaches that the network policy engine 212 can determine a DNS name of the device 206. In one embodiment, the network element 204 further includes a secondary DNS server to provide redundancy for a primary DNS server in the network 218. In this embodiment, the network policy engine 212 retrieves the DNS name for the device 206 by doing a reverse DNS lookup from the secondary DNS server using the IP address of the device 206. The determined DNS name can be a fully qualified domain name or a partial domain name.).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Wang et al. into the combination of Lee and Panse et al. and Liu et al. in order to determining a network policy for a port of a network element based on a device that is linked to that port (See Gourlay et al. ¶ [0002]).
As to claim 11, the combination of Lee and Panse et al. and Liu et al. teaches the one or more computer-readable media according to claim 8 above. However, it does not expressly teach the details of wherein the hostname is determined by using a reverse Domain Name System (DNS) lookup procedure.
Gourlay et al., from analogous art, teaches wherein the hostname is determined by using a reverse Domain Name System (DNS) lookup procedure (See ¶ [0043], Teaches that the network policy engine 212 can determine a DNS name of the device 206. In one embodiment, the network element 204 further includes a secondary DNS server to provide redundancy for a primary DNS server in the network 218. In this embodiment, the network policy engine 212 retrieves the DNS name for the device 206 by doing a reverse DNS lookup from the secondary DNS server using the IP address of the device 206. The determined DNS name can be a fully qualified domain name or a partial domain name.).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Wang et al. into the combination of Lee and Panse et al. and Liu et al. in order to determining a network policy for a port of a network element based on a device that is linked to that port (See Gourlay et al. ¶ [0002]).
As to claim 18, the combination of Lee and Panse et al. and Liu et al. teaches the system according to claim 15 above. However, it does not expressly teach the details of wherein the hostname is determined by using a reverse Domain Name System (DNS) lookup procedure.
Gourlay et al., from analogous art, teaches wherein the hostname is determined by using a reverse Domain Name System (DNS) lookup procedure (See ¶ [0043], Teaches that the network policy engine 212 can determine a DNS name of the device 206. In one embodiment, the network element 204 further includes a secondary DNS server to provide redundancy for a primary DNS server in the network 218. In this embodiment, the network policy engine 212 retrieves the DNS name for the device 206 by doing a reverse DNS lookup from the secondary DNS server using the IP address of the device 206. The determined DNS name can be a fully qualified domain name or a partial domain name.).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Wang et al. into the combination of Lee and Panse et al. and Liu et al. in order to determining a network policy for a port of a network element based on a device that is linked to that port (See Gourlay et al. ¶ [0002]).
Claims 7, 14 are rejected under 35 U.S.C. 103 as being unpatentable over Lee (US 20140244851 A1) and Panse et al. (US 20200162467 A1) and Liu et al. (US 20110173692 A1) and further in view of Fink (US 7817607 B1).
As to claim 7, the combination of Lee and Panse et al. and Liu et al. teaches the method according to claim 1 above. However, it does not expressly teach the details of wherein the security list includes information of an enterprise server and a home server.
Fink, from analogous art, teaches wherein the security list includes information of an enterprise server and a home server (See Col 5 Ln. 11 Teaches that The home agent 118 will authenticate the mobile subscriber (as more fully described below) and reference the access control list 120 to determine the appropriate communication protocol to be established. The home agent 118 will then establish a communication protocol that allows the communication to be sent to the first private network through VLAN Interface A 122. VLAN Interface A 122 interfaces first with load balancer A 126 which balances traffic over the VLAN 128 associated with the first private network. After passing through VLAN A 128, any of the plurality of servers associated with the first private network, e.g., server A1 134 or server A2 136, can be reached via the frame relay network or virtual private network (VPN) 130 associated with the first private network.).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Fink into the combination of Lee and Panse et al. and Liu et al. in order to access a router serving as the home agent and connect to their specific private network(s) (See Fink Col 1 ln 19).
As to claim 14, the combination of Lee and Panse et al. and Liu et al. teaches the one or more computer-readable media according to claim 8 above. However, it does not expressly teach the details of wherein the security list includes information of an enterprise server and a home server.
Fink, from analogous art, teaches wherein the security list includes information of an enterprise server and a home server (See Col 5 Ln. 11 Teaches that The home agent 118 will authenticate the mobile subscriber (as more fully described below) and reference the access control list 120 to determine the appropriate communication protocol to be established. The home agent 118 will then establish a communication protocol that allows the communication to be sent to the first private network through VLAN Interface A 122. VLAN Interface A 122 interfaces first with load balancer A 126 which balances traffic over the VLAN 128 associated with the first private network. After passing through VLAN A 128, any of the plurality of servers associated with the first private network, e.g., server A1 134 or server A2 136, can be reached via the frame relay network or virtual private network (VPN) 130 associated with the first private network.).
Thus, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teaching of Fink into the combination of Lee and Panse et al. and Liu et al. in order to access a router serving as the home agent and connect to their specific private network(s) (See Fink Col 1 ln 19).
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to James R Hollister whose telephone number is (571)270-3152. The examiner can normally be reached Mon - Fri 7:30 am - 4:00 pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Philip Chea can be reached at (571) 272-3951. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
James Hollister
/J.R.H./Examiner, Art Unit 2499 7/17/26
/PHILIP J CHEA/Supervisory Patent Examiner, Art Unit 2499