Prosecution Insights
Last updated: October 01, 2026
Application No. 18/315,269

APPLYING A GROUP BASED POLICY TO NETWORK TRAFFIC FROM A CLIENT

Non-Final OA §103
Filed
May 10, 2023
Priority
Feb 16, 2023 — IN 202341010475
Examiner
BROWN, CHRISTOPHER J
Art Unit
2439
Tech Center
2400 — Computer Networks
Assignee
Hewlett Packard Enterprise Development L.P.
OA Round
3 (Non-Final)
76%
Grant Probability
Favorable
3-4
OA Rounds
0m
Est. Remaining
88%
With Interview

Examiner Intelligence

Grants 76% — above average
76%
Career Allowance Rate
544 granted / 720 resolved
+17.6% vs TC avg
Moderate +13% lift
Without
With
+12.6%
Interview Lift
resolved cases with interview
Typical timeline
3y 5m
Avg Prosecution
36 currently pending
Career history
759
Total Applications
across all art units

Statute-Specific Performance

§101
2.1%
-37.9% vs TC avg
§103
64.0%
+24.0% vs TC avg
§102
11.4%
-28.6% vs TC avg
§112
11.2%
-28.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 720 resolved cases

Office Action

§103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Arguments Applicant’s arguments with respect to claim(s) 1-9, 11-12, 15-24 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument. Applicant argues that Lei fails to teach “ does not disclose obtaining role information from a network access response message, identifying a GBP corresponding to the role, or applying the identified GBP to client traffic”. Examiner has pointed out previously that the role as taught by Lei is used to identify an access control policy, based on obtained role information. Examiner asserts that since access control policies are specific to each role, then the access control policy would have an “identifier”. It does not need to be explicitly stated because the ACL would not even be able to be accessed in the system without an “identifier”. Applicant argues that Lei fails to teach “mapping the role information to a group identifier”. Examiner notes that the Voit reference is explicitly used to ‘map role information to a group identifier”. Applicant states that “Voit is relied on for teaching mapping role information to a group ID”. Applicant argues that “Voit does not disclose obtaining role information from a network access response message” Examiner notes that the Lei reference is used for “obtaining role information from a network response message”. Examiner asserts that neither Lei or Voit alone teach the invention as claimed, and that is why the U.S.C. 103 rejection was made as a combination of Lei and Voit. Applicant alleges that the proposal therefore relied on impermissible hindsight. In response to applicant's argument that the examiner's conclusion of obviousness is based upon improper hindsight reasoning, it must be recognized that any judgment on obviousness is in a sense necessarily a reconstruction based upon hindsight reasoning. But so long as it takes into account only knowledge which was within the level of ordinary skill at the time the claimed invention was made, and does not include knowledge gleaned only from the applicant's disclosure, such a reconstruction is proper. See In re McLaughlin, 443 F.2d 1392, 170 USPQ 209 (CCPA 1971). Applicant does not argue against any prior art for new claims 21-24. Examiner has relied on Desai US 2021/0282069 to meet the new claims. Examiner also points to Hooda US 2018/0255017 for an alternate teaching. This reference is recorded in the “Notice of References Cited” but not relied upon. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1, 8, 9, 11, 12, is/are rejected under 35 U.S.C. 103 as being unpatentable over Lei US 2006/0026286 in view of Voit US 2018/0139240. As per claim 1. Lei teaches A method comprising: intercepting, by a proxy service on a proxy network device, a network access request message pertaining to a client from an access device on a network; forwarding, by the proxy service on the proxy network device, the network access request message to an authentication server; [0024] (teaches requesting access to a server that is forwarded through a proxy) Lei teaches intercepting, by the proxy service on the proxy network device, a network access response message including role information of the client from the authentication server; Lei teaches obtaining, by the proxy service on the proxy network device, the role information of the client from the network access response message; [0009][0046][0047] (teaches reverse proxy receives data from the origin or security server, including role information of the client) Lei teaches and in response to receiving network traffic from the client: identifying, by the proxy service on the proxy network device, a group based policy (GBP) corresponding to the role information of the client; and applying, by the proxy service on the proxy network device, the group based policy to the network traffic from the client. [0037][0043][0047][0051][0054] (teaches the proxy enforcing security based on role and access control groups and whether to allow communication based on said group security permissions) Voit teaches mapping role information to a group identifier wherein the group based policy comprises role derived traffic policy identified by the group ID that defines rules governing treatment of network traffic associated with clients assigned to that role independent of authorization of individual data requests. [0027][0029][0030] (teaches security group tags applied to a network flow, the group applying to a group, and policy enforcement for network traffic based on the security group and role based access control) It would have been obvious to one of ordinary skill in the art before the priority date of the instant application to use the teaching of Voit with the prior art because it improves network security. As per claim 8. Lei teaches The method of claim 1, wherein intercepting the network access response message comprises intercepting a network access acceptance message from the authentication server. [0009][0031][0046] (teaches intercepting and monitoring traffic, receiving security information from server) As per claim 9. Lei teaches the method of claim 1, wherein obtaining comprises receiving, by the proxy service on the proxy network device, the GBP from the authentication server. [0009][0033][0037][0043][0047][0051][0054] (teaches the proxy enforcing security based on role and access control groups and whether to allow communication based on said group security permissions) As per claim 11. Lei teaches the method of claim 1, wherein the GBP corresponding to the role information of the client is present on the proxy network device. [0009][0033][0037][0043][0047][0051][0054] (teaches the proxy enforcing security based on role and access control groups and whether to allow communication based on said group security permissions) As