Detailed Action
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 02/19/2024 is being considered by the examiner.
Priority
Acknowledgment is made of applicant’s claim for foreign priority under 35 U.S.C. 119 (a)-(d). The certified copy has been filed in parent Application No. JP2023-117857, filed on 07/19/2023.
Specification
The title of the invention is not descriptive. A new title is required that is clearly indicative of the invention to which the claims are directed.
Claim Objections
Claims 1 and 4-14 are objected to because of the following informalities: “in a case” condition Examiner recommends to change the “in a case” condition with “when” because in a case the conditional limitation step is not reached, then the remaining limitation steps do not have to followed and will render the remain limitations not valid, therefore, it will not be required to show anticipation or obviousness for all paths of the conditional limitation. Examiner suggest to replacing “in a case” with “when”. Appropriate correction is required.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
(a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention.
Claims 1-2, and 13-14 are rejected under 35 U.S.C. 102(a)2 as being anticipated by INOUE et al. (JP-2021184533-A hereafter INOUE).
Regarding claim 1 INOUE discloses an information processing system comprising:
a processor (see INOUE par.21: “a plurality of CPUs and microprocessors (MPUs) cooperate to control the operation of the entire image forming apparatus 101”) configured to:
in a case where a request to resolve a host name is received (see INOUE par.22: “the print system having the configuration shown in FIG. 1 is operated as before, the name resolution setting performed in the image forming apparatus 101 will be described with reference to FIG. FIG. 2 shows an example of the setting screen related to name resolution. The screen 201 shown in FIG. 2 is an example of the name resolution setting screen displayed on the touch panel screen of the image forming apparatus 101, and the user can select from "use only DNS", "use only DoH", and "use both DNS and DoH". You can touch and select one.”), request an encrypted name resolution client server that performs name resolution using encrypted communication with an encrypted name resolution server to resolve the host name (see INOUE par.20: “The communication unit 407 performs data communication with an external device, and for example, performs data communication with the DSN server 102 and Proxy server 105 on the intranet, and the DoH server 103 and server terminal 104 on the Internet 106. .. In this embodiment, DoH (DNS over HTTPS) is exemplified as an example of a method of performing name resolution via encrypted communication, but the present embodiment is not limited to this. For example, the method of performing name resolution via encrypted communication may be DoT (DNS over TLS) or the like. In this case, the image forming apparatus shall perform data communication with the DoT server on the Internet 106.”, par.24: “user touches and selects "Use only DoH", the image forming apparatus 101 is set to perform name resolution only by inquiring to the DoH server 103.”).
Regarding claim 2 INOUE discloses the information processing system according to claim 1, INOUE further teaches wherein the processor is configured to:
acquire a name resolution result of the host name from the encrypted name resolution client server (see INOUE par.29-31: “the DNS server 102 transmits the IP address of the DoH server 103 to the image forming apparatus 101 in response to the reception of the name resolution request…the DoH server 103 transmits the IP address of the server terminal 104 to the image forming apparatus 101 in response to the reception of the name resolution request.”).
Regarding claim 13 is a computer-readable media claim corresponding to the information processing system of claim 1 respectively, and rejected under the same rational set forth in connection with the rejection of claim 1.
A non-transitory computer readable medium storing an information processing program causing a computer to execute a process comprising: (see INOUE par.0014-0016: “The CPU 401 executes various processes using computer programs and data stored in the ROM 402 and the RAM 403. As a result, the CPU 401 controls the operation of the entire image forming apparatus 101, and also executes or controls each process described later as what the image forming apparatus 101 performs. The ROM 402 stores setting data of the image forming apparatus 101, computer programs and data related to the activation of the image forming apparatus 101, computer programs and data related to the basic operation of the image forming apparatus 101, and the like. The RAM 403 has an area for storing computer programs and data loaded from the ROM 402 and the HDD 404, and data received by the communication unit 407 from an external device.”
