DETAILED ACTION
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the America Invents Act (AIA ).
Response and Claim Status
The instant Office action is responsive to the response received April 28, 2026 (the “Response”).
Claims 1–20 are currently pending.
Drawings
37 C.F.R. § 1.84(q) recites “Lead lines are required for each reference character except for those which indicate the surface or cross section on which they are placed.”
Response to Arguments
Applicants respectfully traverse the drawing objection. The cited reference numerals are readily understandable from the face of the drawings, and a person of ordinary skill in the art would have no difficulty determining the structure or grouping to which each numeral corresponds. In Figs. 2-6, the challenged numerals are not floating ambiguously or detached from their associated subject matter. Rather, they are placed directly on, within, or immediately adjacent to the corresponding labeled blocks, dashed groupings, router enclosures, network clouds, and SIG-service elements. For example, in Fig. 2, “EDGE ROUTER 202” is placed directly on the edge-router enclosure, “TENANT 214” and “TENANT 232” are placed directly with the corresponding tenant groupings, and “SIG SERVICE 218,” “SIG SERVICE 236,” and “SIG SERVICE 238” are placed immediately adjacent to the corresponding SIG-service depictions. The same convention is used consistently throughout Figs. 3-6.
Applicants further submit that the figures at issue are schematic network diagrams and logical block diagrams, not mechanical drawings in which identification of a physical surface or cross-section is required to understand the disclosure. The present application consistently uses high-level architectural illustrations to depict tenants, VPNs, transport VPNs, transport tunnels, edge routers, and SIG services. The specification itself describes these figures as example network diagrams illustrating multi-tenanted networks accessing SIG services and preserving segmentation across such network architectures. In that context, immediate textual placement of a reference numeral on or adjacent to the corresponding block, grouping, or network element is a standard and fully comprehensible drafting convention.
Applicants further note that the written description confirms, and removes any possible doubt about, the identity of the challenged numerals. The specification expressly discusses, for example, tenant 214, tenant 232, edge router 202, and SIG services 218, 236, and 238 in connection with Fig. 2, and likewise discusses the corresponding numerals in Figs. 3-6 in a manner fully consistent with the drawing sheets. Thus, even if lead lines are not used for every such label, the correspondence between the numeral and the depicted element is clear from the combined disclosure of the drawings and specification. There is therefore no ambiguity, no risk of public confusion, and no substantive defect in the drawings as filed.
Response 6–7.
The Examiner is unpersuaded of error. 37 C.F.R. § 1.84(q) recites “Lead lines are required for each reference character except for those which indicate the surface or cross section on which they are placed.” Fig. 2, items 202, 214, 218, 232, 236, 238; Fig. 3, items 302, 314, 330, 332, 340; Fig. 4, items 402, 414, 422, 424, 432; Fig. 5, items 502, 514, 522, 524, 538; Fig. 6, items 602, 614, 630, 632, 640 are reference characters that do not indicate a surface or cross section on which they are placed. Thus, the drawings are objected to under 37 C.F.R. § 1.84(q) for failing to include lead lines for each reference character.
Because the drawing objection will be persisted, the Examiner directs Applicants’ attention to the Director of the USPTO by way of petition. See MPEP § 706.01; see also 37 C.F.R. § 1.181(a)(2).
The Objection
Fig. 2, items 202, 214, 218, 232, 236, 238; Fig. 3, items 302, 314, 330, 332, 340; Fig. 4, items 402, 414, 422, 424, 432; Fig. 5, items 502, 514, 522, 524, 538; Fig. 6, items 602, 614, 630, 632, 640 are reference characters that do not indicate a surface or cross section on which they are placed. Thus, the drawings are objected to under 37 C.F.R. § 1.84(q) for failing to include lead lines for each reference character.
Corrected drawing sheets in compliance with 37 C.F.R. § 1.121(d) are required in reply to the Office action to avoid abandonment of the application. Applicants are advised to employ the services of a competent patent draftsperson outside the Office, as the USPTO does not prepare new drawings. The corrected drawings are required in reply to the Office action to avoid abandonment of the application. The requirement for corrected drawings will not be held in abeyance.
Any amended replacement drawing sheet should include all of the figures appearing on the immediate prior version of the sheet, even if only one figure is being amended. The figure or figure number of an amended drawing should not be labeled as “amended.” If a drawing figure is to be canceled, the appropriate figure must be removed from the replacement sheet, and where necessary, the remaining figures must be renumbered and appropriate changes made to the brief description of the several views of the drawings for consistency. Additional replacement sheets may be necessary to show the renumbering of the remaining figures. Each drawing sheet submitted after the filing date of an application must be labeled in the top margin as either “Replacement Sheet” or “New Sheet” pursuant to 37 C.F.R. § 1.121(d). If the changes are not accepted by the Examiner, Applicants will be notified and informed of any required corrective action in the next Office action. The objection to the drawings will not be held in abeyance.