per claim 12. Lei teaches A proxy network device comprising: a processor; and a non-transitory storage medium storing instructions that, when executed by the processor, cause the proxy network device to: intercept a network access request message pertaining to a client from an access device on a network; [0024] (teaches requesting access to a server that is forwarded through a proxy) Lei teaches forward the network access request message to an authentication server; intercept a network access response message including role information of the client from the authentication server; obtain the role information of the client from the network access response message; [0009][0046][0047] (teaches reverse proxy receives data from the origin or security server, including role information of the client) Lei teaches and in response to receiving network traffic from the client: identify a group based policy (GBP) corresponding to the role information of the client; and apply the group based policy to the network traffic from the client. [0037][0043][0047][0051][0054] (teaches the proxy enforcing security based on role and access control groups and whether to allow communication based on said group security permissions) Voit teaches mapping role information to a group identifier wherein the group based policy comprises role derived traffic policy identified by the group ID that defines rules governing treatment of network traffic associated with clients assigned to that role independent of authorization of individual data requests. [0027][0029][0030] (teaches security group tags applied to a network flow, the group applying to a group, and policy enforcement for network traffic based on the security group and role based access control) It would have been obvious to one of ordinary skill in the art before the priority date of the instant application to use the teaching of Voit with the prior art because it improves network security. Claim(s) 3, 4, 5, 21-24 is/are rejected under 35 U.S.C. 103 as being unpatentable over Lei US 2006/0026286 in view of Voit US 2018/0139240 in view of Desai US 20210282069. As per claim 3. Desai teaches the method of claim 1, wherein the network access response message includes a Media Access Control (MAC) address of the client. [0011]-[0013] [0030] [0037][0054] (teaches mapping a MAC address to a role and using said information at access points to approve or deny communications) As per claim 4. Desai teaches the method of claim 3, further comprising: obtaining, by the proxy service on the proxy network device, the MAC address of the client from the network access response message; mapping, by the proxy service on the proxy network device, the MAC address of the client to the role information of the client; and storing, by the proxy service on the proxy network device, the mapping between the MAC address with the role information of the client. [0011]-[0013] [0030] [0037][0054] (teaches mapping a MAC address to a role and using said information at access points to approve or deny communications) It would have been obvious to one of ordinary skill in the art at the time the invention was filed to use the teaching of Desai with the prior art because it improves security. As per claim 5. Desai teaches the method of claim 4, further comprising: sending, by the proxy service on the proxy network device, the mapping between the MAC address and the role information of the client to a second access device, wherein the GBP corresponding to the role information of the client is applied to the network traffic received on the second access device from the client. [0023] (teaches network discovery protocol which allows access points to share policies and roles, etc) As per claim 21. (New) The method of claim 5, Desai teaches wherein sending the mapping between the MAC address and the role information of the client comprises synchronizing the mapping between the MAC address and the role information of the client with a second proxy network device. [0011] [0013][0023][0035](teaches mapping of MAC addresses of clients, with roles; access control based on role, synchronizing the mapping policy with neighbor discovery protocol to propagate access policies to other proxies) As per claim 22. (New) The method of claim 21, Desai teaches further comprising: receiving, by the second proxy network device, the synchronized mapping between the MAC address and the role information of the client. [0011] [0013][0023][0035](teaches mapping of MAC addresses of clients, with roles; access control based on role, synchronizing the mapping policy with neighbor discovery protocol to propagate access policies to other proxies) As per claim 23. (New) The method of claim 22, Desai teaches further comprising: receiving, by the second proxy network device, network traffic associated with the client; identifying, by the second proxy network device, the role information of the client based on the synchronized mapping; identifying, by the second proxy network device, a group based policy (GBP) corresponding to the identified role information by mapping the identified role information; and applying, by the second proxy network device, the GBP to the network traffic associated with the client. [0011] [0013][0023][0035](teaches mapping of MAC addresses of clients, with roles; access control based on role, synchronizing the mapping policy with neighbor discovery protocol to propagate access policies to other proxies) Lei teaches applies the identified GBP to network traffic associated with the client. [0037][0043][0047][0051][0054] (teaches the proxy enforcing security based on role and access control groups and whether to allow communication based on said group security permissions) As per claim 24. (New) The method of claim 23, Desai teaches wherein, after the client transitions from association with the proxy network device to association with the second proxy network device, the second proxy network device: identifies the role information of the client based on the synchronized mapping; identifies a group based policy (GBP) corresponding to the identified role information; and applies the identified GBP to network traffic associated with the client. [0011] [0013][0023][0035](teaches mapping of MAC addresses of clients, with roles; access control based on role, synchronizing the mapping policy with neighbor discovery protocol to propagate access policies to other proxies) Lei teaches applies the identified GBP to network traffic associated with the client. [0037][0043][0047][0051][0054] (teaches the proxy enforcing security based on role and access control groups and whether to allow communication based on said group security permissions) Claim(s) 2 /are rejected under 35 U.S.C. 103 as being unpatentable over Lei US 2006/0026286 