Prosecution Insights
Last updated: August 17, 2026
Application No. 18/756,763

TELEMETRY RESTRICTION MECHANISM

Final Rejection §103
Filed
Jun 27, 2024
Priority
Dec 22, 2021 — continuation of 12/580,924
Examiner
PHAM, PHUC H
Art Unit
2408
Tech Center
2400 — Computer Networks
Assignee
Intel Corporation
OA Round
4 (Final)
90%
Grant Probability
Favorable
5-6
OA Rounds
5m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 90% — above average
90%
Career Allowance Rate
162 granted / 181 resolved
+31.5% vs TC avg
Strong +18% interview lift
Without
With
+18.0%
Interview Lift
resolved cases with interview
Typical timeline
2y 6m
Avg Prosecution
8 currently pending
Career history
196
Total Applications
across all art units

Statute-Specific Performance

§101
9.3%
-30.7% vs TC avg
§103
70.2%
+30.2% vs TC avg
§102
2.7%
-37.3% vs TC avg
§112
11.7%
-28.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 181 resolved cases

Office Action

§103
DETAILED ACTION The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This office action is in response to communication filed on June 01, 2026. Status of claims within the present application: Claims 1 – 6 are pending. Response to Arguments With regards to claims 1 – 6 that were rejected under 35 U.S.C. 103 as being unpatentable over US 20180063197 A1to Pope et al., (hereinafter, “Pope”) in view of US 20210194894 A1 to Anderson et al., (hereinafter, “Anderson”), applicant’s remarks, filed on April 03, 2026, have been considered, but are not persuasive. Therefore, applicant is directed to the response below: With respect to independent claims 1, 3, and 5, Applicant argued the prior art does not teach "copies a packet and filters the copied packet; it does not select between two telemetry protection modes." Examiner noted that Anderson teaches flows transition between a "capturing" state and a "done" state—a binary mode that determines whether packets are copied for telemetry [Para. 71]. Anderson teaches that packets not matching flow entries undergo a default action (no copy) [Para. 56]. Anderson further teaches a Boolean filter that "controls whether a particular TCP packet is included in telemetry data." [Para. 84 – 86]. These constitute two telemetry modes: one enabling copying and one preventing it. Applicant further argued no "destination-based" mode determination is taught. Examiner noted that Anderson explicitly teaches matching on "specific IP addresses" for telemetry capture decisions [Para. 64]. Anderson defines flows by 5-tuple including destination address [Para. 70]. Pope teaches the NIC monitors "to where" applications communicate [Para. 54]. Pope teaches parsing L3/L4 headers (containing destination information) for classification. The combination teaches destination-based telemetry decisions at a NIC [Para. 93]. Applicant also argued that KSR motivation is insufficient. Examiner noted that the motivation is not merely size reduction and Anderson teaches privacy-driven telemetry decisions [Para. 67 – 68]. Pope teaches destination-specific policy [Para. 47]. A person of ordinary skill in the art in a multi-tenant environment (as recited in the claim preamble) would implement destination-based mode selection to enforce per-tenant privacy policies. Applicant argued Anderson's operation occurs at a switch, not a NIC. Examiner noted that Pope teaches "the rules engine may be provided by a switch." [Para. 171]. Pope teaches rules engines in NICs performing the same type of classification and action execution [Para. 87 – 88]. A person of ordinary skill in the art would recognize that the functional capabilities taught for Anderson's switch can be implemented in Pope's NIC-based rules engine. Therefore, the combination of Pope and Anderson teaches the claimed invention as currently recited. Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13. The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer. Claims 1 – 6 are provisionally rejected on the ground of nonstatutory double patenting as being unpatentable over claim 1 – 2, 6 – 16, and 18 – 20 of co-pending Application No. 17/558,966 (reference application). Although the claims at issue are not identical, they are not patentably distinct from each other because they both used a network interface card to process telemetry packet data payload and determine a telemetry protection mode which is based on the destination of the packet. 18/756,763 17/558,966 1. An apparatus for multi-tenant environment, the apparatus comprising: a network interface card (NIC), including packet processing circuitry to determine whether the NIC is to operate according to a first telemetry protection mode to prevent copying of packet data payloads for telemetry or a second telemetry protection mode to enable copying of packet payloads for telemetry, wherein the first telemetry protection mode or the second telemetry protection mode is determined based on a destination associated with a packet, and wherein the NIC comprises a data processing unit (DPU)-based NIC. 1. An apparatus comprising: a network interface card (NIC), including packet processing circuitry to receive a packet from a tenant via a network, process the packet to examine a message indicating whether one or more network connections associated with the tenant is to operate as a confidential connection and enable the NIC to operate according to a first telemetry protection mode to prevent duplication and mirroring of telemetry packet data payloads upon determining that the message indicates that the one or more network connections are to operate as the confidential connection, wherein a telemetry protection mode including the first telemetry protection mode or a second telemetry protection mode is determined based on a destination of the packet, wherein the packet processing circuitry to generate a telemetry packet including a replacement payload upon determining that the packet is associated with the first telemetry protection mode. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 1 – 6 are rejected under 35 U.S.C. 103 as being unpatentable over US 20180063197 A1to Pope et al., (hereinafter, “Pope”) in view of US 20210194894 A1 to Anderson et al., (hereinafter, “Anderson”). Regarding claim 1, Pope teaches an apparatus for multi-tenant environment, the apparatus comprising: a network interface card (NIC), [Pope, para. 50 discloses an arrangement where a data processor 2 such as a server is configured to communicate with a network 6 via a network interface device 4, sometimes referred to a NIC. A network interface device could be provided in any suitable form, including as a peripheral device or integrated with the hardware of a host data processing device. A data processor could be any kind of computer system, including a server, personal computer, or a bespoke processing unit. A network interface device as described herein provides an interface to a network for use by its host data processing device. In this document, reference is made to a security providing NIC. It should be appreciated that this security providing NIC may be any suitable network interfacing device.] including packet processing circuitry to determine wherein the first telemetry protection mode or the second telemetry protection mode is determined based on a destination associated with a packet, [Pope, para. 56 discloses The NIC may provide a control point. In