Regarding claim 14 INOUE discloses an information processing system comprising:
a processor (see INOUE par.21: “a plurality of CPUs and microprocessors (MPUs) cooperate to control the operation of the entire image forming apparatus 101”) configured to:
in a case where a request to resolve a host name is received from an
information processing apparatus (see INOUE par.22: “the print system having the configuration shown in FIG. 1 is operated as before, the name resolution setting performed in the image forming apparatus 101 will be described with reference to FIG. FIG. 2 shows an example of the setting screen related to name resolution. The screen 201 shown in FIG. 2 is an example of the name resolution setting screen displayed on the touch panel screen of the image forming apparatus 101, and the user can select from "use only DNS", "use only DoH", and "use both DNS and DoH". You can touch and select one.”), request an encrypted name resolution server to resolve the host name using encrypted communication (see INOUE par.20: “The communication unit 407 performs data communication with an external device, and for example, performs data communication with the DSN server 102 and Proxy server 105 on the intranet, and the DoH server 103 and server terminal 104 on the Internet 106. .. In this embodiment, DoH (DNS over HTTPS) is exemplified as an example of a method of performing name resolution via encrypted communication, but the present embodiment is not limited to this. For example, the method of performing name resolution via encrypted communication may be DoT (DNS over TLS) or the like. In this case, the image forming apparatus shall perform data communication with the DoT server on the Internet 106.”, par.24: “user touches and selects "Use only DoH", the image forming apparatus 101 is set to perform name resolution only by inquiring to the DoH server 103.”);
acquire a name resolution result of the host name from the encrypted name
resolution server (see par.29-31: “the DNS server 102 transmits the IP address of the DoH server 103 to the image forming apparatus 101 in response to the reception of the name resolution request…the DoH server 103 transmits the IP address of the server terminal 104 to the image forming apparatus 101 in response to the reception of the name resolution request.”); and
transmit the name resolution result of the host name to the information
processing apparatus (see INOUE par.29-31: “the DNS server 102 transmits the IP address of the DoH server 103 to the image forming apparatus 101 in response to the reception of the name resolution request…the DoH server 103 transmits the IP address of the server terminal 104 to the image forming apparatus 101 in response to the reception of the name resolution request.”).
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 3 and 15 are rejected under 35 U.S.C. 103 as being unpatentable over INOUE as applied to claim 2, in further view of Helfinstine et al. (US-12200136-B2 hereafter Helfinstine).
Regarding claim 3 INOUE discloses the information processing system according to claim 2, INOUE does not explicitly teach, however Helfinstine teaches wherein the processor is configured to:
request the encrypted name resolution client server to resolve the host name without using DoH (see Helfinstine Fig.1 and Col.3 lines 19-22: “The method 109 may comprise a method of sending DNS queries with one more layers of encryption, such as DoT. The method 109 may be performed by a system and/or computing device comprising a DoT application 110.” Furthermore Col.4 lines 9-10: “a DoT authoritative server 118”) and acquire the name resolution result of the host name from the encrypted name resolution client server (see Helfinstine Fig.1 and Col.4 lines 1-20: “The DoT recursive resolver 116 may be configured to determine DNS information. For example, the DoT recursive resolver 116 may be configured to determine an IP address associated with a requested domain. The DoT recursive resolver 106 may be configured to send the DNS query to the IP address associated with the requested domain…The IP address may be associated with a DoT authoritative server 118. The DoT authoritative may be associated with a website. The DoT authoritative server 118 may receive the DNS query from the DoT recursive resolver 116. The DoT authoritative server 118 may be configured to determine a reply to the DNS query…The DoT recursive resolver 116 may be configured to send the reply from the DoT authoritative server 118 to the DoT forwarder 114, the DoT stub resolver 112, and/or the DoT application 110”).
It would have been obvious to someone of ordinary skill in the art before the
effective filing date of the claimed invention to have combined INOUE teaching of claim 2 with Helfinstine teaching because Helfinstine teaching of, “The method 100 may comprise a method of sending DNS queries without one or more layers of encryption, such as DNS-over-TLS (DoT) and/or DNS-over-HTTPS (DoH).”, (see Helfinstine Col.2 lines 2-5). The reason to combine would have been to have choices when querying the encrypted name resolution client server.
