DETAILED ACTION
Authorization for Internet Communications
The examiner encourages Applicant to submit an authorization to communicate with the examiner via the Internet by making the following statement (from MPEP 502.03):
“Recognizing that Internet communications are not secure, I hereby authorize the USPTO to communicate with the undersigned and practitioners in accordance with 37 CFR 1.33 and 37 CFR 1.34 concerning any subject matter of this application by video conferencing, instant messaging, or electronic mail. I understand that a copy of these communications will be made of record in the application file.”
Please note that the above statement can only be submitted via Central Fax, Regular postal mail, or EFS Web (PTO/SB/439).
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Examiner Notes
Examiner cites particular columns and line numbers in the references as applied to the claims below for the convenience of the applicant. Although the specified citations are representative of the teachings in the art and are applied to the specific limitations within the individual claim, other passages and figures may apply as well. It is respectfully requested that, in preparing responses, the applicant fully consider the references in entirety as potentially teaching all or part of the claimed invention, as well as the context of the passage as taught by the prior art or disclosed by the examiner.
Failure to provide a certified translation may result in no benefit being accorded for the non-English application.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 11/06/2023 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Prior Art Howe et al. (U.S. PG PUB 2022/0286894) is from applicant’s IDS and will not be included in PTO-892.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 1: Regarding claim 1, this part of the eligibility analysis evaluates whether the claim falls within any statutory category. MPEP §2106.03. The claim recites method steps; thus, the claim is directed to a process which is one of the statutory categories of invention.
Step 2A Prong 1: This part of the eligibility analysis evaluates whether the claim recites a judicial exception. As explained in MPEP 2106.04(II) and the October 2019 Update, a claim “recites” a judicial exception when the judicial exception is “set forth” or “described” in the claim.
The limitations “extracting identification information from one or more payloads originating from one or more workloads; assigning an identity to each of the one or more workloads based on the identification information” as drafted, recite functions that, under its broadest reasonable interpretation, covers functions that could reasonably be performed in the mind, including with the aid of pen and paper, but for the recitation of generic computer components. That is, the limitations as drafted, are functions that, under its broadest reasonable interpretation, recite the abstract idea of a mental process. The limitations encompass a human mind carrying out the functions through observation, evaluation, judgment and/or opinion, or even with the aid of pen and paper. Thus, these limitations recite and fall within the “Mental Processes” grouping of abstract ideas. See MPEP §2106.04(a)(2). Accordingly, claim 1 recites a judicial exception (i.e. an abstract idea).
Step 2A, Prong 2, This part of the eligibility analysis evaluates whether the claim as a whole integrates the recited judicial exception into a practical application of the exception. This evaluation is performed by (a) identifying whether there are any additional elements recited in the claim beyond the judicial exception, and (b) evaluating those additional elements individually and in combination to determine whether the claim as a whole integrates the exception into a practical application. 2019 PEG Section III(A)(2), 84 Fed. Reg. at 54-55.
In this case, this judicial exception is not integrated into a practical application. The claim recites the following additional elements “a cloud-based system” and “operating in the cloud-based system” are recited at a high-level of generality such that it amounts no more than mere instructions to apply the exception using a generic computer component to perform the judicial exception. Accordingly, the additional elements do not integrate the recited judicial exception into a practical application, and the claim is therefore directed to the judicial exception. See MPEP 2106.05(f).
The additional element “monitoring traffic” fails to meaningfully limit the claim because the element is regarding data gathering and applying the method for execution, thus is categorized as insignificant extra solution activity, thus not practical application under prong 2. Accordingly, the additional elements do not integrate the recited judicial exception into a practical application, and the claim is therefore directed to the judicial exception. See MPEP 2106.05(f).
The additional element “” fails to meaningfully limit the claim because it does not require any particular application of the recited “enforcing,” and is at best the equivalent of merely adding the words “apply it” to the judicial exception. Accordingly, the additional elements do not integrate the recited judicial exception into a practical application, and the claim is therefore directed to the judicial exception. See MPEP 2106.05(f).
Step 2B, This part of the eligibility analysis evaluates whether the claim as a whole amounts to significantly more than the recited exception, i.e., whether any additional element, or combination of additional elements, adds an inventive concept to the claim. MPEP 2106.05.
