DETAILED ACTION
This office action is in response to the RCE filed on 04/07/2026.
Claims 1, 3-5, 9-11, 14 are amended.
Claims 7-8, 17-18 are cancelled.
Claims 1-6, 9-16, and 19-20 are presented for examination.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 04/07/2026 has been entered.
Response to Arguments
Applicant’s arguments, see Remarks pg. 6 filed 04/07/2026 and Remarks pg. 2-3 filed 03/05/2026, with respect to 35 USC 112 (a) rejection have been fully considered and are persuasive. The 35 USC 112 (a) rejection has been withdrawn.
Applicant’s arguments with respect to the 35 USC 103 rejections to the claims filed in Remarks pg. 6-7 on 04/07/2026 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
Applicant further argues in essence:
[a] “In response to that suggestion, claim 1 has been amended to recite that the messaging includes electronic mail, instant messaging, and video conferencing services that are available to users during a cyber security event instead of usual communication interfaces of the users…. As suggested in the advisory action, Thaker does not disclose the claimed configuration. The remaining cited art is likewise silent. For at least the foregoing reasons, the rejection of claims 1-6, 9-16, and 19-20 under section 103 should be withdrawn. Reconsideration and allowance of the claims are respectfully requested.”
In response to [a], while examiner agrees and the claims are rejected under a different combination of references for the new limitation, Schultz is still relied upon to show at least Email communication and video conferencing types being services that are offered by the system initially, albeit not “instead of usual communication interfaces of the users”.
Schultz: para.0017 “ Some example applications include web browsers, email clients” para.0040 “ For example, distributing all ingress traffic to one VPN connection may ensure that two-way voice, video, or other real-time type traffic” messaging includes email and video conferencing provided during attacks such as man in the middle attacks in para.0015.
New reference Karasaridis teaches the concept of generating new instances of existing communication services during cybersecurity events explained in more detail below to teach the new limitation. Therefore because of at least the reasons above, Szhultz is relied upon to teach at least available communication services during the cyber security event.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1-6, 9-16, 19-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Thaker et al. (hereinafter Thaker, US 2022/0232510 A1) in view of Yadav et al. (hereinafter Yadav, US 2021/0352096 A1) in view of Schultz et al. (hereinafter Schultz, US 2017/0171156 A1) in view of Karasaridis (hereinafter Kara, US 2016/0164911 A1).
Regarding Claim 1, Thaker discloses A computer system (Thaker: Fig. 1A 100 including system 115, network 105 and devices 110a-b) for providing a temporary self-provisioning communication system (Thaker: Fig. 1A System 115 Para.0023 “As shown in FIG. 1F, and by reference number 145, the system 115 performs one or more actions based on which threshold is satisfied.” Para.0024 “In some implementations, performing the one or more actions includes the system 115 causing traffic to be rerouted from a path associated with one of the wireless network devices 110A to a different path and/or cause a new path to be installed for one of the wireless network devices 110A.” system 115 provides automated remediation, i.e without directly consulting a human agent therefore self-provisioning, of risks detected, and providing temporary solutions such as in para.0027), comprising:
one or more processors; and non-transitory computer-readable storage media encoding instructions which, when executed by the one or more processors (Thaker: para.0046-0048 “correspond to system 115..As shown in FIG. 3, device 300 may include a bus 310, a processor 320, a memory 330, a storage component 340…non-transitory computer-readable medium”), cause the computer system to:
monitor criteria associated with the computer system (Thaker: para.0033 “As shown in FIG. 1G, and by reference number 155, the system 115 monitors performance of the one or more actions. The system 115 may monitor the performance of the network 105 based on performing the one or more actions.” Para.0011 “As shown in FIG. 1A, and by reference number 120, the system 115 may receive information identifying a quantity of wireless network devices 110A, distance data, signal strengths of the wireless network devices 110A, carrier data, and path data from network devices 110 associated with the network 105.” System 115 monitors the network and devices of the geographical location in Fig. 1A, including criteria 120, such as a quantity of connected devices, path data etc.),
wherein the computer system includes the temporary self-provisioning communication system (Thaker: para.0024 “the system 115 causing traffic to be rerouted from a path associated with one of the wireless network devices 110A to a different path and/or cause a new path to be installed for one of the wireless network devices 110A.” system 115 provides services that remediate/solve routing issues and providing temporary solutions such as in para.0027, automatically therefore includes a temporary self-provisioning communication system.);
calculate a risk score (Thaker: Fig. 1C, para.0019 diversity risk score) associated with the temporary self-provisioning communication system (Thaker: para.0013 “the system 115 assigns scores to the quantity of wireless network devices 110A available for service in the geographical location, the distance data, the signal strengths, the carrier data, and the path data to generate a plurality of scores.” Para.0019 “As shown in FIG. 1C, and by reference number 130, the system 115 combines the plurality of scores to generate a diversity risk score for the geographical location.” A score is assigned to each variable, and combined to generate a diversity risk score.); and
automatically, by the one or more processors, change networking of the computer system when the risk score exceeds a threshold (Thaker: para.0020 “As shown in FIG. 1D, and by reference number 135, the system 115 compares the diversity risk score to a diversity risk threshold scale.” Para.0023 “As shown in FIG. 1F, and by reference number 145, the system 115 performs one or more actions based on which threshold is satisfied.” Para.0024 “In some implementations, performing the one or more actions includes the system 115 causing traffic to be rerouted from a path associated with one of the wireless network devices 110A to a different path and/or cause a new path to be installed for one of the wireless network devices 110A.” Based on the diversity risk score exceeding some threshold, one or more of a plurality of networking changes are implemented in Fig. 1F. para.0024 lists a plurality of changes to networking that can be performed.).