Regarding claim 15 INOUE discloses the information processing system according to claim 14, INOUE further discloses wherein the processor is configured to:
request the encrypted name resolution server to resolve the host name using the DoH as the encrypted communication (see INOUE par.20: “The communication unit 407 performs data communication with an external device, and for example, performs data communication with the DSN server 102 and Proxy server 105 on the intranet, and the DoH server 103 and server terminal 104 on the Internet 106. .. In this embodiment, DoH (DNS over HTTPS) is exemplified as an example of a method of performing name resolution via encrypted communication, but the present embodiment is not limited to this. For example, the method of performing name resolution via encrypted communication may be DoT (DNS over TLS) or the like. In this case, the image forming apparatus shall perform data communication with the DoT server on the Internet 106.”, par.24: “user touches and selects "Use only DoH", the image forming apparatus 101 is set to perform name resolution only by inquiring to the DoH server 103.”). and
INOUE does not explicitly teach, however Helfinstine teaches
receive a request to resolve the host name, in which DoH is not used , from the information processing apparatus (see Helfinstine Fig.1 and Col.3 lines 19-22: “The method 109 may comprise a method of sending DNS queries with one more layers of encryption, such as DoT. The method 109 may be performed by a system and/or computing device comprising a DoT application 110.” Furthermore Col.4 lines 9-10: “a DoT authoritative server 118”);
It would have been obvious to someone of ordinary skill in the art before the
effective filing date of the claimed invention to have combined INOUE teaching of claim 14 with Helfinstine teaching because Helfinstine teaching of, “The method 100 may comprise a method of sending DNS queries without one or more layers of encryption, such as DNS-over-TLS (DoT) and/or DNS-over-HTTPS (DoH).”, (see Helfinstine Col.2 lines 2-5). The reason to combine would have been to have choices when querying the encrypted name resolution client server.
Claim 4 is rejected under 35 U.S.C. 103 as being unpatentable over INOUE as applied to claim 1, in further view of Moriya et al. (US-20230017329-A1 hereafter Moriya).
Regarding claim 4 INOUE discloses the information processing system according to claim 1, INOUE does not explicitly teach, however Moriya teaches wherein the processor is configured to:
request the encrypted name resolution client server to resolve the host name in a case where a host name resolution process using the encrypted communication is valid (see Moriya Fig.6 and par.0064: “determines whether use of DoH is set. In a case where a setting value corresponding to the setting item DoH is ON, the DNS control unit 1040 determines that use of DoH is set (YES in step S601), and the processing proceeds to step S602”, par.0067-0068: “S604, the control unit 1040 transfers the name resolution request requested by the application, to the DoH client 1080. Subsequently, in step S605, the DoH client 1080 having received the name resolution request requests the DoH server 107 to perform name resolution by using the encrypted communication… S608, the control unit 1040 receives a result of the name resolution from the DoH client 1080, and determines whether the IP address has been acquired as a result of the name resolution. In a case where the IP address corresponding to the host name has been acquired as a result of the name resolution by the DoH server 107”); and
request a name resolution server that performs the name resolution without using the encrypted communication to resolve the host name in a case where the host name resolution process using the encrypted communication is invalid (see Moriya Fig.6 and par.0064: “In a case where the setting value corresponding to the setting item DoH is OFF, the DNS control unit 1040 determines that use of DoH is not set (NO in step S601), and the processing proceeds to step S606”, par.0069: “In step S606, the control unit 1040 requests the DNS client 1021 to perform name resolution. Subsequently, in step S607, the DNS client 1021 transfers the name resolution request to the DNS server 102. The name resolution request is performed in plain text as described above. When the host name is a domain name managed by DNS server 102, the DNS server 102 returns an IP address corresponding to the domain.”).