Claim Rejections – 35 U.S.C. § 103
The following is a quotation of 35 U.S.C. § 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Che, Antoo, and King
Claims 1, 5, 9, 13, and 17 are rejected under 35 U.S.C. § 103 as being obvious over Che et al. (US 2008/0215752 A1; filed May 16, 2008) in view of Antoo et al. (US 2016/0140520 A1; filed Nov. 18, 2014), and in further view of King et al. (US 2022/0263789 A1; filed Feb. 12, 2021).1
Response to Arguments
Applicants argue
[c]laim 1 recites in part: “transmit, by the edge router, the response to the tenant of the multi-tenanted network according to the one or more hash entries of the one or more reference tables.” The art or record does not teach or suggest at least this limitation.
The present application’s core inventive concept is not simply that a response is sent back after a request is made. Rather, the claim requires that the response be transmitted to the tenant according to the one or more hash entries of the one or more reference tables––that is, according to the very segmentation-preserving state created from request-associated identifiers so that the response is delivered to the correct tenant segment or VPN. The specification makes this point repeatedly. It explains that return traffic from a SIG service may include a destination IP and transport-tunnel-related identifier used as a key to identify a VPN identifier from which the associated flow originated, that the response may then be demultiplexed according to that identifier, and that port translation tables may also be consulted where source-port collisions arise. Conversely, King teaches maintaining packet-flow affinity so that packets in the same network flow are sent to the same compute instance in an overlay-network scaling scenario. That is not the same as returning SIG response traffic to the proper tenant segment according to request-associated hash entries in reference tables. Che likewise does not teach this limitation because Che merely forwards a response in accordance with generic service-routing information, not according to tenant-segmentation-preserving hash entries that maintain VPN or segment identity across shared transport structures. The Examiner’s combination therefore substitutes unrelated flow-selection and service-routing concepts for the claimed return-path preservation architecture. The references do not teach or suggest transmitting the response according to the claimed hash entries and reference tables.
Response 9–10.
The Examiner is unpersuaded of error. At the outset, the Examiner notes Applicants’ arguments are not commensurate with the scope of claim 1, which does not recite (1) transmitting a response to a correct tenant segment or VPN being according to very segmentation-preserving state created from request-associated identifiers; (2) returning traffic from a SIG service including a destination IP and transport-tunnel-related identifier used as a key to identify a VPN identifier from which the associated flow originated, that the response may then be demultiplexed according to that identifier, and that port translation tables may also be consulted where source-port collisions arise; and (3) returning SIG response traffic to the proper tenant segment according to request-associated hash entries in reference tables. See In re Self, 671 F.2d 1344, 1348 (CCPA 1982) (limitations not appearing in the claims cannot be relied upon for patentability).
Turning to the rejection, the Examiner relies principally on Che for teaching many of the recited elements of claim 1. Of particular note, the Examiner finds Che teaches adding one or more entries to one or more reference tables, wherein the one or more entries includes one or more identifiers associated with a request. Moreover, the Examiner finds Che teaches transmitting, by an edge router, a response to a tenant of a multi-tenanted network according to the one or more entries of the one or more reference tables.
The Examiner further finds Che’s one or more entries are not hash entries, turning to King to show that hash entries are known in the art. Thus, the Examiner proposes to include King’s teaching with Che, such that the combined system predictably yields transmitting, by an edge router, a response to a tenant of a multi-tenanted network according to one or more hash entries of one or more reference tables. Accordingly, Applicants’ arguments regarding Che’s and King’s alleged individual shortcomings (see Response 9–10) are unavailing. Here, the rejection is not based solely on Che or King alone, but rather on the cited references’ collective teachings. See In re Keller, 642 F.2d 413, 426 (CCPA 1981); In re Merck & Co., Inc., 800 F.2d 1091, 1097 (Fed. Cir. 1986).
Next, Applicants argue
[c]laim 1 also recites in part: “receive, by an edge router, from a tenant of a multi- tenanted network, a request to access a Secured Internet Gateway (SIG) service associated with a cloud provider.” The art or record does not teach or suggest at least this limitation.
The rejection does not reasonably establish that the cited combination teaches or suggests this limitation. Che is directed to service routing among service servers and service routers, where a service router receives a service interaction request from a service server and, after consulting a service information center, forwards the request onward to another service server. In other words, Che concerns service-server routing in a distributed service architecture, not traffic received at an edge router from a tenant in a multi-tenanted network for access to a Secured Internet Gateway (“SIG”) service. The present application, by contrast, is expressly directed to a multi-tenant edge-router environment in which separate tenants and separate tenant segments seek access to SIG services, and in which segmentation must be preserved while routing traffic to and from those SIG services. The specification repeatedly defines the problem in precisely those terms, explaining that multiple tenants and multiple segments per tenant may access SIG services through a multi-tenant edge device and that preservation of segmentation is the core technical challenge being addressed.