However Thaker does not explicitly disclose wherein the computer system includes the temporary self-provisioning communication system that provides messaging and ticket tracking, wherein the messaging includes electronic mail, instant messaging, and video conferencing services that are available to users during a cyber security event instead of usual communication interfaces of the users; automatically, by the one or more processors, change networking of the computer system when the risk score exceeds a threshold including to: establish a new virtual private network using a new certificate; change to a new service provider for the networking; and route the messaging and ticket tracking of the temporary self-provisioning communication system through the new virtual private network of the new service provider.
Yadav discloses wherein the computer system includes the self-provisioning communication system (Yadav: Fig. 1 system 100, para.0013) that provides messaging and ticket tracking (Yadav: para.0003 “In various embodiments, a system receives data indicating an active security alert (e.g., an open ticket in a ticketing system) for a specific vulnerability. The system is enabled to retrieve vulnerability parameters from the alert and generate (or retrieve) a script for detecting the vulnerability based on those parameters. The script is then executed to determine whether the vulnerability has been remediated. Responsive to the script determining that the vulnerability has been remediated which in turn would result in no active alert for that specific vulnerability, the system transmits a request to resolve the security alert (e.g., and therefore, close the ticket). The script is then continually or periodically executed (e.g., at an interval or at a specified time(s)). If the system, through executing the script, determines that the vulnerability has been reintroduced into the environment (e.g., via a code upgrade or a parameter update), the system reopens the existing alert indicating that the vulnerability has been reintroduced into the environment.” Para.0050 “Based on the determination that the vulnerability exists, the script execution module 220 may transmit a command to the communication module 240 to transmit a message (e.g., to the tracking system) that the vulnerability still exists.” Messaging is performed by the system in para.0050, Tickets are tracked by the system that handles remediation of tickets for detection of vulnerabilities, and continuously updates the status of the ticket until resolution);
route the messaging and ticket tracking of the self-provisioning communication system through the current network and current service provider (Yadav: Para.0050 “Based on the determination that the vulnerability exists, the script execution module 220 may transmit a command to the communication module 240 to transmit a message (e.g., to the tracking system) that the vulnerability still exists.” Fig. 1, para.0017 “Network 115 may be any network that enables devices to connect to each other. For example, network 115 may be the Internet, a local network, or a combination of the two. Network 115 may support various protocols to connect devices.” The messaging and tracking of system 100 is routed via network 115 from system 120 to system 110.)
Therefore it would have been obvious to one ordinary skill in the art before the effective filing date of the claimed invention to combine Thaker with Yadav in order to incorporate wherein the computer system includes the self-provisioning communication system that provides messaging and ticket tracking; and route the messaging and ticket tracking of the self-provisioning communication system through the current network and current service provider, such that vulnerabilities identified from user tickets in Yadav in para.0014 and 0019, by the temporary self-provisioning communication system, may be considered when generating a risk score in Thaker that considered information from a plurality of sources in para.0019, para.0054.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of further considering types of risks detected from opened tickets from users (Yadav: para.0014, 0019), thereby increasing the accuracy by incorporating additional sources of data for vulnerabilities in the network.
