Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 06/24/2026 has been entered.
Response to Arguments
In response to communication filed on 06/24/2026, applicant amends claims 1, 8, and 15. The following claims, 1-20 are presented for examination.
Applicant’s arguments, see Pages 8-10, filed June 24, 2026, with respect to the rejection(s) of claim(s) 1-20 under 35 USC 103 have been fully considered and are persuasive. Therefore, the rejection has been withdrawn. However, upon further consideration, a new ground(s) of rejection is made in view of newly found prior art reference, Starr et al. (US2022/0103523 A1, file date 09/30/2020).
Upon further consideration and based on claim amendments, a new ground of rejection of claims 1-20 is set forth below.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1, 148 USPQ 459 (1966), that are applied for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Veereshwara et al. (US2021/0273918 A1, publish date 09/02/2021) in view of Shravan et al. (US2021/0281576 A1, file date 03/04/2020) further in view of Levin et al. (US2022/0029988 A1, file date 07/27/2020) further in view of Starr et al. (US2022/0103523 A1, file date 09/30/2020).
Claims 1, 8, 15:
With respect to claims 1, 8, 15, Veereshwara et al. discloses a method/system for security processing for an endpoint device in a network (identity certificate 300 used of authenticating identity of the service, the PII posture 302 can be embedded into the identity certificate 300, e.g. as x509 extensions (0038), Figure 3)/ non-transitory computer readable medium having stored thereon instructions (A non-transitory computer-readable storage medium having stored therein instructions which, when executed by one or more processors, cause the one or more processors to perform the following operations, 0020) that, when executed, cause one or more processing devices to/ the method comprising:
a memory device; a hardware processor coupled with the memory device (memory 706, processor 708, Figure 7)(memory 820, processor 804, Figure 8), the hardware processor configurable to:
receiving, by a first processing device, an indication that a security posture of an endpoint device has changed to a new security posture, wherein the endpoint device includes an endpoint agent executing on the endpoint device (one or more fog nodes 162 can be mobile fog nodes. The mobile fog nodes can move to different geographic locations, logical locations or networks, and/or fog instances while maintaining connectivity with the cloud layer 154 and/or the endpoints 116, the particular fog node may connect to a particular physical and/or logical connection point with the cloud 154 while located at the starting location and switch to a different physical and/or logical connection point with the cloud 154 while located at the destination location, 0031) (can exchange such identity certificates with each other to authenticate the identity of the other micro service, to exchange the embedded PII postures, and to further authenticate the validity of the embedded PII postures at the sidecars, the identity certificate 200 would need to be regenerated with the updated PII posture 302, The sidecars 204 and 214 can also selectively apply one or more of the different postures, include to the location of one or both micro services, when both micro services engaged in the same PII communication are at the same network environment, premise, or enterprise, send alert for the transmission, when both microservices engaged in the same PII communication are not at the same network environment, premise, or enterprise, at least one sidecar would drop or anonymize, 0042);
acquiring, by the first processing device, information corresponding to at least one change in the security posture (in order to change the PII posture, the identity certificate 200 would need to be regenerated with the updated PII posture 302, and the distributing/exchanging PII postures through distributing/exchanging identity certificates would need to be conducted again, 0042);
transmitting, by the first processing device, a message to the selected endpoint management system;
receiving a new security certificate generated by the selecting endpoint management system based at least on the new security posture of the endpoint device;
installing the new security certificate in at least one directory corresponding to the endpoint agent; and
utilizing the new security certificate to access a secure resource (can exchange such identity certificates with each other to authenticate the identity of the other micro service, to exchange the embedded PII postures, and to further authenticate the validity of the embedded PII postures at the sidecars, the identity certificate 200 would need to be regenerated with the updated PII posture 302, The sidecars 204 and 214 can also selectively apply one or more of the different postures, include to the location of one or both micro services, when both micro services engaged in the same PII communication are at the same network environment, premise, or enterprise, send alert for the transmission, when both microservices engaged in the same PII communication are not at the same network environment, premise, or enterprise, at least one sidecar would drop or anonymize, 0042).
Shravan et al. teaches Post a security posture evaluation, the network appliance either grants the user device with full network access or limits access along with sending remediation information to the user device to bring it into compliance with the policies. (0010), receiving, by a first processing device, an indication that a security posture of an endpoint device has changed to a new security posture (The client 120 monitors for changes on the user device 118 related to the compliance information, the client 120 detects that at least one setting related to the requested compliance information has changed on the user device 118 (622). Based on the updated compliance information, the client 120 provides only compliance information that has changed since the compliance information was last sent to the network appliance 110 (624), 0047) (Figure 6, 620, 622, 624),
acquiring, by the first processing device, information corresponding to at least one change in the security posture (Based on the updated compliance information, the client 120 provides only compliance information that has changed since the compliance information was last sent to the network appliance 110 (624), 0047) (Figure 6, 620, 622, 624).
Veereshwara et al. and Shravan et al. are analogous art because they are from the same field of endeavor of security posture networks.