Response 10.
The Examiner is unpersuaded of error. At the outset, the Examiner notes Applicants’ arguments are not commensurate with the scope of claim 1, which does not recite (1) a multi-tenant edge-router environment in which separate tenants and separate tenant segments seek access to SIG services, and in which segmentation must be preserved while routing traffic to and from those SIG services; and (2) multiple tenants and multiple segments per tenant may access SIG services through a multi-tenant edge device and that preservation of segmentation is the core technical challenge being addressed. See Self, 671 F.2d at 1348.
Turning to the rejection, the Examiner finds Applicants’ arguments are also not responsive to the rejection, which relies on Che to teach receiving, by an edge router, from a tenant of a multi- tenanted network, a request to access a service. The Examiner further finds Che’s service is not a SIG service associated with a cloud provider, turning to Antoo to show that a SIG service associated with a cloud provider is known in the art. Thus, the Examiner proposes to include Antoo’s teaching with Che, such that the combined system predictably yields receiving, by an edge router, from a tenant of a multi- tenanted network, a request to access a Secured Internet Gateway (SIG) service associated with a cloud provider. Accordingly, Applicants’ arguments regarding Che’s alleged individual shortcomings (see Response 10–11) are unavailing. Here, the rejection is not based solely on Che alone, but rather on the cited references’ collective teachings. See Keller, 642 F.2d at 426; Merck, 800 F.2d at 1097.
Next, Applicants argue
[t]he Examiner’s reliance on Antoo does not cure this deficiency. Antoo concerns payroll-card funding and refers to “secured data gateway services” or secure webservices for transmitting funding-related data. That is not a SIG reference in the claimed technical sense. Antoo nowhere discloses or suggests a Secured Internet Gateway service in the SD-WAN / multi-tenant edge-routing context claimed here. Rather, it addresses secure transmission in a payroll-processing system. Thus, the rejection improperly equates a generic “secured data gateway” in a payroll-funding environment with a claimed SIG service associated with a cloud provider. That equation is not supported by the references and ignores the specialized meaning that the term “SIG service” carries in the present application. The cited art therefore fails to teach this limitation.
Response 11; see also id. at 13 (arguing “Antoo again does not fill the gap because its ‘secured data gateway services’ are part of a payroll-card funding platform and are unrelated to SIG services or multi-tenant edge routing.”).
The Examiner is unpersuaded of error. During examination, claims are given their broadest reasonable interpretation consistent with the Specification. See In re Am. Acad. of Sci. Tech Ctr., 367 F.3d 1359, 1364 (Fed. Cir. 2004). “Construing claims broadly during prosecution is not unfair to the applicant . . . because the applicant has the opportunity to amend the claims to obtain more precise claim coverage.” Id.
Applicants’ Specification does not define the term “Secured Internet Gateway (SIG) service” to so limit its interpretation. To be sure, the Specification recites “make use of some Secured Internet Gateway (SIG) services for their network (e.g., Cisco Umbrella, Zscalar, etc.).” Spec. ¶ 2. The Examiner’s emphasizes “e.g.” as these forms of a SIG service are merely exemplary. Therefore, under its broadest reasonable interpretation, the term “SIG service” is a service provided by a secure internet gateway.
Turning to the rejection, Antoo teaches “the systems and processes can be implemented through secured data gateway services.” Antoo ¶ 23; see also id. ¶ 16. Antoo, then, teaches a service provided by a secure internet gateway (the claimed “Secured Internet Gateway (SIG) service”).
Next, Applicants argue
[c]laim 1 also recites in part: “access one or more reference tables.” The art or record does not teach or suggest at least this limitation.
Although the Examiner points to Che’s consultation of service information to locate a corresponding physical address, IP address, or port, that disclosure at most teaches a conventional service-routing lookup and does not disclose the claimed reference-table architecture in the context required by claim 1. Che’s service information center stores correspondences used to route service interaction requests among service servers. That is a generic service-discovery or routing function. In the present application, however, the claimed “one or more reference tables” are not merely look-up structures for locating a destination. They are part of a segmentation-preserving framework that associates request-identifying information with tenant- and segment-specific forwarding state so that return traffic from a SIG service may be correctly demultiplexed and forwarded to the originating tenant segment. The application describes mux/demux tables, port translation tables, and per-transport-VPN tables that preserve segmentation for individual tenant segments even in the face of common transport links, overlapping addresses, and shared transport constructs. Accordingly, even if Che can be said to teach consultation of some information repository, it does not teach the claimed reference-table scheme as properly understood in light of the specification. The Examiner’s mapping is therefore overly abstract and fails to show that the prior art teaches the claimed limitation in the claimed context.