some embodiments, by establishing an overlay network which enables distributed control of the NIC functions, a layer of network management can be provided which may be cryptographically secure and/or where control can be restricted to a small set of authorized operators. Para. 58 – 63 discloses the NIC may provide one or more of the following: monitoring and/or securing of every network packet; provide a protected and/or tamper resistant execution domain; isolate and/or identify compromised servers; protect servers and/or data from network attack; and protect organizations from malicious operators. Para. 66 discloses the rule engine may be provided in one trusted domain and the controller may be provided in a different trusted domain. The communication between the rule engine and controller is secure, using for example encryption.] and wherein the NIC comprises a data processing unit (DPU)-based NIC [Pope, para. 50 discloses a data processor 2 such as a server is configured to communicate with a network 6 via a network interface device 4, sometimes referred to a NIC. A network interface device could be provided in any suitable form, including as a peripheral device or integrated with the hardware of a host data processing device. A data processor could be any kind of computer system, including a server, personal computer, or a bespoke processing unit. A network interface device as described herein provides an interface to a network for use by its host data processing device.], but Pope does not teach whether the NIC is to operate according to a first telemetry protection mode to prevent copying of packet data payloads for telemetry or a second telemetry protection mode to enable copying of packet payloads for telemetry, wherein the packet includes a telemetry packet for telemetry monitoring. However, Anderson does teach whether the NIC is to operate according to a first telemetry protection mode to prevent copying of packet data payloads for telemetry or a second telemetry protection mode to enable copying of packet payloads for telemetry. [Anderson, para. 49 discloses a switch in a software-defined network receives a packet sent by an endpoint device via the SDN. The switch makes a copy of the packet based on one or more header fields of the packet matching one or more flow table entries of the switch. The switch forms telemetry data for reporting to a traffic analysis service by applying a metadata filter to the copy of the packet. The metadata filter prevents at least a portion of the copy of the packet from inclusion in the telemetry data. The switch sends the formed telemetry data to the traffic analysis service. Para. 63 discloses switch 402 may create a packet copy 604a for further processing by telemetry capture process 249. With respect to the original packet 604, another entry in flow table 412 may cause switch 402 to process packet 604 as normal. For example, as shown, switch 402 may send packet 604 on to port 602a for forwarding towards the intended destination of packet 604.], wherein the packet includes a telemetry packet for telemetry monitoring. [Anderson, para. 32 discloses traffic analysis process 248 may execute one or more machine learning-based classifiers to classify encrypted traffic in the network (and its originating application) for any number of purposes. In one embodiment, traffic analysis process 248 may assess captured telemetry data (e.g., captured by telemetry capture process 249) regarding one or more traffic flows, to determine whether a given traffic flow or set of flows are associated with malware in the network, such as a particular family of malware applications. Para. 41 discloses telemetry exporter 306 may perform deep packet inspection (DPI) on one or more of the packets of traffic flow 308, to assess the contents of the packet.] Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Pope’s NIC to incorporate Anderson’s selective telemetry capture mechanism. Pope’s NIC already functions as a security control point that monitors every network packet, parses header information including destination, and determines per-flow actions through its rule engine [Pope, para.54, 56, 93 – 95]. Anderson teaches selectively determining whether packets are copied for telemetry based on packet header characteristics [Anderson, para. 49, 62 – 64], where telemetry is collected in a “selective, intelligent, and context-aware manner” [Anderson, para. 48]. A person of ordinary skill would have been motivated to combine these teachings because: (1) in Pope’s multi-tenant environment, different destinations have different privacy requirements, and Anderson explicitly recognizes that “user privacy is a concern” in telemetry capture decisions and that sensitive information should be excluded [Anderson, para. 67–68]; (2) selective telemetry capture greatly reduces resource consumption [Anderson, para. 67], which benefits Pope’s NIC where processing resources are more constrained [Pope, para. 87]; and (3) Pope’s NIC already performs destination-aware, per-flow action determination [Pope, para. 54, 93 – 95], making the addition of Anderson’s selective telemetry behavior a predictable application of a known technique to a known device. See KSR, 550 U.S. at 416; MPEP §2143(I)(A). As per claim 2, modified Pope teaches the apparatus of claim 1, wherein the NIC comprises a smart NIC. [Pope, para. 51 discloses the security providing NIC while logically a component of a server may can be considered to be a physically separate and distinct piece of hardware and logically distinct network entity. Para. 53 discloses The NIC may only be accessed through highly crypto-secure interfaces. The NIC may be constructed to be tamper resistant. The NIC may be regarded as secure gatekeeper between the server and the network, protecting both the network from malicious or faulty servers and the server from the network.] Regarding claims 3 – 4, they recite features similar to features within claims 1 – 2, they are rejected in a similar manner. Regarding claims 5 – 6, they recite features similar to features within claims 1 – 2, they are rejected in a similar manner. Conclusion Pertinent prior art made of record however not relied upon: US 10574702 B1 to Rickerd et al. “A system assesses a security configuration proposed for production on a target computer system. The system may receive the security configuration proposed for production and obtain telemetry metrics generated based on security configurations implemented on one or more computer systems of the service provider. The system may assess a security configuration proposed for deployment based on telemetry metrics and generate status information based on the assessment. An authorization recommendation may be provided based whether the status information indicates that the proposed security configuration satisfies one or more conditions.” THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to Phuc Pham whose telephone number is (571)272-8893. The examiner can normally be reached Monday - Thursday 7:30 AM - 4:30 PM; Friday 8:00 AM - 12:00 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Linglan Edwards can be reached at (571) 270-5440. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /P.P./Patent Examiner, Art Unit 2408 /LINGLAN EDWARDS/Supervisory Patent Examiner, Art Unit 2408
Read full office action