It would have been obvious to someone of ordinary skill in the art before the
effective filing date of the claimed invention to have combined INOUE teaching of claim 1 with Moriya teaching because Moriya teaching of, “a communication apparatus, including a setting unit configured to set whether to use encrypted communication for name resolution, as operation setting of the communication apparatus, a storage unit configured to store a condition for excluding from a target of the name resolution using the encrypted communication, and a communication control unit configured to, in a case where name resolution of a host name requested from an application is performed, request a first Domain Name System (DNS) server to perform the name resolution of the host name via an encrypted communication path established with the first DNS server at least based on a fact that use of the encrypted communication is set by the setting unit, and to request a second DNS server to perform the name resolution of the host name by plain text based on a fact that non-use of the encrypted communication is set by the setting unit, wherein, in a case where the request of the name resolution of the host name satisfies the condition stored in the storage unit, the communication control unit requests the second DNS server to perform the name resolution of the host name by the plain text even in a case where use of the encrypted communication is set by the setting unit.”, (see Moriya par.0010).
Claim 5 is rejected under 35 U.S.C. 103 as being unpatentable over INOUE in view of Moriya as applied to claim 4, in further view of Helfinstine et al. (US-12200136-B2 hereafter Helfinstine).
Regarding claim 5 INOUE in view of Moriya discloses the information processing system according to claim 4, Moriya further teaches wherein the processor is configured to:
request the name resolution server to resolve the host name or request the encrypted name resolution server to resolve the host name using the encrypted communication in a case where the name resolution request process for the encrypted name resolution client server is invalid (see Moriya par.0068-0069: “In a case where the IP address corresponding to the host name has not been acquired (NO in step S608), the processing proceeds to step S606. For example, in a case where communication with the DoH server cannot be performed or in a case where the result of the name resolution received from the DoH server indicates that the destination could not be found, the control unit 1040 determines that the IP address has not been acquired. The processing in step S608 is processing to implement, in the case where the destination cannot be found by Doll fallback transiting the name resolution to name resolution by plain text. In step S606, the control unit 1040 requests the DNS client 1021 to perform name resolution. Subsequently, in step S607, the DNS client 1021 transfers the name resolution request to the DNS server 102.”). and
INOUE in view of Moriya do not explicitly teach however Helfinstine teaches
request the encrypted name resolution client server to resolve the host name in a case where a name resolution request process for the encrypted name resolution client server is valid (see Helfinstine Col.3 lines 52- Col.4 lines 1-12: “the DoT forwarder 114 may be configured to not send the DNS request. Based on the DoT forwarder 114 determining that the requested domain name is appropriate, the DoT forwarder 114 may be configured to send the DNS request. The DoT forwarder 114 may be configured to send the DNS request via TLS… The DNS request from the DoT forwarder 114 may be received by a DoT recursive resolver 116… the DoT recursive resolver 116 may be configured to determine an IP address associated with a requested domain… The IP address may be associated with a DoT authoritative server 118. The DoT authoritative may be associated with a website. The DoT authoritative server 118 may receive the DNS query from the DoT recursive resolver 116.”).
It would have been obvious to someone of ordinary skill in the art before the
effective filing date of the claimed invention to have combined INOUE in view of Moriya teaching of claim 4 with Helfinstine teaching because Helfinstine teaching of, “Based on the DoT forwarder 114 determining that the requested domain name is inappropriate, the DoT forwarder 114 may be configured to not send the DNS request. Based on the DoT forwarder 114 determining that the requested domain name is appropriate, the DoT forwarder 114 may be configured to send the DNS request. The DoT forwarder 114 may be configured to send the DNS request via TLS.”, (see Helfinstine Col.3 lines: 52-61).
Claim 6 is rejected under 35 U.S.C. 103 as being unpatentable over INOUE as applied to claim 1, in further view of WANG et al. (CN-116032542-A hereafter WANG).
Regarding claim 6 INOUE discloses the information processing system according to claim 1, INOUE does not teach, however WANG teaches wherein the processor is configured to:
request the encrypted name resolution client server to resolve the host name in a case where a version of an encrypted name resolution client application implemented in a host apparatus is older than a version of an encrypted name resolution client application implemented in the encrypted name resolution client server (see WANG par.36: “browsers such as Chrome and Firefox support DoH configuration, and a small number of operating systems can support system-level DoH configuration, but most older operating systems cannot support global DoH configuration. If you want DoH to be available to all applications in the entire operating system, you need a way to support global DoH.”, par.38: “provides a query method, device, network equipment and readable storage medium, through the UDP DNS to DoH service, the ordinary DNS query request is converted into a DoH query request, and then forwarded to the upstream DoH server to obtain the corresponding query results. In this way, the problem that the old version of the operating system cannot use the global DoH can be avoided, and the security of the DNS service can be improved.”).