Response 11.
The Examiner is unpersuaded of error. At the outset, the Examiner notes Applicants’ arguments are not commensurate with the scope of claim 1, which does not recite (1) the claimed “one or more reference tables” are part of a segmentation-preserving framework that associates request-identifying information with tenant- and segment-specific forwarding state so that return traffic from a SIG service may be correctly demultiplexed and forwarded to the originating tenant segment; and (2) mux/demux tables, port translation tables, and per-transport-VPN tables that preserve segmentation for individual tenant segments even in the face of common transport links, overlapping addresses, and shared transport constructs. See Self, 671 F.2d at 1348.
Turning to the rejection, Che’s “service information center I is designed to store the routing information of various services handled by each service server. Here, the routing information includes . . . physical addresses.” Che ¶ 26. According to Che, “[t]he physical address of a service may be the IP address and corresponding port number of the service server that provides the service.” Id. ¶ 28
For example,
[i]n step 303, the service information center I finds the corresponding physical address, that is, the IP address and port of the service server S2 that can provide the service requested by the service server S1 . . . and returns the IP address and port of the service server S2 to the service router R1.
Id. ¶ 52
Thus, the Examiner finds Che teaches accessing, by service router R1 (the claimed “edge router”), the service information center I’s routing information (the claimed “one or more reference tables”).
Next, Applicants argue
[c]laim 1 also recites in part: “add one or more hash entries to the one or more reference tables, wherein the one or more hash entries includes one or more identifiers associated with the request.” The art or record does not teach or suggest at least this limitation.
The Examiner’s reliance on King for this limitation is misplaced because King’s hash and flow-table logic addresses an entirely different technical problem and does not disclose the claimed tenant-segmentation-preserving reference-table scheme. King concerns scaling overlay IP addresses across multiple compute instances in a cloud networking environment. To accomplish that objective, King describes generating hash values from packet fields, selecting among multiple physical IP addresses or next-hop paths, and in certain embodiments adding entries to a flow table so that subsequent packets in the same flow are directed to the same compute instance. Those teachings are directed to flow affinity and overlay-IP load distribution. They do not teach adding hash entries to reference tables for preserving tenant and segment identity while requests traverse a shared or partially shared transport path to a SIG service. The present application explains that its hash entries are associated with identifiers such as source IP information, transport tunnel identifiers, HA-pair identifiers, or translated port information, and that those entries are used to preserve tenant and segment distinctions so that return traffic from the SIG service is demultiplexed to the correct VPN or network segment. King does not disclose that architecture. Nor does King disclose a hash-entry mechanism that preserves segmentation among multiple tenant segments on a multi- tenant edge router while communicating with SIG services. Instead, King is concerned with choosing one compute instance among many for packet delivery. The Examiner’s position thus rests on an impermissibly broad generalization that any hash-derived forwarding state is equivalent to the claimed hash-entry/reference-table framework. It is not. Properly understood, King’s teachings are materially different from the claimed limitation.
Response 12.
The Examiner is unpersuaded of error. At the outset, the Examiner notes Applicants’ arguments are not commensurate with the scope of claim 1, which does not recite (1) adding hash entries to reference tables for preserving tenant and segment identity while requests traverse a shared or partially shared transport path to a SIG service; (2) hash entries associated with identifiers such as source IP information, transport tunnel identifiers, HA-pair identifiers, or translated port information, and that those entries are used to preserve tenant and segment distinctions so that return traffic from the SIG service is demultiplexed to the correct VPN or network segment; and (3) a hash-entry mechanism that preserves segmentation among multiple tenant segments on a multi- tenant edge router while communicating with SIG services. See Self, 671 F.2d at 1348.
Nor are Applicants’ arguments responsive to the rejection, which relies on Che to teach adding one or more entries to one or more reference tables, wherein the one or more entries includes one or more identifiers associated with a request.
The Examiner further finds Che’s entries are not hash entries, turning to King to show that hash entries are known in the art. Thus, the Examiner proposes to include King’s teaching with Che, such that the combined system predictably yields adding one or more hash entries to one or more reference tables, wherein the one or more hash entries includes one or more identifiers associated with a request. Accordingly, Applicants’ arguments regarding King’s alleged individual shortcomings (see Response 12) are unavailing. Here, the rejection is not based solely on King alone, but rather on the cited references’ collective teachings. See Keller, 642 F.2d at 426; Merck, 800 F.2d at 1097.
Next, Applicants argue
[c]laim 1 also recites in part: “transmit, by the edge router, the request to the SIG service” The art or record does not teach or suggest at least this limitation.