It would have been obvious to one skilled in the art before the effective filing date of the claimed invention to use Shravan et al. in Veereshwara et al. in Shravan et al. for updated compliance information and the compliance information on the compliance database to evaluates compliance of the user device. (see Shravan et al. 0010).
Levin et al. teaches providing zero-trust network security, The intermediate CA certificates are distributed among nodes, authorized entities are allowed to communicate pursuant to a network firewall policy to be enforced (0018),
receiving a new security certificate based at least on the new security posture;
installing the new security certificate in at least one directory corresponding to the endpoint agent (Each entity receives a unique intermediate CA certificate, new intermediate CA certificates are sent, for example, periodically (e.g., when the current period of time is about to expire), 0028); and
utilizing the new security certificate to access a secure resource (a host certificate is valid if it is a non-expired CA certificate issued by the same central authority, where communications with the other entity are allowed, 0036, 0041).
Veereshwara et al. and Levin et al. are analogous art because they are from the same field of endeavor of network security.
It would have been obvious to one skilled in the art before the effective filing date of the claimed invention to use Levin et al. in Veereshwara et al. for purposes of enforcing identity-based network firewall policies in a seamless manner which does not require modifying entities or network infrastructure. By distributing CA certificates to and deploying agents at each node, the central authority can cause enforcement of the firewall policy in a distributed manner and without requiring modifying the underlying infrastructure and improve security by providing techniques for preventing unauthorized use of stolen certificates (see Levin et al. 0021)
Neither Veereshwara et al. nor Levin et al. discloses
accessing, by the endpoint agent, a maintained list of endpoint management systems accessible to the endpoint devices;
selecting, by the endpoint agent from the maintained list, one of a plurality of endpoint management systems based on at least one of
(a) a home location of the endpoint device,
(b) a current location of the endpoint device, or
(c) availability of the endpoint management system as claimed.
However, Starr et al. teaches the global monitoring service 108 may maintain an updated health status of the VPN server 106a located in region 1, VPN server 106b located in region 2, and VPN server 106n located in region-n. (Figure 1), The agent 204 may be configured to forward all traffic originating from the endpoint device 202 through the secure Internet connection established with the particular VPN server to the cloud-based security service. The agent 204 may also ensure a consistent security posture regardless of location (0038),
accessing, by the endpoint agent, a maintained list of endpoint management systems accessible to the endpoint devices;
selecting, by the endpoint agent from the maintained list, one of a plurality of endpoint management systems based on at least one of
(a) a home location of the endpoint device,
(b) a current location of the endpoint device, or
(c) availability of the endpoint management system;
transmitting, by the first processing device, a message to the selected endpoint management system (the agent 112 may intercept the connection attempt, and initiate a domain name service (DNS) request through network 110 to a VPN server selection service 104, The VPN server selection service 104 may be associated with multiple pools of VPN servers in which each pool is associated with a particular geographic region. The VPN server selection service 104, on receipt of the DNS request from agent 112, creates a DNS response that includes an IP address of a particular VPN server and sends the DNS response to the agent 112. (0030) (if the health status of the VPN server does not meet a predefined threshold, if the server identifies a high load, for example, on its compute, storage, memory, and/or bandwidth resources the server may pull itself out from the pool of available VPN servers. 0032) (secure server selection service 404 selects the VPN server 410 or set of VPN servers that is/are geographically relevant to the endpoint device and is in good condition, 0042) (a location determination module 506 configured to detect the location of the endpoint device, the location of the endpoint device based on the IP address, to select a pool from the plurality of VPN servers based on the determined location of the endpoint device and select a particular VPN server from the selected pool based on the status of the VPN servers of the selected pool, 0044).
Veereshwara et al., Levin et al., and Starr et al. are analogous art because they are from the same field of endeavor of network security.
It would have been obvious to one skilled in the art before the effective filing date of the claimed invention to use Starr et al. in Veereshwara et al. and Levin et al. to a secure Internet connection between an endpoint device and a cloud-based security service that provides autonomous, geographically relevant network overlay protection using real-time advanced cybersecurity controls. (see Starr et al. 0002)
Claims 2, 9, 16:
With respect to claims 2, 9, 16, the combination of Veereshwara et al., Shravan et al. , Levin et al., and Starr et al. discloses the limitations of claims 1, 8, 15, as addressed.
Levin et al. teaches wherein transmitting, by the first processing device, a message to the selected endpoint management system comprises a request to register the endpoint device with the selected endpoint management system (the central authority is able to distribute the load of creating identity data (e.g., identity tokens) among the nodes based on the certificates issued by the central authority, 0030) (a host certificate is valid if it is a non-expired CA certificate issued by the same central authority. In a further embodiment, S340 includes determining whether the certificate of the host certificate includes a valid host signature (e.g., a valid signature of a cloud provider), 0036).
Veereshwara et al. and Levin et al. are analogous art because they are from the same field of endeavor of network trust security.
The motivation for combining Veereshwara et al. and Levin et al. is recited in claims 1, 8, 15.