However Thaker-Yadav does not explicitly disclose wherein the messaging includes electronic mail, instant messaging, and video conferencing services that are available to users during a cyber security event instead of usual communication interfaces of the users; automatically, by the one or more processors, change networking of the computer system when the risk score exceeds a threshold including to: establish a new virtual private network using a new certificate; change to a new service provider for the networking; and route the messaging and ticket tracking of the temporary self-provisioning communication system through the new virtual private network of the new service provider.
Schultz discloses wherein the messaging includes electronic mail, and video conferencing services that are available to users during a cyber security event (Schultz: para.0017 “ Some example applications include web browsers, email clients” para.0040 “ For example, distributing all ingress traffic to one VPN connection may ensure that two-way voice, video, or other real-time type traffic” messaging includes email and video conferencing provided during attacks such as man in the middle attacks in para.0015.)
automatically, by the one or more processors, change networking of the computer system based on a risk assessment (Schultz: para.0043 “ risk assessments for the networks that the client is currently connected to (or plans to connect to). This enables the client device 102 and VPN aggregation component 118 to dynamically manage the “security/performance” ratio.” Para.0074 “ At 704, the client device determines whether to establish a second VPN connection. The client device may determine to establish the second VPN connection based on a policy in a policy store that indicates that application traffic is to be provided with additional security.” Based on a plurality of risk and security considerations, a second connection, i.e vpn, can be established.) including to:
establish a new virtual private network using a new certificate (Schultz: para.0075 “At 706 (following the “YES” arrow), the client device establishes the second VPN connection. The client device establishes the second VPN connection over a second network interface device that interfaces with a second access network.” para.0026 “Embodiments may utilize different tunneling protocols, encryption protocols, authentication credentials, encryption keys, and so forth for different VPN connections. That way, an attacker that is able to compromise one VPN connection is not able to re-use authentication credentials or keys to compromise another VPN connection established by the VPN client.” Different encryption keys may be used for the new VPN, therefore a different certificate than the first network is used to establish the new vpn.);
change to a new service provider for the networking (Schultz: Fig.1-2, para.0075 “At 706 (following the “YES” arrow), the client device establishes the second VPN connection. The client device establishes the second VPN connection over a second network interface device that interfaces with a second access network.” As seen in Fig. 1 and 2, a different access network may be used for the second VPN, and a different VPN server may be used as well.); and
route communications through the new virtual private network of the new service provider (Schultz: para.0078 “At 712, the VPN aggregation component of the client device causes the flowlets to be distributed over multiple VPN connections, such as the first VPN connection and the second VPN connection. The distribution of flowlets over the multiple VPN connection may be determined based on load balancing over the multiple VPN connections.” Communications are transmitted over the second VPN via a different access network and VPN server, as seen in Fig. 1 and 2.).
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date to combine Thaker-Yadav with that of Schultz in order to incorporate wherein the messaging includes electronic mail, and video conferencing services that are available to users during a cyber security event; automatically, by the one or more processors, change networking of the computer system based on a risk assessment including to: establish a new virtual private network using a new certificate; change to a new service provider for the networking; and route communications through the new virtual private network of the new service provider, and apply this to the risk score threshold evaluation in Thaker and to the messaging and ticket tracking of Yadav, such that the messaging and ticket tracking of Yadav is routed via the more secure VPN connection established in Schultz.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improved security in communication (Schultz: para.0001, para.0004).
However Thaker-Yadav-Shultz does not explicitly disclose wherein the messaging includes electronic mail, instant messaging, and video conferencing services that are available to users during a cyber security event instead of usual communication interfaces of the user.
Kara discloses wherein the messaging includes instant messaging, and video conferencing services (Kara: para.0022 “Additionally, the user 101 may make telephone calls, conduct chat sessions, send instant messages, send or receive data, or perform any other types of communications using the legitimate client 102.” Para.0061 “or a combination thereof, can send or receive voice, video or data, and to communicate over the communications network 105” services provided by the system include instant message and video conferencing calls.)
that are available to users during a cyber security event instead of usual communication interfaces of the users (Kara: para.0049 “If, however, the comparison of the measurement to the threshold indicates the measurement satisfies the threshold, the method 600 may include, at step 606, characterizing and/or identifying that an attack is occurring at the first node in the system 100.” para.0051 “After estimating the type of virtual machines and the number of virtual machines to be deployed at the nodes with available capacity, the method 600 may include, at step 612, provisioning and launching the estimated number of virtual machines at the nodes with available capacity that are away from access links and/or peering links associated with the first node. The virtual machines launched at the nodes with available capacity may be utilized to handle legitimate traffic and requests, such as traffic generated by legitimate clients 102, 120.” The system is capable of instantiating new VMs that provide these services, instead of the usual communication interfaces i.e. those instantiated prior to the attack, during the cyber security attack).