Che discloses forwarding a service interaction request from a service router to another service server after consulting a service information center. That is not transmission from an edge router to a Secured Internet Gateway service associated with a cloud provider in a multi-tenant, tenant-segmented environment. Antoo again does not fill the gap because its “secured data gateway services” are part of a payroll-card funding platform and are unrelated to SIG services or multi-tenant edge routing. The present application is directed to routing tenant-segmented traffic from an edge router over transport VPNs and transport tunnels to cloud-hosted SIG services while preserving segment identity. The cited art does not teach that technical arrangement. The rejection therefore fails to establish that the prior art discloses or renders obvious transmitting the claimed request to the claimed SIG service.
Response 12–13.
The Examiner is unpersuaded of error. At the outset, the Examiner notes Applicants’ arguments are not commensurate with the scope of claim 1, which does not recite routing tenant-segmented traffic from an edge router over transport VPNs and transport tunnels to cloud-hosted SIG services while preserving segment identity. See Self, 671 F.2d at 1348.
Nor are Applicants’ arguments responsive to the rejection, which relies on Che to teach transmitting, by an edge router, a request to a service. The Examiner further finds Che’s service is not a SIG service associated with a cloud provider, turning to Antoo to show that a SIG service associated with a cloud provider is known in the art. Thus, the Examiner proposes to include Antoo’s teaching with Che, such that the combined system predictably yields transmitting, by an edge router, a request to a SIG service associated with a cloud provider. Accordingly, Applicants’ arguments regarding Che’s alleged individual shortcomings (see Response 12–13) are unavailing. Here, the rejection is not based solely on Che alone, but rather on the cited references’ collective teachings. See Keller, 642 F.2d at 426; Merck, 800 F.2d at 1097.
Next, Applicants argue
[c]laim 1 also recites in part: “receive, at the edge router, a response from the SIG service” The art or record does not teach or suggest at least this limitation.
The reliance on Che’s disclosure of receiving a response from a service server is insufficient. Che’s response path occurs within its service-routing architecture and merely reflects the conventional return of a response between service components. It does not involve receiving a response at an edge router from a SIG service after a tenant- originated request has traversed a segmentation-preserving transport path in a multi-tenant environment. The present application specifically addresses the problem that, in multi-tenant and multi-segment networks, return traffic must be uniquely identified and delivered back to the proper tenant segment despite overlapping addresses, shared transport constructs, and possible port translation. Che is silent as to those concerns, and Antoo does not supply the missing SIG-service context. The cited combination therefore does not teach this limitation in the sense required by claim 1.
Response 13.
The Examiner is unpersuaded of error. Applicants’ arguments are not commensurate with the scope of claim 1, which does not recite (1) receiving a response at an edge router from a SIG service after a tenant- originated request has traversed a segmentation-preserving transport path in a multi-tenant environment; and (2) uniquely identifying return traffic and delivering the return traffic back to the proper tenant segment despite overlapping addresses, shared transport constructs, and possible port translation. See Self, 671 F.2d at 1348.
Che teaches receiving, at service router R1 (the claimed “edge router”), a response at fig. 3, item 305 from a service server S2 (the claimed “service”). The Examiner further finds Che’s service is not a SIG service associated with a cloud provider, turning to Antoo to show that a SIG service associated with a cloud provider is known in the art. Thus, the Examiner proposes to include Antoo’s teaching with Che, such that the combined system predictably yields receiving, at an edge router, a response from a SIG service.
Finally, Applicants argue
[e]ven aside from the deficiencies in the individual mappings, the rejection lacks a persuasive rationale for combining the cited references in the manner required to reach the claimed invention. Che is directed to service-server routing, Antoo to secure payroll- card funding through secured data gateways and webservices, and King to flow hashing and table-driven selection in overlay-IP scaling. The present application, by contrast, addresses a different and more specific problem: how to preserve per-tenant and per-segment differentiation when traffic is routed from a multi-tenant edge router to cloud-based SIG services and back, including in scenarios involving common transport tunnels, HA transport tunnel pairs, common transport VPNs, unique transport VPNs, overlapping IP addresses, and possible port collisions. The Office Action’s stated reasoning does not explain why a person of ordinary skill would have modified Che’s service-router architecture with Antoo’s payroll-funding gateway concepts and King’s overlay-network flow-table logic to arrive at the claimed per-tenant/per-segment return-path preservation architecture. At most, the rejection identifies generic networking concepts from disparate environments and then reconstructs the claim using hindsight. The law requires more than identifying broadly analogous concepts; it requires a reasoned explanation grounded in the references themselves as to why their teachings would have been combined in the particular way claimed. That showing is absent here. Because Che is not directed to multi-tenant edge routing to SIG services, because Antoo is not a SIG reference in the claimed technical sense, because King’s hash/flow-table logic is not the claimed segmentation-preserving reference-table mechanism, and because the Examiner has not articulated a convincing path to the claimed architecture, the rejection of claim 1 should be reversed.
Response 13–14.