As discussed above with respect to integration of the abstract idea into a practical application, the additional elements of the “a cloud-based system” and “operating in the cloud-based system” are merely generic computer components to apply the judicial exception which cannot provide an inventive concept.
The claims include additional elements “monitoring traffic” that are not sufficient to amount to significantly more than the judicial exception because they are essentially regarding data gathering and applying method for execution. Under step 2B, the courts have identified data gathering as well understood routine and conventional. See MEPE 2106.05d.
Furthermore, the limitation “enforcing policies on the one or more workloads and traffic associated therewith based on the assigned identity” does not require any particular application of the recited “enforcing,” and is at best the equivalent of merely adding the words “apply it” to the judicial exception. Mere instructions to apply an exception cannot provide an inventive concept. Accordingly, the claim does not appear to be patent eligible under 35 USC 101.
Claims 2, is a dependent claim rejected for the same reasons as claim 1. Furthermore, the claims include additional elements “wherein the monitoring includes inline monitoring of the one or more workloads associated with the cloud-based system” This additional element does not amount to a practical application, nor recite significantly more than a judicial exception, is merely data gathering which the court have identified as well understood, routine, and conventual activity. See MPEP 2106.05(d).
Claim 3, is a dependent claim rejected for the same reasons as claim 1. Furthermore, claims include additional elements “wherein the one or more payloads originate from the one or more workloads operating in the cloud-based system and are directed to one or more external systems, and wherein the one or more payloads are intercepted by the cloud-based system.” This additional element does not amount to a practical application, nor recite significantly more than a judicial exception, is merely data gathering which the court have identified as well understood, routine, and conventual activity. See MPEP 2106.05(d).
Claim 4, is a dependent claim rejected for the same reasons as claim 1. Furthermore, claims include additional elements “wherein the steps further comprise: identifying an authentication scheme used by the one or more workloads; extracting identification information from one or more payloads based on the authentication scheme; and discovering an identity for each of the one or more workloads.” This additional element does not amount to a practical application, nor recite significantly more than a judicial exception, is merely data gathering which the court have identified as well understood, routine, and conventual activity. See MPEP 2106.05(d).
Claim 5, is a dependent claim rejected for the same reasons as claim 1. Furthermore, claims include additional elements “wherein enforcing policies comprises rate limiting, and access control based on an identity of a workload associated with the traffic.” This additional element does not amount to a practical application, nor recite significantly more than a judicial exception, is merely data gathering which the court have identified as well understood, routine, and conventual activity. See MPEP 2106.05(d).
Claim 6, is a dependent claim rejected for the same reasons as claim 1. Furthermore, claims include additional elements “wherein the identification information is used to identify a type of workload from which the traffic originated.” This additional element does not amount to a practical application, nor recite significantly more than a judicial exception, is merely data gathering which the court have identified as well understood, routine, and conventual activity. See MPEP 2106.05(d).
Claim 7, is a dependent claim rejected for the same reasons as claim 6. Furthermore, claims include additional elements “wherein policy is enforced on traffic between the one or more workloads and one or more external systems based on a type of the one or more workloads.” This additional element does not amount to a practical application, nor recite significantly more than a judicial exception, is merely data gathering which the court have identified as well understood, routine, and conventual activity. See MPEP 2106.05(d).
Claim 8, is a dependent claim rejected for the same reasons as claim 1. Furthermore, claims include additional elements ”wherein the one or more workloads are associated with an enterprise having a plurality of departments, and wherein the steps further comprise: assigning each of the one or more workloads to a department of the plurality of departments based on the identification information.” This additional element does not amount to a practical application, nor recite significantly more than a judicial exception, is merely data gathering which the court have identified as well understood, routine, and conventual activity. See MPEP 2106.05(d).
Claim 9, is a dependent claim rejected for the same reasons as claim 1. Furthermore, claims include additional elements ” wherein the enforcing policy is based on a department to which a workload is assigned.” This additional element does not amount to a practical application, nor recite significantly more than a judicial exception, is merely data gathering which the court have identified as well understood, routine, and conventual activity. See MPEP 2106.05(d).
Claim 10, is a dependent claim rejected for the same reasons as claim 1. Furthermore, claims include additional elements “wherein the enforcing policy includes allowing or blocking traffic from a workload to an external system based on a department to which the workload is assigned.” This additional element does not amount to a practical application, nor recite significantly more than a judicial exception, is merely data gathering which the court have identified as well understood, routine, and conventual activity. See MPEP 2106.05(d).