Claims 3, 10, 17:
With respect to claims 3, 10, 17, Veereshwara et al. discloses wherein transmitting, by the first processing device, a message to the selected endpoint management system comprises a request indicating the new security posture (can exchange such identity certificates with each other to authenticate the identity of the other micro service, to exchange the embedded PII postures, and to further authenticate the validity of the embedded PII postures at the sidecars, the identity certificate 200 would need to be regenerated with the updated PII posture 302, The sidecars 204 and 214 can also selectively apply one or more of the different postures, include to the location of one or both micro services, when both micro services engaged in the same PII communication are at the same network environment, premise, or enterprise, send alert for the transmission, when both microservices engaged in the same PII communication are not at the same network environment, premise, or enterprise, at least one sidecar would drop or anonymize, 0042).
Claims 4, 11, 18:
With respect to claims 4, 11, 18, Veereshwara et al. discloses a security certificate for the endpoint device (the identity certificate 200 would need to be regenerated with the updated PII posture 302, Figure 3).
Levin et al. teaches providing zero-trust network security, The intermediate CA certificates are distributed among nodes, authorized entities are allowed to communicate pursuant to a network firewall policy to be enforced (0018),
wherein transmitting, by the first processing device, a message to the selected endpoint management system comprises a request having the new security certificate (Each entity receives a unique intermediate CA certificate, new intermediate CA certificates are sent, for example, periodically (e.g., when the current period of time is about to expire), 0028)
Veereshwara et al. and Levin et al. are analogous art because they are from the same field of endeavor of zero trust security.
The motivation for combining Veereshwara et al. and Levin et al. is recited in claims 1, 8, 15.
Claims 5, 12, 19:
With respect to claims 5, 12, 19, Veereshwara et al. discloses wherein the security posture includes at least one of: an indication of an out of date operating system executing on the endpoint device, an insecure application executing on the endpoint device, a vulnerable hardware element included as part of the endpoint device, or an up to date virus detection and mitigation application executing on the endpoint device (can also validate the identity of each other as the generator and receiver of the PII through the identify certificates, 0047) (a posture can be deemed as valid if the identity certificate it embedded in is authenticated., 0048) (an application implemented through the network 200 can be formed through a plurality of microservices in the network 200. PII posture units 206 and 216 can be coupled to the sidecars 204 and 214, respectively, to manage PII postures of the corresponding microservices 202 and 212, 0037)(the PII posture 302 of the microservice 202 or 212 includes an identification of one or more types of PII that the microservice 202 or 212 is authorized to distribute and one or more types of PII that the microservice 202 or 212 is authorized to receive, 0039).
Shravan et al. discloses wherein the security posture includes at least one of: an indication of an out of date operating system executing on the endpoint device, an insecure application executing on the endpoint device, a vulnerable hardware element included as part of the endpoint device, or an up to date virus detection and mitigation application executing on the endpoint device (a policy may require that the user device 118 have a certain antivirus product, settings of the antivirus product, a certain firewall product, settings of the firewall product, a certain patch management product, settings of the patch management product, a certain status of an application (e.g., the application is open, etc.), a certain a file on the device, a certain status of one or more ports, and/or settings of registry keys, etc. The network appliance 110 requests all compliance information related to the identified requirements (606), 0044).
Veereshwara et al. and Shravan et al. are analogous art because they are from the same field of endeavor of zero trust security.
The motivation for combining Veereshwara et al. and Levin et al. is recited in claims 1, 8, 15.
Claims 6, 13, 20:
With respect to claims 6, 13, 20, Veereshwara et al. discloses further comprising: determining, by the processing device, an owner of the endpoint device based at least in part on information received as part of the request from the endpoint device ((can also validate the identity of each other as the generator and receiver of the PII through the identify certificates, 0047) (such an identity certificate 300 can be used for authenticating the identity of the service 202 or 212, 0038).
Claims 7, 14:
With respect to claims 7, 14, the combination of Veereshwara et al., Shravan et al. , Levin et al., and Starr et al. discloses the limitations of claims 1 and 8, as addressed.
Veereshwara et al. discloses wherein accessing the secure resource occurs until a network session disconnect (indicate dropping the PII from the sidecar if the microservice that transmitted the PII is not allowed to transmit the PII, e.g. according to rules for controlling communication of PII. (0040)
Levin et al. teaches wherein accessing the secure resource occurs until a network session disconnect (execution continues with S380, where communications with the other entity are blocked, 0041).
Veereshwara et al. and Levin et al. are analogous art because they are from the same field of endeavor of zero trust security.
The motivation for combining Veereshwara et al. and Levin et al. is recited in claims 1 and 8.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure, (see PTO-Form 892)
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Helai Salehi whose telephone number is 571-270-7468. The examiner can normally be reached on Monday - Friday from 9 am to 5 pm., every other Friday off.
If attempts to reach the examiner by telephone are unsuccessful, the examiner's supervisor, Jeff Pwu, can be reached on 571-272-6798. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, Applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free).
/HELAI SALEHI/Examiner, Art Unit 2433
/JEFFREY C PWU/Supervisory Patent Examiner, Art Unit 2433