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Thaker-Yadav-Schultz with Kara in order to incorporate wherein the messaging includes, instant messaging, and video conferencing services that are available to users during a cyber security event instead of usual communication interfaces of the user, and further apply this concept to the email communications of Schultz such that new instances of the email server are also instantiated during the cyber security attack.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improving network performance during a cybersecurity attack (Kara: para.0003).
Regarding Claim 2, Thaker-Yadav-Schultz-Kara discloses claim 1 as set forth above.
However Thaker-Schultz does not explicitly disclose wherein the networking includes at least one virtual private network between components of the computer system.
Schultz discloses wherein the networking includes at least one virtual private network between components of the computer system (Schultz: para.0046 “FIG. 2 is a block diagram that illustrates an example environment 200 for a router client device 202 aggregating multiple VPN connections. The router client device 202 connects to multiple access networks, such as the access network 104 and the access network 106. The router client device 202 establishes multiple VPN connections, such as the VPN connection 108 and the VPN connection 112, which are maintained concurrently for distribution of flowlets.” Fig. 2 shows VPN connections between multiple components of the computer system, environment 200.).
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date to combine Thaker-Yadav with that of Schultz in order to incorporate wherein the networking includes at least one virtual private network between components of the computer system.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improved security in communication (Schultz: para.0001, para.0004).
Regarding Claim 3, Thaker-Yadav-Schultz-Kara discloses claim 1 as set forth above.
However Thaker-Yadav does not explicitly disclose comprising further instructions which, when executed by the one or more processors, cause the computer system to: establish a virtual private network connection between components of the computer system; and prioritize data through the virtual private network connection.
Schultz discloses comprising further instructions which, when executed by the one or more processors (Schultz para.0058 processor 402), cause the computer system to: establish a virtual private network connection between components of the computer system (Schultz: para.0075 “At 706 (following the “YES” arrow), the client device establishes the second VPN connection. The client device establishes the second VPN connection over a second network interface device that interfaces with a second access network.” VPN is established between components of system 200. Fig. 2 between router and servers); and
prioritize data through the virtual private network connection (Schultz: para.0078 “At 712, the VPN aggregation component of the client device causes the flowlets to be distributed over multiple VPN connections, such as the first VPN connection and the second VPN connection. The distribution of flowlets over the multiple VPN connection may be determined based on load balancing over the multiple VPN connections. The distribution of flowlets over the multiple VPN connections may be determined based on a scheme to reduce the out-of-order arrival of packets at the receiver. The distribution of flowlets over the multiple VPN connection may be determined based on a balance between security and performance.” Data flow is prioritized between the VPN connection to optimize security and performance.).
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date to combine Thaker-Yadav with that of Schultz in order to incorporate comprising further instructions which, when executed by the one or more processors, cause the computer system to: establish a virtual private network connection between components of the computer system; and prioritize data through the virtual private network connection.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improved security in communication (Schultz: para.0001, para.0004).
Regarding Claim 4, Thaker-Yadav-Schultz-Kara discloses claim 1 as set forth above.
However Thaker-Yadav does not explicitly disclose comprising further instructions which, when executed by the one or more processors, cause the computer system to: establish a virtual private network connection between a client device and a network of the computer system; and prioritize data through the virtual private network connection.
Schultz discloses comprising further instructions which, when executed by the one or more processors (Schultz: para.0050 processor 302), cause the computer system to: establish a virtual private network connection between a client device and a network of the computer system (Schultz: para.0075 “At 706 (following the “YES” arrow), the client device establishes the second VPN connection. The client device establishes the second VPN connection over a second network interface device that interfaces with a second access network.” VPN is established between client device to the network of the computer system, i.e the network comprising the application servers.);
and prioritize data through the virtual private network connection (Schultz: para.0078 “At 712, the VPN aggregation component of the client device causes the flowlets to be distributed over multiple VPN connections, such as the first VPN connection and the second VPN connection. The distribution of flowlets over the multiple VPN connection may be determined based on load balancing over the multiple VPN connections. The distribution of flowlets over the multiple VPN connections may be determined based on a scheme to reduce the out-of-order arrival of packets at the receiver. The distribution of flowlets over the multiple VPN connection may be determined based on a balance between security and performance.” Data flow is prioritized between the VPN connection to optimize security and performance.).