The Examiner is unpersuaded of error. Any judgment on obviousness is in a sense necessarily a reconstruction based on hindsight reasoning. In re McLaughlin, 443 F.2d 1392, 1395 (CCPA 1971). But so long as it takes into account only knowledge which was within the level of ordinary skill in the art at the time the claimed invention was made and does not include knowledge gleaned only from Applicants’ disclosure, such a reconstruction is proper. Id.
At the outset, the Examiner finds to the extent the combination of Che and Antoo securely transmits network traffic, the combination of Che’s teachings reduces maintenance service layer difficulty, and the combination of Che and King provides a heightened level of security, as articulated by the Examiner, also improves durability and efficiency, it is well settled that
an implicit motivation to combine exists not only when a suggestion may be gleaned from the prior art as a whole, but when the “improvement” is technology-independent and the combination of references results in a product or process that is more desirable, for example because it is stronger, cheaper, cleaner, faster, lighter, smaller, more durable, or more efficient.
DyStar Textilfarben GmbH & Co. Deutschland KG v. C.H. Patrick Co.,
464 F.3d 1356, 1368 (Fed. Cir. 2006) (emphasis added). Thus, to the extent that the Examiner’s rationale to combine the references also improves durability and efficiency, such an enhancement is also an adequate motivation to combine the references under DyStar.
Moreover, to the extent Appellant contends that the Examiner’s rationale to combine the references is based solely on teachings gleaned from Appellant’s disclosure (see Response 13–14), the Examiner disagrees. See McLaughlin, 443 F.2d at 1395. The Examiner’s articulated reason to combine the references is not based on impermissible hindsight, but rather uses prior art elements predictably according to their established functions to securely transmit network traffic, reduce maintenance service layer difficulty, and provide a heightened level of security—an obvious improvement. See KSR Int’l Co. v. Teleflex Inc., 550 U.S. 398, 417 (2007). On this record, then, the Examiner’s proposed combination of the cited references is supported by articulated reasoning with some rational underpinning to
justify the Examiner’s obviousness conclusions.
The Rejection
Regarding claim 1, while Che teaches a computer-implemented method (fig. 3) for differentiated multi-segmented cloud security (intended use in italics; see MPEP § 2111.02), comprising:
receiving, by an edge router (fig. 3, item R1), from a tenant (fig. 3, item S1) of a multi-tenanted network (“The network includes service servers S1, S2, and S3, a service information center I, service routers R1 and R2, a service control center C and a service translator T.” at ¶ 23) a request (fig. 3, item 301) to access a service (fig. 3, item S2) (intended use in italics);
accessing, by the edge router, one or more reference tables (“In step 303, the service information center I finds the corresponding physical address, that is, the IP address and port of the service server S2 that can provide the service requested by the service server S1” at ¶ 52; “The service information center I is designed to store the routing information of various services handled by each service server. Here, the routing information includes the logic destination addresses and physical addresses” at ¶ 26; “The physical address of a service may be the IP address and corresponding port number of the service server that provides the service.” at ¶ 28);
adding one or more entries (“The service information center I is designed to store the routing information of various services handled by each service server.” at ¶ 26; Che at least suggests service information center I adding routing information of various services handled by each service server to its memory in order to store the routing information of the various services handled by each service server) to the one or more reference tables, wherein the one or more “The physical address of a service may be the IP address and corresponding port number of the service server that provides the service.” at ¶ 28) associated with the request;
transmitting, by the edge router, the request to the service (fig. 3, item 304);
receiving, at the edge router, a response (fig. 3, item 305) from the service; and
transmitting, by the edge router, the response to the tenant of the multi-tenanted network according to the one or more entries of the one or more reference tables (fig. 3, item 306; “according to” in the sense the transmitting would not occur but for first accessing the one or more reference tables),
Che does not teach (A) the service being a Secured Internet Gateway (SIG) associated with a cloud provider; (B) the adding being performed by the edge router; and (C) the entries being hash entries.
(A)
Antoo teaches a Secured Internet Gateway (SIG) service (“the systems and processes can be implemented through secured data gateway services” at ¶ 23) associated with a cloud provider (“cloud service provider” at ¶ 35).
It would have been obvious to one of ordinary skill in the art before the filing date of the invention for Che’s service to be an SIG service associated with a cloud provider as taught by Antoo “such that network traffic can be securely transmitted.” Antoo ¶ 16.
(B)
Che teaches an edge router (fig. 3, item R1) performing functions (fig. 3, items 302–306).
It would have been obvious to one of ordinary skill in the art before the filing date of the invention for Che’s edge router to perform the adding as taught by Che to “reduce difficulty for maintenance on the service layer.” Che ¶ 9.