Claim 11, is an independent device claim and is rejected for the same reasons as claim 1. In particular, the claim recites additional elements – A non-transitory computer-readable medium comprising instructions that, when executed, cause one or more processors to perform steps--. The medium and processors are recited at a high-level of generality (i.e., as a generic medium, processors) such that it amounts no more than mere instructions to apply the exception using a generic computer component. Accordingly, the additional element does not integrate the abstract idea into a practical application, nor is an inventive concept because it does not impose any meaningful limits on practicing the abstract idea. The claim is directed to an abstract idea.
Claims 12-20 are dependent product claims corresponding to 2-10, respectively and are rejected for the same reasons.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1, 4, 6, 7, 11, 14, 16, and 17 are rejected under 35 U.S.C. 103 as being unpatentable over Banerjee et al. (U.S. PG PUB 2018/0203741).
Regarding claim 1, Banerjee teaches a method comprising steps of:
monitoring traffic in a cloud-based system (see ¶[0048] “Resource consumption monitoring and resource allocation are critical components of cloud computing. It is to be understood that although this disclosure includes a detailed description on cloud computing,”);
extracting identification information from one or more payloads originating from one or more workloads operating in the cloud-based system (see ¶[0022] “Context identification program 116 may further process the collected data to extract performance metrics. Context identification program 116 may further communicate the extracted performance metrics to various components of the distributed data processing environment.”);
assigning an identity to each of the one or more workloads based on the identification information (see ¶ [0023] “Context identification program 116 executes a series of steps in order to track resource allocation by attaching resource allocation identifiers corresponding to a workload performed by one or more virtual machines, to associate the resource consumption of the workload at periodic time intervals in a uniform time scale. As depicted, context identification program 116 assigns an identifier corresponding to a workload and a virtual machine assigned to the workload.”); and
enforcing policies on the one or more workloads and traffic associated therewith based on the assigned identity (see ¶[0017] “Resource manager 108, residing in management console 104, enables implementation of policy driven host resource allocation and host resource allocation adjustment. Resource manager 108 may utilize host resource requirements, where the host resource requirements specify resource allocations for resource definitions of a particular virtual machine (e.g., virtual machine 112A and 112B). Resource manager 108 may also utilize host resource characteristics for resource allocations, where host resource characteristics may include an adapter type, connectivity to a particular type of a network, and a particular type of assist or acceleration processor (e.g., cryptographic processors).”).
Because Banerjee discloses multiple embodiments and implementations, and all the findings may be disclosed in different embodiments/implementations, obviousness rejection is made. One of ordinary skill in the art at the time of the invention would be able to combine different embodiments adjacent to each other in the prior art and does not require a leap of inventiveness. Banerjee discloses that these embodiments/implementations are used in order to allocate resources and monitor workloads for better performance (see ¶ [0022] of Banerjee).
Regarding claim 4, Banerjee teaches wherein the steps further comprise: identifying an authentication scheme used by the one or more workloads (see ¶[0070] “Security provides identity verification for cloud consumers and tasks, as well as protection for data and other resources.”); extracting identification information from one or more payloads based on the authentication scheme (see ¶[0022] “Context identification program 116 may further process the collected data to extract performance metrics. Context identification program 116 may further communicate the extracted performance metrics to various components of the distributed data processing environment.”); and discovering an identity for each of the one or more workloads (see ¶[0070] “Security provides identity verification for cloud consumers and tasks, as well as protection for data and other resources. User portal 83 provides access to the cloud computing environment for consumers and system administrators. Service level management 84 provides cloud computing resource allocation and management such that required service levels are met.”).
Regarding claim 6, Banerjee teaches wherein the identification information is used to identify a type of workload from which the traffic originated (see ¶[0028] “Context identification program 116 associates a workload and the virtual machine assigned to the workload with the resource consumption data collected using performance monitoring interrupts (PMIs) in a rolling buffer (step 208). In one embodiment, context identification program 116 may associate the workload and the virtual machine assigned to the workload with the resource consumption of processors or processor cores at periodic time intervals in a uniform time scale in a rolling buffer.”).