It would have been obvious to someone of ordinary skill in the art before the
effective filing date of the claimed invention to have combined INOUE teaching of claim 1 with WANG teaching because WANG teaching of, “an operating system that does not support DoH only needs to modify the address of the DNS server to the address of a network device that can provide UDP DNS to DoH services, and all DNS query requests on the system can be converted into DoH query requests, thereby avoiding the old version The operating system cannot use the global DoH problem to improve the security of DNS services.”, (see WANG par.76).
Claim 7 and 8 are rejected under 35 U.S.C. 103 as being unpatentable over INOUE as applied to claim 1, in further view of Boucadair et al. (US-20240048576-A1 hereafter Boucadair).
Regarding claim 7 INOUE discloses the information processing system according to claim 1, INOUE does not explicitly teach, however Boucadair teaches wherein the processor is configured to:
perform an authentication request process of requesting the encrypted name resolution client server to perform authentication (see Boucadair par.0234-0235: “Upon receipt of the DoH request, the first DoH server 62 may interface with an authorisation server 63 to retrieve the instructions to be applied when a new connection should be set up. To do so, the first DoH server 62 transmits to the authorisation server 63 a redirection authorisation verification request, for example of the “Access-Request” type.”); and
request the encrypted name resolution client server to resolve the host name in a case where the authentication request process has succeeded (see Boucadair par.0240: “the authorisation server 63 may communicate these different information (domain name, addresses, alternative port number, etc.) to the first DoH server 62, in response to the redirection authorisation verification request, for example in a “Access-Accept” type message. In particular, the addresses/port number may be communicated in the response in addition to the domain name so as to avoid a DoH client asking another server (which may be malicious) for the resolution of this domain name.”).
It would have been obvious to someone of ordinary skill in the art before the
effective filing date of the claimed invention to have combined INOUE teaching of claim 1 with Boucadair teaching because Boucadair teaching of, “the use of such an authorisation server allows improving the reliability of the different procedures/actions, in particular for verifying the legitimacy of the second server or for solving the authentication problems.”, (see Boucadair par.0127).
Regarding claim 8 INOUE discloses the information processing system according to claim 2, INOUE does not explicitly teach, however Boucadair teaches wherein the processor is configured to:
perform an authentication request process of requesting the encrypted name resolution client server to perform authentication (see Boucadair par.0234-0235: “Upon receipt of the DoH request, the first DoH server 62 may interface with an authorisation server 63 to retrieve the instructions to be applied when a new connection should be set up. To do so, the first DoH server 62 transmits to the authorisation server 63 a redirection authorisation verification request, for example of the “Access-Request” type.”); and
request the encrypted name resolution client server to resolve the host name in a case where the authentication request process has succeeded (see Boucadair par.0240: “the authorisation server 63 may communicate these different information (domain name, addresses, alternative port number, etc.) to the first DoH server 62, in response to the redirection authorisation verification request, for example in a “Access-Accept” type message. In particular, the addresses/port number may be communicated in the response in addition to the domain name so as to avoid a DoH client asking another server (which may be malicious) for the resolution of this domain name.”).
It would have been obvious to someone of ordinary skill in the art before the
effective filing date of the claimed invention to have combined INOUE teaching of claim 2 with Boucadair teaching because Boucadair teaching of, “the use of such an authorisation server allows improving the reliability of the different procedures/actions, in particular for verifying the legitimacy of the second server or for solving the authentication problems.”, (see Boucadair par.0127).
Claim 9 is rejected under 35 U.S.C. 103 as being unpatentable over INOUE in view of Helfinstine as applied to claim 3, in further view of Boucadair et al. (US-20240048576-A1 hereafter Boucadair).