(C)
King teaches hash entries (“generate the hash values.” at ¶ 8; “generate a hash value by hashing the contents of certain fields” at ¶ 176)
It would have been obvious to one of ordinary skill in the art before the filing date of the invention for Che’s entries to be hash entries as taught by King to provide “a heightened level of security.” King ¶ 60.
Regarding claim 5, while Che teaches wherein the one or more reference tables (“In step 303, the service information center I [sic] finds the corresponding physical address, that is, the IP address and port of the service server S2 that can provide the service requested by the service server S1” at ¶ 52) are maintained for a network (“The network includes service servers S1, S2, and S3, a service information center I, service routers R1 and R2, a service control center C and a service translator T.” at ¶ 23) transmitting the request (fig. 3, item 301) to the
Che does not teach (A) the service being an SIG service; and (B) the network being a transport virtual provide network (VPN).
(A)
Antoo teaches an SIG service (“the systems and processes can be implemented through secured data gateway services” at ¶ 23).
It would have been obvious to one of ordinary skill in the art before the filing date of the invention for Che’s service to be an SIG as taught by Antoo “such that network traffic can be securely transmitted.” Antoo ¶ 16.
(B)
King teaches a transport VPN (“Virtual Private Networks (VPNs)” at ¶ 47).
It would have been obvious to one of ordinary skill in the art before the filing date of the invention for Che’s network to be a transport VPN as taught by King “to ensure high availability and to protect against resource failure.” King ¶ 58.
Regarding claim 9, Che teaches a system (fig. 3) comprising: one or more processors (Che at least suggests the system illustrated in fig. 3 comprises one or more processors); and a memory (Che at least suggests the system illustrated in fig. 3 comprises a memory) storing instructions that, when executed by the one or more processors, configured the system to perform operations according to claim 1. Thus, references/arguments equivalent to those present for claim 1 are equally applicable to claim 9.
Regarding claim 13, claim 5 recites substantially similar features. Thus, references/arguments equivalent to those present for claim 5 are equally applicable to claim 13.
Regarding claim 17, Che teaches a non-transitory computer-readable storage medium (Che at least suggests the system illustrated in fig. 3 comprises a memory), the non-transitory computer-readable storage medium including instructions that when executed by a computer (Che at least suggests the system illustrated in fig. 3 comprises a computer), cause the computer to perform operations according to claim 1. Thus, references/arguments equivalent to those present for claim 1 are equally applicable to claim 17.
Che, Antoo, King, and Mehta
Claims 2, 10, and 18 are rejected under 35 U.S.C. § 103 as being obvious over Che in view of Antoo, in further view of King, and in further view of Mehta et al. (US 2014/0198794 A1; filed Jan. 8, 2014).
Regarding claim 2, while Che teaches wherein the request is transmitted through an inherent connection (fig. 3, item 301),
Che does not teach wherein the inherent connection being a unique transport tunnel, and the one or more identifiers include at least a source Internet Protocol (IP) address and a transport tunnel identifier.
Mehta teaches a unique transport tunnel (“tunnel type (GRE, IP-in-IP, IPSec, SSL or L2TPv3)” at ¶ 48), and
one or more identifiers include at least a source Internet Protocol (IP) address (fig. 11, items 1115, 1140) and a transport tunnel identifier.
It would have been obvious to one of ordinary skill in the art before the filing date of the invention for Che’s inherent connection to be a unique transport tunnel and for the Che/Antoo/King combination’s one or more identifiers to include at least a source Internet Protocol (IP) address and a transport tunnel identifier as taught by Mehta “for providing the quality of service (QoS) and guaranteed failover time for these services.” Mehta ¶ 3.
Regarding claims 10 and 18, claim 2 recites substantially similar features. Thus, references/arguments equivalent to those present for claim 2 are equally applicable to claims 10 and 18.
Che, Antoo, King, and Shaw
Claims 3, 11, and 19 are rejected under 35 U.S.C. § 103 as being obvious over Che in view of Antoo, in further view of King, and in further view of Shaw et al. (US 2008/0310326 A1; filed Aug. 14, 2008).
Regarding claim 3, while Che teaches wherein the request is transmitted through an inherent connection (fig. 3, item 301),
Che does not teach the inherent connection being a high availability (HA) transport tunnel pair, and the one or more identifiers include at least an HA transport tunnel pair identifier.
Shaw teaches high availability (HA) transport tunnel pair (fig. 5B illustrates HA transport tunnel pairs including “T1 on R1” and “T2 on R1”; Fig. 5C, items A–D; “tunnel pairs A-D” at ¶ 39), and
one or more identifiers include at least an HA transport tunnel pair identifier (“identification of tunnel pairs” at ¶ 38; fig. 5B illustrates identification of tunnel pairs including “T1 on R1,” “T2 on R1”).