in view of Voit US 2018/0139240 in view of Boutros US 2018/0097734. As per claim 2. Boutros teaches the method of claim 1, wherein intercepting the network access request message comprises listening to network communication from an Anycast IP address configured on the access device. [0003][0018][0028] (teaches configuring router to use Anycast IP address to further communicate with external networks) It would have been obvious to one of ordinary skill in the art at the time the invention was filed to use the teaching of Boutros with the prior art because it simplifies network routing. Claim(s) 7, is/are rejected under 35 U.S.C. 103 as being unpatentable over Lei US 2006/0026286 in view of Voit US 2018/0139240 in view of Sethi US 2023/0049341. As per claim 7. Sethi teaches the method of claim 1, wherein intercepting the network access request message comprises intercepting an Extensible Authentication Protocol (EAP) response message of the client. [0015][0017] (teaches interception of EAP from client and forwarding to authentication server) It would have been obvious to one of ordinary skill in the art to use the teaching of Sethi with the prior art because it expands the amount of authentication method compatibility and increases security. Claim(s) 15-16 is/are rejected under 35 U.S.C. 103 as being unpatentable over Lei US 2006/0026286 in view of Voit US 2018/0139240 in view of Sivaraj US 2017/0195220. As per claim 15. Sivaraj teaches the proxy network device of claim 12, wherein the network comprises a Virtual Extensible Local Area Network (VXLAN). [0011]-[0015] (teaches use of VXLAN) It would have been obvious to one of ordinary skill in the art at the time the invention was filed to use the teaching of Sivaraj with the prior art because it allows implementation of virtual networks. As per claim 16. Lei teaches A non-transitory machine-readable storage medium comprising instructions that upon execution cause a proxy network device to: intercept, via a proxy service on the proxy network device, forward, via the proxy service on the proxy network device, the network access request message to an authentication server; [0024] (teaches requesting access to a server that is forwarded through a proxy) Lei teaches intercept, via the proxy service on the proxy network device, a network access response message including role information of the client from the authentication server; [0009][0046][0047] (teaches reverse proxy receives data from the origin or security server, including role information of the client) Lei teaches obtain, via the proxy service on the proxy network device, the role information of the client from the network access response message; and in response to receiving network traffic from the client: identify, via the proxy service on the proxy network device, a group based policy (GBP) corresponding to the role information of the client; and apply, via the proxy service on the proxy network device, the group based policy to the network traffic from the client. [0037][0043][0047][0051][0054] (teaches the proxy enforcing security based on role and access control groups and whether to allow communication based on said group security permissions) Voit teaches mapping role information to a group identifier wherein the group based policy comprises role derived traffic policy identified by the group ID that defines rules governing treatment of network traffic associated with clients assigned to that role independent of authorization of individual data requests. [0027][0029][0030] (teaches security group tags applied to a network flow, the group applying to a group, and policy enforcement for network traffic based on the security group and role based access control) It would have been obvious to one of ordinary skill in the art before the priority date of the instant application to use the teaching of Voit with the prior art because it improves network security. Sivaraj teaches a network access request message pertaining to a client from an access device on a VXLAN; [0011]-[0015] (teaches use of VXLAN) It would have been obvious to one of ordinary skill in the art at the time the invention was filed to use the teaching of Sivaraj with the prior art because it allows implementation of virtual networks. Claim(s) 17-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Lei US 2006/0026286 in view of Voit US 2018/0139240 in view of Sivaraj US 2017/0195220 in view of Desai US 2021/0282069. As per claim 17. Desai teaches The non-transitory machine-readable storage medium of claim 16, further comprising instructions to: obtain, via the proxy service on the proxy network device, a MAC address of the client from the network access response message; map, via the proxy service on the proxy network device, the MAC address of the client with the role information of the client; and store, by the proxy service on the proxy network device, the mapping between the MAC address and the role information of the client. [0011]-[0013] [0030] [0037][0054] (teaches mapping a MAC address to a role and using said information at access points to approve or deny communications) As per claim 18. Desai teaches the non-transitory machine-readable storage medium of claim 17, further comprising instructions to: send the mapping between the MAC address and the role information of the client to a second access device, wherein the GBP corresponding to the role information of the client is applied to the network traffic received on the second access device from the client. [0011]-[0013] [0030] [0037][0054] (teaches mapping a MAC address to a role and using said information at access points to approve or deny communications) As per claim 19. Sivaraj teaches the non-transitory machine-readable storage medium of claim 18, further comprising instructions to send the mapping between the MAC address and the role information of the client via a VXLAN. [0011]-[0015] (teaches use of VXLAN and mapping MAC address of the client) As per claim 20. Desai teaches the non-transitory machine-readable storage medium of claim 16, further comprising instructions to authenticate the access device through the authentication server prior to forwarding the network access request message to the authentication server. [0011]-[0013] [0030] [0037][0054] (teaches mapping a MAC address to a role and using said information at access points to approve or deny communications) Conclusion A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to CHRISTOPHER BROWN whose telephone number is (571)272-3833. The examiner can normally be reached M-F 8-5. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Luu Pham can be reached at (571) 270-5002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /CHRISTOPHER J BROWN/Primary Examiner, Art Unit 2439
Read full office action