Regarding claim 9 INOUE in view of Helfinstine disclose the information processing system according to claim 3, INOUE in view of Helfinstine do not explicitly teach, however Boucadair teaches wherein the processor is configured to:
perform an authentication request process of requesting the encrypted name resolution client server to perform authentication (see Boucadair par.0234-0235: “Upon receipt of the DoH request, the first DoH server 62 may interface with an authorisation server 63 to retrieve the instructions to be applied when a new connection should be set up. To do so, the first DoH server 62 transmits to the authorisation server 63 a redirection authorisation verification request, for example of the “Access-Request” type.”); and
request the encrypted name resolution client server to resolve the host name in a case where the authentication request process has succeeded (see Boucadair par.0240: “the authorisation server 63 may communicate these different information (domain name, addresses, alternative port number, etc.) to the first DoH server 62, in response to the redirection authorisation verification request, for example in a “Access-Accept” type message. In particular, the addresses/port number may be communicated in the response in addition to the domain name so as to avoid a DoH client asking another server (which may be malicious) for the resolution of this domain name.”).
It would have been obvious to someone of ordinary skill in the art before the
effective filing date of the claimed invention to have combined INOUE in view of Helfinstine teaching of claim 3 with Boucadair teaching because Boucadair teaching of, “the use of such an authorisation server allows improving the reliability of the different procedures/actions, in particular for verifying the legitimacy of the second server or for solving the authentication problems.”, (see Boucadair par.0127).
Claim 10 is rejected under 35 U.S.C. 103 as being unpatentable over INOUE in view of Moriya as applied to claim 4, in further view of Boucadair et al. (US-20240048576-A1 hereafter Boucadair).
Regarding claim 10 NOUE in view of Moriya disclose the information processing system according to claim 4, NOUE in view of Moriya does not explicitly teach, however Boucadair teaches wherein the processor is configured to:
perform an authentication request process of requesting the encrypted name resolution client server to perform authentication (see Boucadair par.0234-0235: “Upon receipt of the DoH request, the first DoH server 62 may interface with an authorisation server 63 to retrieve the instructions to be applied when a new connection should be set up. To do so, the first DoH server 62 transmits to the authorisation server 63 a redirection authorisation verification request, for example of the “Access-Request” type.”); and
request the encrypted name resolution client server to resolve the host name in a case where the authentication request process has succeeded (see Boucadair par.0240: “the authorisation server 63 may communicate these different information (domain name, addresses, alternative port number, etc.) to the first DoH server 62, in response to the redirection authorisation verification request, for example in a “Access-Accept” type message. In particular, the addresses/port number may be communicated in the response in addition to the domain name so as to avoid a DoH client asking another server (which may be malicious) for the resolution of this domain name.”).
It would have been obvious to someone of ordinary skill in the art before the
effective filing date of the claimed invention to have combined INOUE in view of Moriya teaching of claim 4 with Boucadair teaching because Boucadair teaching of, “the use of such an authorisation server allows improving the reliability of the different procedures/actions, in particular for verifying the legitimacy of the second server or for solving the authentication problems.”, (see Boucadair par.0127).
Claim 11 is rejected under 35 U.S.C. 103 as being unpatentable over INOUE in view of Moriya, and Helfinstine as applied to claim 5, in further view of Boucadair et al. (US-20240048576-A1 hereafter Boucadair).
Regarding claim 11 INOUE in view of Moriya, and Helfinstine disclose the information processing system according to claim 5, INOUE in view of Moriya, and Helfinstine do not explicitly teach, however Boucadair teaches wherein the processor is configured to:
perform an authentication request process of requesting the encrypted name resolution client server to perform authentication (see Boucadair par.0234-0235: “Upon receipt of the DoH request, the first DoH server 62 may interface with an authorisation server 63 to retrieve the instructions to be applied when a new connection should be set up. To do so, the first DoH server 62 transmits to the authorisation server 63 a redirection authorisation verification request, for example of the “Access-Request” type.”); and
request the encrypted name resolution client server to resolve the host name in a case where the authentication request process has succeeded (see Boucadair par.0240: “the authorisation server 63 may communicate these different information (domain name, addresses, alternative port number, etc.) to the first DoH server 62, in response to the redirection authorisation verification request, for example in a “Access-Accept” type message. In particular, the addresses/port number may be communicated in the response in addition to the domain name so as to avoid a DoH client asking another server (which may be malicious) for the resolution of this domain name.”).