It would have been obvious to one of ordinary skill in the art before the filing date of the invention for Che’s inherent connection to be an HA transport tunnel pair and for the Che/Antoo/King combination’s one or more identifiers to include at least an HA transport tunnel pair identifier as taught by Shaw “to improve the network’s performance.” Shaw ¶ 41.
Regarding claims 11 and 19, claim 3 recites substantially similar features. Thus, references/arguments equivalent to those present for claim 3 are equally applicable to claims 11 and 19.
Che, Antoo, King, and Ishibashi
Claims 4, 12, and 20 are rejected under 35 U.S.C. § 103 as being obvious over Che in view of Antoo, in further view of King, and in further view of Ishibashi et al. (US 2003/0147352 A1; filed Jan. 31, 2003).
Regarding claim 4, while Che teaches wherein the request is transmitted through an inherent connection (fig. 3, item 301), and the one or more reference tables include IP addresses and ports (“In step 303, the service information center I [sic] finds the corresponding physical address, that is, the IP address and port of the service server S2 that can provide the service requested by the service server S1” at ¶ 52),
Che does not teach the inherent connection being a common transport tunnel and the IP addresses and ports being a port entry translate table.
Ishibashi teaches a common transport tunnel (fig. 4 illustrates tunnels by “TUNNEL ID”) and
a port entry translate table (“the detected port entry of the port table” at ¶ 139; fig. 14B, item S154; fig. 15, item S161).
It would have been obvious to one of ordinary skill in the art before the filing date of the invention for Che’s inherent connection to be a common transport tunnel and for Che’s IP addresses and ports to be a port entry translate table as taught by Ishibashi “to provide a path establishment method for accommodating paths of a plurality of different fault recovery types in a single communications network.” Ishibashi ¶ 14.
Regarding claims 12 and 20, claim 4 recites substantially similar features. Thus, references/arguments equivalent to those present for claim 4 are equally applicable to claims 12 and 20.
Che, Antoo, King, and Pazhayakath
Claims 6 and 14 are rejected under 35 U.S.C. § 103 as being obvious over Che in view of Antoo, in further view of King, and in further view of Pazhayakath et al. (US 2014/0334491 A1; filed Apr. 3, 2014).
Regarding claim 6, Che does not teach wherein the one or more hash entries are removed from the one or more reference tables after a duration of time.
Pazhayakath teaches removing data from a table after a duration of time (“a step of removing the signature function data from the hash table after a pre-determined time interval elapses (Step 322).” at ¶ 33; fig. 3, item 322).
It would have been obvious to one of ordinary skill in the art before the filing date of the invention for Che’s one or more hash entries to be removed from the one or more reference tables after a duration of time as taught by Pazhayakath to “promote[[s]] increased throughput performance and promote[[s]] reduction in end-to-end packet delay.” Pazhayakath ¶ 39.
Regarding claim 14, claim 6 recites substantially similar features. Thus, references/arguments equivalent to those present for claim 6 are equally applicable to claim 14.
Che, Antoo, King, and Vohra
Claims 7 and 15 are rejected under 35 U.S.C. § 103 as being obvious over Che in view of Antoo, in further view of King, and in further view of Vohra (US 2002/0176134 A1; filed Dec. 20, 2001).
Regarding claim 7, Che does not teach wherein the one or more hash entries are added to the one or more reference tables using a multiplexer.
Vohra teaches adding two elements using a multiplexer (“The channels can be added, i.e. multiplexed, using a commercially available multiplexer” at ¶ 41).
It would have been obvious to one of ordinary skill in the art before the filing date of the invention for Che’s one or more hash entries and one or more reference tables to be added using a multiplexer as taught by Vohra for “better performance of the network.” Vohra ¶ 15.
Regarding claim 15, claim 7 recites substantially similar features. Thus, references/arguments equivalent to those present for claim 7 are equally applicable to claim 15.
Allowable Subject Matter
Claims 8 and 16 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims.
Conclusion
Any inquiry concerning this communication or earlier communications from the Examiner should be directed to DAVID P. ZARKA whose telephone number is (703) 756-5746. The Examiner can normally be reached Monday–Friday from 9:30AM–6PM ET.
If attempts to reach the Examiner by telephone are unsuccessful, the Examiner’s supervisor, Vivek Srivastava, can be reached at (571) 272-7304. The fax phone number for the organization where this application or proceeding is assigned is (571) 273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://portal.uspto.gov/external/portal. Should you have questions about access to the Private PAIR system, contact the Electronic Business Center (EBC) at (866) 217-9197 (toll-free).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, Applicants are encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
/DAVID P ZARKA/PATENT EXAMINER, Art Unit 2449
1 The Examiner has added Che’s teaching of the adding method-step (claim 1, lines 6–8) with additional explanation not provided in the previous Office action mailed January 29, 2026. Accordingly, in the interests of giving Applicants a full and
fair opportunity to respond, the Examiner designate the instant Office action as non-final.