Prosecution Timeline

Show 5 earlier events
Apr 06, 2026
Final Rejection mailed — §103
Jun 08, 2026
Response after Non-Final Action
Jul 06, 2026
Request for Continued Examination
Jul 09, 2026
Response after Non-Final Action
Aug 11, 2026
Non-Final Rejection mailed — §103
Sep 22, 2026
Interview Requested
Sep 28, 2026
Examiner Interview Summary
Sep 28, 2026
Applicant Interview (Telephonic)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12719928
SYSTEM AND METHOD FOR ADAPTIVE DECEPTION ORCHESTRATION
2y 0m to grant Granted Aug 25, 2026
Patent 12712905
EVALUATING NETWORK FLOW RISKS
3y 11m to grant Granted Aug 18, 2026
Patent 12694100
CREATION AND RETENTION OF IMMUTABLE SNAPSHOTS TO FACILITATE RANSOMWARE PROTECTION
3y 5m to grant Granted Jul 28, 2026
Patent 12689631
USING MESSAGE CONTEXT TO EVALUATE SECURITY OF REQUESTED DATA
5y 10m to grant Granted Jul 21, 2026
Patent 12688291
RANSOMWARE DETECTION AND DATA PRUNING MANAGEMENT
1y 11m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
76%
Grant Probability
88%
With Interview (+12.6%)
3y 5m (~0m remaining)
Median Time to Grant
High
PTA Risk
Based on 720 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month