It would have been obvious to someone of ordinary skill in the art before the
effective filing date of the claimed invention to have combined INOUE in view of Moriya, and Helfinstine teaching of claim 5 with Boucadair teaching because Boucadair teaching of, “the use of such an authorisation server allows improving the reliability of the different procedures/actions, in particular for verifying the legitimacy of the second server or for solving the authentication problems.”, (see Boucadair par.0127).
Claim 12 is rejected under 35 U.S.C. 103 as being unpatentable over INOUE in view of WANG as applied to claim 6, in further view of Boucadair et al. (US-20240048576-A1 hereafter Boucadair).
Regarding claim 12 INOUE in view of WANG disclose the information processing system according to claim 6, INOUE in view of WANG do not explicitly teach, however Boucadair teaches wherein the processor is configured to:
perform an authentication request process of requesting the encrypted name resolution client server to perform authentication (see Boucadair par.0234-0235: “Upon receipt of the DoH request, the first DoH server 62 may interface with an authorisation server 63 to retrieve the instructions to be applied when a new connection should be set up. To do so, the first DoH server 62 transmits to the authorisation server 63 a redirection authorisation verification request, for example of the “Access-Request” type.”); and
request the encrypted name resolution client server to resolve the host name in a case where the authentication request process has succeeded (see Boucadair par.0240: “the authorisation server 63 may communicate these different information (domain name, addresses, alternative port number, etc.) to the first DoH server 62, in response to the redirection authorisation verification request, for example in a “Access-Accept” type message. In particular, the addresses/port number may be communicated in the response in addition to the domain name so as to avoid a DoH client asking another server (which may be malicious) for the resolution of this domain name.”).
It would have been obvious to someone of ordinary skill in the art before the
effective filing date of the claimed invention to have combined INOUE in view of WANG teaching of claim 6 with Boucadair teaching because Boucadair teaching of, “the use of such an authorisation server allows improving the reliability of the different procedures/actions, in particular for verifying the legitimacy of the second server or for solving the authentication problems.”, (see Boucadair par.0127).
Conclusion
The prior art made of record and not relied upon is considered pertinent to
applicant's disclosure:
Barnett et al.( US-20230291715-A1) a way to keep DNS traffic from “leaking” around a trusted DNS-control system. A small local agent is installed on a user device and is paired with a trusted external DNS protection server. When an application wants to reach a website or other internet resource, the agent intercepts the DNS lookup instead of letting the app contact outside DNS servers directly. The agent can also block direct DNS access attempts over common DNS paths, including standard DNS on port 53 and encrypted DNS methods like DoH and DoT. The agent then sends the request to the trusted DNS protection server for resolution. The server can either return the correct IP address or send back a block/denial response.
Helfinstine et al.( US-20220353233-A1) the system 100 may support and/or facilitate a Domain Name System (DNS), Hypertext Transfer Protocol (HTTP), Hypertext Transfer Protocol Secure (HTTPS), DNS over HTTPS (DoH), Transport Layer Security (TLS) protocol, DNS over TLS (DoT), encrypted DNS, encrypted server name indication (eSNI) hash service, and/or the like. For example, the system 100 may implement eSNI using an arithmetic hash of a fully qualified domain name (FQDN) sent/received via DoH (and/or DoT).
Any inquiry concerning this communication or earlier communications from the examiner should be directed to DUILIO MUNGUIA whose telephone number is (571)270-5277. The examiner can normally be reached M-F 9:30AM - 5:00PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Eleni A Shiferaw can be reached at (571) 272-3867. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/DUILIO MUNGUIA/Examiner, Art Unit 2497
/ELENI A SHIFERAW/Supervisory Patent Examiner, Art Unit 2497