Regarding claim 7, Banerjee teaches wherein policy is enforced on traffic between the one or more workloads and one or more external systems based on a type of the one or more workloads (see ¶[0017] “Resource manager 108, residing in management console 104, enables implementation of policy driven host resource allocation and host resource allocation adjustment. Resource manager 108 may utilize host resource requirements, where the host resource requirements specify resource allocations for resource definitions of a particular virtual machine (e.g., virtual machine 112A and 112B). Resource manager 108 may also utilize host resource characteristics for resource allocations, where host resource characteristics may include an adapter type, connectivity to a particular type of a network, and a particular type of assist or acceleration processor (e.g., cryptographic processors).”).
Regarding claim 11, is an independent medium claim rejected for the same reasons as claim 1. In addition, Banerjee teaches a non-transitory computer-readable medium comprising instructions that, when executed, cause one or more processors to perform steps (see ¶[0021]).
Regarding claims 14, 16, and 17, are dependent claims corresponding to claims 4, 6, and 7 above, and are rejected for the same reasons.
Claim(s) 2, 3, 8, 9, 12, 13, 18, and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Banerjee et al. (U.S. PG PUB 2018/0203741) in view of Howe et al. (U.S. PG PUB 2022/0286894).
Regarding claim 2, Banerjee does not expressly disclose, however, Howe teaches wherein the monitoring includes inline monitoring of the one or more workloads associated with the cloud-based system (see ¶[0054] “As such, the cloud-based system 100 provides inline monitoring inspecting traffic between the users 102, the Internet 104, and the cloud services 106, including Secure Sockets Layer (SSL) traffic.”).
Hence, it would have been obvious to one or ordinary skill in the art before the effective filing date to modify the teachings of Banerjee by adapting Howe to limit traffic for privacy reasons or cost (see ¶[0005] of Howe).
Regarding claim 3, Banerjee teaches wherein the one or more payloads originate from the one or more workloads operating in the cloud-based system and are directed to one or more external systems (see ¶[0020] “Virtual machine 112A, virtual machine 112B, and hypervisor 110 are resource consumers. Virtual resources are supported by physical resources, which may exist internally or externally of physical server 102.”).
Banerjee does not expressly disclose, however, Howe teaches wherein the one or more payloads are intercepted by the cloud-based system (see ¶[0167] “All traffic between the cloud service, including (but not limited to) signaling and workflows, must be over an encrypted tunnel ensuring zero capability for interception or manipulation of the service access or function within the Edge. Thus, the service is only available to those who are allowed to access it and nothing more.”).
Hence, it would have been obvious to one or ordinary skill in the art before the effective filing date to modify the teachings of Banerjee by adapting Howe to limit traffic for privacy reasons or cost (see ¶[0005] of Howe).
Regarding claim 8, Banerjee does not expressly disclose, however, Howe teaches wherein the one or more workloads are associated with an enterprise having a plurality of departments, and wherein the steps further comprise: assigning each of the one or more workloads to a department of the plurality of departments based on the identification information (see ¶[0237] “Consuming 5G UDM/UDR values as an identity control from an UPF connected control function will give the service provider (Zscaler) the ability to correctly assign identity to traffic flows. Which, in turn, will allow for the assignment of correct policy and steering decisions to be applied on the traffic initiating from the UE. These identifiers should be consumed, similar to how Security Assertion Markup Language (SAML) is used to consume the output of an Identity Provider (IDP). Note that the service could also signal the results of its analyses to 5G core components including (but not limited to) the Authentication Management Function (AMF), or the Session Management Function (SMF), to enable the 5G core to dynamically update how UE traffic is managed.”).
Hence, it would have been obvious to one or ordinary skill in the art before the effective filing date to modify the teachings of Banerjee by adapting Howe to limit traffic for privacy reasons or cost (see ¶[0005] of Howe).
Regarding claim 9, Banerjee does not expressly disclose, however, Howe teaches wherein the enforcing policy is based on a department to which a workload is assigned (see ¶[0060] “Further, the cloud-based system 100 can be multi-tenant, with each tenant having its own users 102 and configuration, policy, rules, etc. One advantage of the multi-tenancy and a large volume of users is the zero-day/zero-hour protection in that a new vulnerability can be detected and then instantly remediated across the entire cloud-based system 100. The same applies to policy, rule, configuration, etc. changes—they are instantly remediated across the entire cloud-based system 100. As well, new features in the cloud-based system 100 can also be rolled up simultaneously across the user base, as opposed to selective and time-consuming upgrades on every device at the locations 112, 114, 118, and the devices 110, 116.”).