Prosecution Timeline

Show 2 earlier events
Sep 24, 2025
Response Filed
Nov 04, 2025
Final Rejection mailed — §103
Feb 04, 2026
Response after Non-Final Action
Apr 03, 2026
Request for Continued Examination
Apr 10, 2026
Response after Non-Final Action
Apr 24, 2026
Non-Final Rejection mailed — §103
Jun 01, 2026
Response Filed
Jul 30, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12683760
TERMINAL DEVICE, COMPUTER PROGRAM, COMMUNICATION SYSTEM, AND COMMUNICATION METHOD
3y 7m to grant Granted Jul 14, 2026
Patent 12683770
SYSTEMS AND METHODS FOR SECURE MODULAR HARDWARE BINDING
2y 11m to grant Granted Jul 14, 2026
Patent 12676746
RECOVERY USING AN ENCRYPTED FALLBACK KEY IN METADATA
2y 2m to grant Granted Jul 07, 2026
Patent 12652160
ANONYMOUS, AUTHENTICATED AND PRIVATE SATELLITE TASKING SYSTEM
3y 5m to grant Granted Jun 09, 2026
Patent 12645825
CLIENT-SIDE ENCRYPTION WITH LOW-COST INTEGRITY CHECK
3y 5m to grant Granted Jun 02, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

5-6
Expected OA Rounds
90%
Grant Probability
99%
With Interview (+18.0%)
2y 6m (~5m remaining)
Median Time to Grant
High
PTA Risk
Based on 181 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month