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date to combine Thaker-Yadav with that of Schultz in order to incorporate comprising further instructions which, when executed by the one or more processors, cause the computer system to: establish a virtual private network connection between a client device and a network of the computer system; and prioritize data through the virtual private network connection.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improved security in communication (Schultz: para.0001, para.0004).
Regarding Claim 5 Thaker-Yadav-Schultz-Kara discloses Claim 4 as set forth above.
However Thaker-Yadav does not explicitly disclose comprising further instructions which, when executed by the one or more processors, cause the computer system to create the virtual private network connection between a wireless router and the network.
Schultz further discloses comprising further instructions which, when executed by the one or more processors, cause the computer system to create the virtual private network connection between a wireless router and the network (Schultz: para.0075 “At 706 (following the “YES” arrow), the client device establishes the second VPN connection. The client device establishes the second VPN connection over a second network interface device that interfaces with a second access network.” VPN is established between components of system 200. Fig. 2 between router and the network of the servers. Para.0058 “The router client device 400 …The private network interface hardware 406 may be any of various network interface hardware types, including wired Ethernet, wireless Ethernet” Fig. 4 400, 406, the router may be a wireless ethernet router.).
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date to combine Thaker-Yadav with that of Schultz in order to incorporate further instructions which, when executed by the one or more processors, cause the computer system to create the virtual private network connection between a wireless router and the network.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improved security in communication (Schultz: para.0001, para.0004).
Regarding Claim 6, Thaker-Yadav-Schultz-Kara discloses claim 1 as set forth above.
Thaker further discloses wherein the criteria are selected from one or more of: a length of time the temporary self-provisioning communication system has been active; and from where the temporary self-provisioning communication system is accessed (Thaker: para.0036 “As shown in FIG. 2, environment 200 may include system 115, which may include one or more elements of and/or may execute within a cloud computing system 202.” para.0012 “The distance data may include information identifying distances from the wireless network devices 110A to the geographical location. ” para.0015 “For example, the distance data identifying a distance from a wireless network device 110A to the geographical location may be assigned a first score (e.g., 0) when the distance satisfies a first distance condition (e.g., less than about three miles), a second score (e.g., 1) when the distance satisfies a second distance condition (e.g., between about three miles and about ten miles), and a third score (e.g., 2) when the distance satisfies a third distance condition (e.g., greater than about ten miles).” The criteria include a distance from the geographical location for each network device 110A that accesses the network 105 in Fig. 1A. The distance from the geographical location indicates where each wireless device 110A access the network 105.).
Regarding Claim 9, Thaker-Yadav-Schultz-Kara discloses claim 1 as set forth above.
Thaker further discloses comprising further instructions which, when executed by the one or more processors, cause the computer system to sum each of the criteria to calculate the risk score (Thaker: para.0019 “As shown in FIG. 1C, and by reference number 130, the system 115 combines the plurality of scores to generate a diversity risk score for the geographical location. For example, the system 115 may calculate a sum of the plurality of scores to generate the diversity risk score. ” each individual score for each criteria is summed together for a total diversity risk score.).
Regarding Claim 10, Thaker-Yadav-Schultz-Kara discloses claim 9 as set forth above.
Thaker further discloses comprising further instructions which, when executed by the one or more processors, cause the computer system to compare the risk score to the threshold (Thaker: para.0020 “As shown in FIG. 1D, and by reference number 135, the system 115 compares the diversity risk score to a diversity risk threshold scale.” Para.0023 “As shown in FIG. 1F, and by reference number 145, the system 115 performs one or more actions based on which threshold is satisfied.” The diversity risk is compared to a diversity risk threshold).
Regarding Claims 11-16, 19-20, they teach all of the same steps as claims 1-6, 9-10 but in method form (Thaker: para.0036). Therefore the supporting rationale for the rejection to claims 1-6, 9-10 apply equally as well to that of claims 11-16, 19-20.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Gao et al. US 2024/0250893 para.0060 , 0144-0145 and Fig. 2, calculates risks rates and modifies the network based on the risk.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to EUI H KIM whose telephone number is (571)272-8133. The examiner can normally be reached 7:30-5 M-R, M-F alternating.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Kamal B Divecha can be reached at 5712725863. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/EUI H KIM/ Examiner, Art Unit 2453
/KAMAL B DIVECHA/ Supervisory Patent Examiner, Art Unit 2453