Hence, it would have been obvious to one or ordinary skill in the art before the effective filing date to modify the teachings of Banerjee by adapting Howe to limit traffic for privacy reasons or cost (see ¶[0005] of Howe).
Regarding claims 12, 13, 18, and 19 are dependent claims corresponding to claims 2, 3, 8, and 9 above, and are rejected for the same reasons.
Claim(s) 5, 10, 15 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Banerjee et al. (U.S. PG PUB 2018/0203741) in view of Meyers et al. (U.S. PG PUB 2017/0104790).
Regarding claim 5, Banerjee does not expressly disclose, however, Meyers teaches wherein enforcing policies comprises rate limiting (see ¶[0011] “Example security actions include permit, block, notify, capture traffic for analysis, quarantine, limit traffic rate, and the like.”), and access control based on an identity of a workload associated with the traffic (see ¶[0011] “A security policy is a construct that identifies access to applications or resources of the network. A security policy can include a filter and an action to perform based on the filter. For example, the security policy can be described by a data structure with a list of accessible services and/or ports allowed for communication”).
Regarding claim 10, Banerjee does not expressly disclose, however, Meyers teaches wherein the enforcing policy includes allowing or blocking traffic from a workload to an external system based on a department to which the workload is assigned (see ¶[0019] “security policy can be enforced in various ways based on the actions available to the system 100, such as blocking, permitting, isolating, rerouting, capturing, and the like. For example, various services may be denied for communication purposes, such as a particular social media communication or the ability to ping when the asset is identified as highly risky relative to other assets of the network. Blocking communications by port or data inspection can restrain vulnerabilities from exploitation. For another example, specific services or application functionality can be restricted, such as denial of transfer via file transfer protocol (“FTP”) or limitations for uploading a particular size or class of document. Enabling enforcement to occur dynamically based on risk of the asset (which may change at any given moment) allows for the IPS, NFGW, or other network security device to adjust enforcement policies dynamically.”).
Hence, it would have been obvious to one or ordinary skill in the art before the effective filing date to modify the teachings of Banerjee by adapting Meyers to ensure secure and authorized communications (see ¶[0008] of Meyers).
Regarding claims 15 and 20 are dependent claims corresponding to claims 5 and 10 above, and are rejected for the same reasons.
Interview Requests
In accordance with 37 CFR 1.133(a)(3), requests for interview must be made in advance. Interview requests are to be made by telephone (571-270-7848) call or FAX (571-270-8848). Applicants must provide a detailed agenda as to what will be discussed (generic statement such as “discuss §102 rejection” or “discuss rejections of claims 1-3” may be denied interview). The detail agenda along with any proposed amendments is to be written on a PTOL-413A or a custom form and should be faxed (or emailed, subject to MPEP 713.01.I / MPEP 502.03) to the Examiner at least 5 business days prior to the scheduled interview. Interview requests submitted within amendments may be denied because the Examiner was not notified, in advance, of the Applicant Initiated Interview Request and due to time constraints may not be able to review the interview request to prior to the mailing of the next Office Action.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Andreasen et al. (U.S. PG PUB 2009/0109845) teaches receiving packet flow optimization (PFO) configuration data that associates each rule name of multiple PFO rule names with a corresponding method for processing a data packet in a communications network based on data in a payload of a layer 3 protocol of the data packet. A first policy message is received from a policy management process in the communications network. The first policy message includes rule data that indicates a signaled rule name associated with a particular network address in the communications network. In response to receiving the first policy message, a data packet of the particular network address is processed according to a particular method associated with a particular rule name selected based on the signaled rule name. As a result, a PFO policy is controlled from the policy management process.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to CARINA YUN whose telephone number is (571)270-7848. The examiner can normally be reached Mon, Tues, Thurs, 9-4 (EST).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to call.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Kevin Young can be reached on (571) 270-3180. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
Carina Yun
Patent Examiner
Art Unit 2194
/CARINA YUN/Examiner, Art Unit 2194